All remote jobs

Principal Dark Web Collection Analyst

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Remote from
USA
Salary
USD 152k–228,500 / yr
Department
Cybersecurity
Employment
Full Time
Experience
Director
Published
Apply before
5 Nov 2026
Listing views
27
Application actions
2
Application toolkit

Make your next move.

Prepare your resume, explore your fit, and draft a cover letter for this opportunity.

AI Summary

The role, at a glance.

This principal-level cybersecurity intelligence role owns strategy and hands-on collection for dark-web and underground-community sources. The analyst evaluates criminal forums, illicit marketplaces, and covert messaging channels; maintains access and personas; and produces finished threat intelligence. The position requires at least five years of relevant research experience, professional Russian proficiency, strong OPSEC judgment, and the ability to operate within legal and policy boundaries. It also involves close partnership with engineering on automated collection pipelines and broad communication with product, sales, customers, and external audiences. Success depends on independent strategic judgment, credible analytical writing, and the ability to adapt quickly to volatile adversary infrastructure.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

5/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

5/5
IndependentCollaborative
AI insightThis is a principal-level specialist role requiring rare operational experience in closed underground communities, Russian-language capability, and strong legal, ethical, and OPSEC discipline. The analyst is expected to make and defend high-impact collection investment decisions while personally conducting sensitive research.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate
$190,250
US market range$150k–$240k
AI insightThe posting explicitly discloses a US base salary range of $152,000 to $228,500 per year, with a midpoint of $190,250. The estimated US market range for a principal dark-web threat-intelligence specialist is approximately $150,000 to $240,000 annually; the disclosed range is competitive and consistent with the role's seniority and specialized language and collection requirements.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you decide whether a newly identified criminal forum is worth the operational effort required to gain and maintain access?

I would evaluate the forum's actor quality, relevance to priority intelligence requirements, exclusivity of content, activity level, credibility, access barriers, operational risk, and expected collection durability. I would document the assessment, compare it with existing sources, and recommend investment only when the intelligence value clearly outweighs the legal, operational, and maintenance costs.

Describe how you would maintain OPSEC while operating a persona in an invite-only underground community.

I would begin with an approved operational plan that defines the persona's purpose, boundaries, technical isolation, communications pattern, and escalation procedures. I would maintain strict separation from personal and corporate identities, avoid actions beyond authorized collection, preserve detailed source documentation, and regularly reassess exposure indicators and legal or policy constraints.

What steps would you take when a key marketplace or forum is taken down or migrates to new infrastructure?

I would rapidly validate the disruption, preserve relevant evidence, monitor trusted channels for migration signals, and map successor infrastructure, administrators, and user movement. I would update source assessments and collection plans, communicate the operational impact to stakeholders, and prioritize re-establishing access where the source remains strategically valuable.

How would you translate manual dark-web research tradecraft into requirements for an engineering team building collection automation?

I would define the intelligence objective, source-specific workflows, data fields, authentication and access constraints, reliability requirements, and indicators that require analyst review. I would provide examples of high-value artifacts and edge cases, work with engineering on safe and compliant automation boundaries, and measure success through collection completeness, timeliness, source continuity, and analytical usefulness.

How do you tailor a threat-intelligence finding for an executive customer versus a technical analyst audience?

For executives, I would lead with business impact, confidence, affected risks, and clear recommended actions in concise language. For technical analysts, I would provide supporting evidence, source context, indicators, actor relationships, methodology, and caveats so they can validate findings and operationalize the intelligence.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.
Opportunity details

About this role.

With 1,000+ intelligence professionals serving over 1,900 clients worldwide, Recorded Future is the world’s most advanced, and largest, intelligence company!

Recorded Future is expanding its dark web collection capability with a focus on underground community intelligence — criminal forums, illicit marketplaces, and covert messaging channels where threat actors recruit, collaborate, and transact.

You will be Recorded Future’s internal authority on the dark web ecosystem — the person other teams turn to when they need to understand how underground communities operate, what’s worth collecting, and where not to invest. This means making real strategic decisions: which forums warrant access efforts, which intelligence areas to prioritize, and which sources don’t merit the operational cost. You will own that judgment and defend it across the organization. At the same time, this is a hands-on role. You will personally navigate underground infrastructure, build and maintain access, create and manage personas, and extract intelligence directly. The expert and the operator are the same person here.

What You’ll Do:

  • Serve as the company-wide subject matter expert on dark web and underground community dynamics, advising product, engineering, sales, and analyst teams
  • Make and own strategic collection decisions: which forums, markets, and channels to pursue; which intelligence areas to prioritize; and where to explicitly not invest resources
  • Identify, evaluate, and gain access to criminal forums, darknet marketplaces, Telegram channels, and adjacent covert infrastructure within legal and policy boundaries
  • Develop and maintain collection strategies, personas, and source documentation to sustain access across a volatile source landscape
  • Partner with engineering to translate research tradecraft into automated collection pipelines
  • Monitor sources for operational changes — takedowns, migrations, rebrands — and continuously adapt
  • Produce finished intelligence on key threat actors, community dynamics, and emerging underground infrastructure: actor profiles, source assessments, and analytical summaries
  • Collaborate broadly across internal teams — product, PMM, sales, customer success, and research — as the go-to voice on underground community intelligence
  • Represent Recorded Future externally: writing customer-facing blogs, presenting at webinars, and contributing to public research on dark web tactics and trends

What You’ll Bring:

  • 5+ years of hands-on dark web threat research with demonstrable collection outcomes across forums, marketplaces, or covert channels
  • Deep, current expertise in the structure and dynamics of major criminal forums and darknet markets — how they operate, how access is governed, and how actors and communities evolve
  • Proven ability to operate within closed or invite-only communities while maintaining OPSEC and legal compliance
  • Russian language proficiency at a professional working level — essential for this role
  • Strong analytical writing skills — ability to produce concise, well-sourced intelligence products for both technical and executive audiences
  • Comfort operating externally: presenting to customers, hosting webinars, and writing public-facing content with authority

Preferred Qualifications:

  • Additional language skills relevant to underground communities (Ukrainian, Romanian, Chinese, Portuguese, Arabic)
  • Background in cybercrime research, threat actor tracking, or law enforcement intelligence
  • Prior experience at a threat intelligence vendor, CSIRT, law enforcement, or intelligence agency
  • Basic scripting ability (Python) for data parsing and format conversion

The base salary range for this full-time position is $152,000 – $228,500. Our salary ranges are determined by role, level, and location. The salary displayed reflects the range for new hire salaries for the position across all US locations. Within the range, individual pay is determined by state, work location and additional factors, including job-related skills, experience, and relevant education or training. This position may be eligible for incentive compensation, equity, and medical, dental, vision, life insurance and 401K. Your recruiter can share more about the specific details of the compensation and benefit package during the hiring process.

#LI-Remote

Why should you join Recorded Future?
Recorded Future employees (or “Futurists”), represent over 40 nationalities and embody our core values of having high standards, practicing inclusion, and acting ethically. Our dedication to empowering clients with intelligence to disrupt adversaries has earned us a 4.6-star user rating on G2 and more than 50% of Fortune 100 companies as customers.

Want more info?
Blog & Podcast: Learn everything you want to know (and maybe some things you’d rather not know) about the world of cyber threat intelligence
Linkedin, Instagram & Twitter: What’s happening at Recorded Future
The Record: The Record is a cybersecurity news publication that explores the untold stories in this rapidly changing field
Timeline: History of Recorded Future
Recognition: Check out our awards and announcements

We are committed to maintaining an environment that attracts and retains talent from a diverse range of experiences, backgrounds and lifestyles. By ensuring all feel included and respected for being unique and bringing their whole selves to work, Recorded Future is made a better place every day.

If you need any accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to our recruiting team at careers@recordedfuture.com

Recorded Future is an equal opportunity and affirmative action employer and we encourage candidates from all backgrounds to apply. Recorded Future does not discriminate based on race, religion, color, national origin, gender including pregnancy, sexual orientation, gender identity, age, marital status, veteran status, disability or any other characteristic protected by law.

Recorded Future will not discharge, discipline or in any other manner discriminate against any employee or applicant for employment because such employee or applicant has inquired about, discussed, or disclosed the compensation of the employee or applicant or another employee or applicant.

Recorded Future does not administer a lie detector test as a condition of employment or continued employment. This is in compliance with the law of the Commonwealth of Massachusetts, and in alignment with our hiring practices across all jurisdictions.

Recorded Future maintains a drug-free workplace.

Note: Our interview process for all final-round candidates requires a mandatory in-person interview or a live, scheduled video conference with the hiring manager. We do not conduct interviews via instant messaging or text. All communications during the application process will come from individuals within our HR department via their Recorded Future email address.


Notice to Agency and Search Firm Representatives: Recorded Future will not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to Recorded Future, including those sent to our employees or through our website, will become the property of Recorded Future. Recorded Future will not be liable for any fees related to unsolicited resumes.

Agencies must have a valid written agreement in place with Recorded Future’s recruitment team and must receive written authorization before submitting resumes. Submissions made without such agreements and authorization will not be accepted and no fees will be paid.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. .

Log in to save
One quick step before you apply

Sign in to continue.

Sign in or create a free account to continue to the employer's application.

Applying is free. After signing in, return to this job and select Apply Now.
Add alert
Jobs Talent AI Tools Salaries
Menu