🇮🇹 Milan, Italy · 15h ago
Head of Cyber Threat Intelligence [RAL up to 100k EUR]
TROPICO Security
LinkedInleadEnglish-friendly
About TropicoTropico Security builds Deception-as-a-Service: decoy portals, honeypots, and AI-agent traps that catch attackers in the act. We are backed by top European cyber investors, and protect enterprises in banking, logistics, manufacturing, and critical infrastructure.The roleThis is a hybrid role. Part of it is building and leading our CTI function, the rest is client-facing: you’ll be the person our customers trust to explain what is targeting them, why it matters, and what to do next.What you’ll doPlan the CTI strategy and partnerships. Track campaigns, infrastructure, and TTPs observed across our decoys. Deliver threat briefings to CISOs and SOC teams, support onboarding and incident escalations, and help clients turn findings into detection and response improvements. Join conversations as the technical voice on threat intelligence.Feed what you learn back into decoy design, detection logic, and our intelligence-sharing integrations (MISP, STIX/TAXII, SIEM platforms). Help decide what our platform should detect next.Work with our team to publish research, speak at conferences, and engage with the community, CERTs, and ISACs, especially in finance and critical infrastructure.What we’re looking for6+ years in cyber threat intelligence, threat hunting, incident response, or offensive security, with at least some experience leading people or a functionSolid command of adversary tradecraft: initial access, credential theft, lateral movement in Active Directory, phishing infrastructure, and ransomware operationsHands-on experience with MITRE ATT&CK or similar frameworks, and intelligence platforms (MISP, OpenCTI, or equivalent)Ability to write clear intelligence products for different audiences, from a technical IOC report to a two-paragraph executive summaryComfort in front of clients: you can run a briefing, handle tough questions, and build trust with security leadersFluent in English. Optional: Italian, French, German, SpanishNice to have: experience with deception technology or honeypots, malware analysis or reverse engineering; familiarity with DORA, NIS2, or financial-sector threat landscapes, background in a CERT, SOC, MSSP, or government agency; GIAC (GCTI, GCIH), OSCP, or similar certifications; published research or conference talks.What we offerGross annual salary of €60,000-€100,000, depending on experienceGenerous stock option packageA founding-level role with real ownership over how the CTI function is builtAccess to a unique, first-party dataset of live attacker behaviourHybrid working from Milan and/or remote from Italy with flexible hoursA small, senior, technical team that ships quicklySourced from LinkedIn. Relocantly aggregates public job postings; apply on the original site.