AS64502 · Starlight Servers, Inc.NOC +0 100 4 0000 (24h)Halls 12 · Regions 4Backbone status: nominal
Starlight Servers / Inc.

Careers / SLS-2447

Threat Analyst, Trace Operations

  • Platform Defence — Trace Operations
  • Kestrel Flats (KSF1), Central Plains · on-site 5 days
  • Full time, permanent
  • Analyst II

Trace Operations answers one question for the rest of the company: who is that, and how close are we. We run continuous trace against hostile activity on our fabrics and hand attribution to Incident Command, Regulatory, and — where a commercial interest exists — to Commercial Intelligence. The subject population is roughly 41,000 identifiable operators. You will come to know several hundred of them by their habits.

Responsibilities

  • Run trace to completion on assigned activity. Mean time-to-attribution on the desk is 31 hours; the objective for this year is 24.
  • Maintain operator profiles: tooling, working hours, deck signature, warez preferences, and the tells that survive a change of all four.
  • Score every open trace for proximity on the nine-point scale and keep the score current. A trace at 7 or above is reported to Incident Command the same shift.
  • Do not contact subjects. Do not warn subjects. Do not act on a trace; hand it over.
  • Produce the monthly population report: who is new, who has gone quiet, who has changed hands. "Gone quiet" is a category, not a conclusion.
  • Give evidence internally at review, and externally where Regulatory requires it. Externally you appear as the desk, not as yourself.

Requirements

  • Three years in threat intelligence, fraud analytics, network forensics or an equivalent attribution discipline.
  • Working knowledge of flow data at scale and the patience to sit with a partial picture for weeks.
  • Ability to hold a population of subjects in mind as people without developing an opinion about them. Both halves of that sentence are load-bearing.
  • Clear, unadorned written English. Trace reports are read by lawyers and are occasionally read out.
  • Tier 2 screening on offer.

Nice to have

  • Deck familiarity. Analysts who have jacked in read a trace faster than analysts who have not.
  • Prior work on either side of a trace, disclosed at screening. Disclosure is not a bar; discovery later is.
  • Statistical background sufficient to tell a pattern from a coincidence at n = 3.

Analysts rotate off long-running subjects at 18 months. The rotation is not optional and is not a performance signal.

Process

  1. Application read by the hiring manager, not by a filter. Five working days.
  2. Screening call, 30 minutes, with the recruiter for the team named on the requisition.
  3. Technical or desk conversation, 90 minutes, with two people you would work beside.
  4. Site visit, half a day, at the facility named on the requisition. You will walk a hall.
  5. Offer, with the band, the screening tier and the on-call obligation stated in writing.

Apply — SLS-2447

Apply now

The hiring manager for Platform Defence — Trace Operations reads these directly. Five working days to a reply, including the replies that are no.

We ask for a name, an email and a message. We do not accept a CV, an address, a telephone number or identification at this stage, and the form will not take them.

Applications go to the NetGodz game team; Starlight Servers is fictional and no real job is being offered.