Cyber Threat Analyst | Data Scientist (m/w/d)

Bundesamt für Sicherheit in der Informationstechnik

Bonn, Nordrhein-Westfalen, Deutschland
Published Oct 15, 2025
Full-time
No information

Job Summary

This role involves serving as a Cyber Threat Analyst within the Federal Security Operation Center (BSOC), the core analysis unit of Germany's Federal Office for Information Security (BSI). The primary mission is to defend federal government networks by analyzing and evaluating suspected cyber incidents and advanced, targeted attacks. Day-to-day responsibilities include the detailed analysis and assessment of security-relevant events, such as malware attacks, analyzing extensive log and protocol data, extracting Indicators of Compromise (IoCs), and identifying detection gaps. You will work closely with internal BSI departments like CERT-Bund and Threat Intelligence, contributing to the optimization of detection performance. The ideal candidate possesses a technical degree (e.g., Computer Science, IT Security) and foundational to advanced knowledge in network protocols, operating systems, and techniques for analyzing malicious programs and scripts. This position offers a unique opportunity to actively shape the secure digital future of Germany in a highly technical and collaborative team environment in Bonn.

Required Skills

Education

Bachelor's degree or equivalent (FH-Diplom) in Computer Science, Technical Informatics, IT Security, Physics, Mathematics, Communications Engineering, Electrical Engineering, IT Management, Administrative or Business Informatics, or a comparable relevant technical/IT field.

Experience

  • Professional experience in analyzing programs (PE32), scripts (Powershell, JS, VBS, VBA), and documents (Microsoft Office, PDF, RTF) with malicious functions or exploits, including deobfuscation.
  • Knowledge of TCP/IP protocols, network services, and network traffic analysis.
  • Knowledge of operating systems and standard applications for assessing vulnerability exploitability.
  • Knowledge of log analysis and event correlation for operational or security monitoring.

Languages

Not specified

Additional

  • Must work at the Bonn office.