This is a Closed Call for Applications
Zeroth Cloud is an automated threat detection, response, and intelligence-sharing platform built to defend civil society organisations- independent media, human rights defenders, and digital rights groups facing increasingly sophisticated cyber threats. We are recruiting ten (10) trainees for an intensive analyst training programme, from which the top five (5) will be selected as operational analysts on the project.
What You Will Do
- Monitor and triage security alerts across multiple beneficiary organisations
- Investigate incidents end-to-end using tools like SOAR, Cortex, MISP, and AI-assisted analysis tools
- Enrich indicators of compromise using publicly available databases and platforms
- Produce incident reports and threat intelligence summaries for both technical and non-technical beneficiary audiences
- Build trust-based relationships with civil society partners and contribute to sector-wide threat intelligence
What You Will Gain
- Hands-on experience with Zeroth Cloud, an industry-standard SOC tooling expected to be widely used by security operators, help desks, and civil society across the Global South in a couple of years.
- Certification as a Zeroth Cloud Analyst, plus mentorship from senior analysts
- Exposure to real-world incident response in high-stakes, high-impact environments
- A monthly stipend if selected as an operational analyst (see Timeline below)
A Global Community of Practice
Selected analysts join a growing global Zeroth Cloud community — researchers, engineers, and analysts working with partners worldwide to deploy, administer, and continuously improve the platform. Members participate in monthly threat-landscape briefings, and quarterly skills development, and contribute case studies that shape the future of the programme and the field.
Timeline
| Phase | Dates |
| Applications open | 30 April 2026 |
| Applications close | 15 May 2026 |
| Interviews | 18 – 29 May 2026 |
| Training & Capstone Project | 22 June – 28 August 2026 |
| Final Selection of Top Analysts | 31 August 2026 |
| Operational period (Top 5 only) | September 2026 – June 2027 |
| Stipend | Monthly stipend of $750 (Senior analyst) and $400 (Junior analyst) paid to operational analysts |
Role Categories
- Junior Analysts (Tier 1): First-line monitoring alerts across assigned beneficiary organisations: triage, IOC extraction, Cortex enrichment, and case creation. They handle routine incidents end-to-end, draft notifications for review, and escalate complex or ambiguous cases upward.
- Senior Analysts (Tier 2/3): Lead investigations on escalated and multi-organisation incidents, including campaign correlation across beneficiaries via MISP. They mentor juniors, review beneficiary communications before sending during supervised operations, own escalation decisions and produce contextual threat intelligence.
How to Apply
Submit your application via the application form no later than 15 May 2026. A complete application must include: (1) CV, (2) one-page statement of interest describing your background and motivation, and (3) two professional or academic references. Prerequisites: basic networking knowledge, familiarity with the Linux command line, prior security awareness training, strong written English, and demonstrated commitment to civil society or digital rights.
