WHAT ZEROFOX WILL LOOK LIKE TO YOUZTAC (ZeroFox Threat Analysis Center) is where ZeroFox's intelligence promise gets stress-tested every single day - real clients, real deadlines, threats that don't wait for business hours. This team doesn't just monitor the internet; it decides what actually matters on it, across physical security, cyber, geopolitical, and reputational risk at once. You're joining at a moment when clients are asking ZTAC for faster answers and sharper judgment than ever, and this role is where that gets built.
THE ROLEYou'll use ZeroFox's patented technology to pull relevant signal out of noisy, high-volume data - from mainstream social platforms to deep and dark web forums - and turn it into intelligence that actually changes what a client does next. The work spans physical security threats, cyber risk, geopolitical developments, reputational exposure, and compliance concerns, often in the same week, sometimes in the same report.
This isn't queue-clearing. You'll research a threat, decide what's credible and what's noise, and write it up in a BLUF-first format a client's security team can act on without a follow-up call. You'll work daily security and incident alerts, support recurring intelligence deliverables, brief clients directly, and partner with Collection Management to keep the intelligence pipeline getting sharper - not just bigger.
In your first 90 days, you'd be expected to run point on at least one recurring client deliverable, complete ZTAC's onboarding certifications, and independently produce a BLUF-format report your manager signs off on without edits.
You'll thrive here if...• You've done real OSINT and social media investigation work - 2-3 years of it - and know the difference between a lead and a rabbit hole
• You can hold four threat categories (physical, cyber, geopolitical, reputational) in your head at once without losing the thread on any of them
• You've written a BLUF-format report under deadline and had a client act on it the same day
• You're comfortable being the one who decides something is credible enough to escalate - nobody's rubber-stamping your judgment
• Getting better at this daily - sharper tradecraft, new certifications, better sourcing - actually motivates you
This probably isn't for you if...• You want a fully scoped ticket queue where someone else has already decided what's relevant - this role requires deciding that yourself
• You've never had to defend why you called something credible, or not, to someone who disagreed
• You're not comfortable working the deep and dark web as part of the job - this role goes there regularly
• Briefing a customer directly, live, makes you want to hand it off to someone else
• You're looking for a single-domain specialty - this role moves across physical, cyber, and geopolitical risk, and narrow focus isn't the job
Requirements• 2-3 years of OSINT and social media research experience, including executive threat assessments or investigations
• Ability to judge the credibility, value, and relevance of information across sources - and say so clearly in writing
• Strong written and oral communication skills; comfortable producing BLUF-style reports and briefing customers directly
• Experience with at least one online investigative tool (Whois, Ping, Traceroute, or similar), plus proficiency in Google Suite
• Working familiarity with surface web platforms, blogs, IRC, message boards, and deep/dark web environments
Would love, but we won't hold it against you:• Experience conducting studies on threat vectors, actors, or trends and turning them into recommendations
• Deep familiarity with deep/dark web tradecraft and the platforms threat actors actually use
• Project management instincts and a track record of managing customer relationships well
• Some college coursework in cybersecurity, intelligence studies, or homeland security
• Working knowledge of a specific threat landscape - cybercrime, fraud, physical/corporate security, hacktivism, or geopolitical risk
Benefits- Comprehensive health, dental, and vision (Cigna)
- 401(k) with 3% match, 100% immediately vested - no cliff
- HSA with quarterly company contributions
- Company-paid disability and life insurance
- Generous time off