Intelligence Analyst II, Buyer Threat Intelligence Unit
Amazon · Seattle, WA · 4 wk ago
ManufacturingFull-time
About the role
The Buyer Team is seeking a Threat Intelligence Analyst to lead a net-new intelligence function within Buyer Risk Prevention (BRP). This role is responsible for proactively identifying, analyzing, and disrupting emerging buyer-related threats to Amazon through systematic intelligence gathering across dark web marketplaces, encrypted channels, and fraud-as-a-service platforms. You will establish investigation methodology, tradecraft standards, and tooling workflows while also delivering actionable intelligence that feeds directly into detection rules, ML model retraining, and Legal referrals.
Responsibilities
- Dark Web & Deep Web Intelligence Collection: Monitor and analyze dark web marketplaces, carding forums, private Telegram channels, Discord servers, and paste sites for Amazon-specific exploitation techniques and emerging fraud modus operandi.
- Threat Actor Profiling: Identify, profile, and track threat actors, fraud-as-a-service providers, and organized fraud rings targeting Amazon's buyer ecosystem.
- Fraud MO Investigation & Reporting: Produce ≥1 comprehensive fraud modus operandi investigation report per month for Legal, including threat actor attribution, technical indicators, and estimated business impact.
- Tradecraft & Methodology Leadership: Establish and maintain investigation methodology, operational security standards, and tooling workflows for the BTIU team.
- Mentorship & Team Development: Serve as team lead, mentoring fellow analysts, and building toward independent investigation capability across the team.
- Cross-Functional Collaboration: Partner with ML, Risk Teams, Engineering, Legal, and Law Enforcement teams to operationalize intelligence findings into detection rules, model features, and enforcement actions.
- Law Enforcement Coordination: Establish and maintain referral pathways with Legal and external law enforcement agencies.
- Urgent Threat Alerts: Issue real-time alerts when active exploitation campaigns targeting Amazon buyers are detected, enabling immediate defensive response.
- Tooling & Automation: Drive adoption and optimization of intelligence platforms and build custom collection scripts and enrichment pipelines.
Qualifications
- Experience handling confidential information
- Experience establishing successful partnerships with internal and external teams to execute tactical initiatives or equivalent
- Proficiency with OSINT methodologies and investigative research techniques
- Knowledge of fraud ecosystems: carding, account takeover (ATO), synthetic identity fraud, refund abuse, phishing, or fraud-as-a-service models
- Familiarity with payment systems, e-commerce fraud vectors, or chargeback patterns
- Ability to operate with discretion and sound judgment when handling sensitive information
- 5+ years of experience in one or more of the following: cyber threat intelligence, fraud investigations, risk analysis, or cybercrime research
Preferred Qualifications
- Experience navigating and collecting intelligence from dark web marketplaces, underground forums, and encrypted communication channels
- Operational security (OPSEC) expertise — persona management, attribution avoidance, and safe browsing practices in adversarial environments
- Experience with threat intelligence frameworks (MITRE ATT&CK)
- SANS certifications: FOR578 (Cyber Threat Intelligence), SEC487 (OSINT Gathering and Analysis), or equivalent
- Experience with intelligence platforms: Flashpoint, Recorded Future, Maltego Enterprise
- Established relationships with law enforcement agencies or intelligence-sharing communities (e.g., FS-ISAC)
- Experience building or contributing to a threat intelligence function
- Background in producing court-ready evidence or supporting legal/enforcement proceedings
- Experience integrating threat intelligence into ML pipelines or automated detection systems
- Experience with link analysis tools for visual investigation and relationship mapping