
Manager, Cyber Threat Intelligence – Response
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Oversee MLB's threat intelligence and incident response initiatives throughout the League office, the 30 Clubs, and their affiliates.
• Manage the vulnerability intelligence program and evaluate real-world risks stemming from vulnerabilities, exploit code, proof-of-concepts, and the weaponization of threat actors.
• Establish remediation priorities based on severity, exploit intelligence, asset context, and active targeting.
• Direct research efforts utilizing OSINT, social media, deep and dark web resources, commercial intelligence platforms, and industry information-sharing groups.
• Monitor threat actors, campaigns, indicators of compromise, as well as tactics, techniques, and procedures.
• Develop automation for vulnerability research, intelligence enrichment, alert correlation, investigation support, and reporting.
• Transform intelligence into detection content, alert logic, hunt hypotheses, and tuning recommendations using Sigma, YARA, SIEM queries, EDR logic, and detection-as-code methodologies.
• Design and lead hypothesis-driven threat hunts across endpoint, identity, cloud, network, email, and application telemetry.
• Support the incident response lifecycle from triage to closure, including containment, eradication, recovery, and escalation.
• Act as incident commander when on-call and facilitate incident bridges involving the vSOC, Clubs, Legal, Privacy, Communications, Technology, and other stakeholders.
• Conduct post-incident reviews, update playbooks and controls, and monitor corrective actions.
• Supervise analysts, contractors, vSOC partners, and external security providers.
• Manage security awareness training, education, and phishing simulation initiatives.
• Organize and lead League-wide, Club, and internal tabletop exercises.
• Create and maintain incident response plans, escalation paths, procedures, and playbooks.
• Bachelor's degree in Cybersecurity, Information Security, Computer Science, Criminal Justice, Criminology, Law, or a related field, or equivalent practical experience.
• Comprehensive understanding of threat actors, campaigns, indicators of compromise, tactics, techniques, and procedures, including practical application of the MITRE ATT&CK framework.
• Proficient knowledge of AWS or GCP.
• Familiarity with scripting, detection, or query languages such as PowerShell, Python, SQL, KQL, SPL, Sigma, or YARA.
• Background in cyber threat intelligence, incident response, security operations, digital forensics, or a similar security role.
• Experience managing security incidents through triage, escalation, containment, eradication, recovery, and post-incident review.
• Proven experience in developing and executing threat hunts across endpoint, identity, cloud, network, email, or application data.
• Experience in creating or tuning detection content using SIEM queries, EDR logic, Sigma, YARA, or detection-as-code methodologies.
• Hands-on experience with EDR/XDR, SIEM, and vulnerability assessment tools.
• Proficient in using OSINT, social media sources, deep and dark web monitoring, and commercial threat intelligence platforms.
• Experience with security automation and orchestration (SOAR) platforms, including creating workflows for threat intel research, enrichment, correlation, and reporting.
• Excellent documentation and communication skills, capable of articulating attack methods, response decisions, and risks to both technical and non-technical audiences.
• Ability to manage sensitive information and participate in a rotational after-hours on-call and incident escalation schedule.
• Preferred certifications include: CompTIA CySA+, CompTIA CTIA, or SANS GIAC Cyber Threat Intelligence (GCTI).
• Competitive Benefits Package.
• Company 401K Contribution.
• Paid Time Off and Holidays.
• Paid Parental Leave.
• Access to Free Tickets to Baseball Games & MLB.TV.
• Discounts at MLB Store | MLBShop.com.
• Employee Assistance Programs (EAP).
• Onsite/Online Training & Development Programs.
• Tuition Reimbursement.
• Disability Benefits (short term and long term).
• Life and Accidental Death Insurance.
• Pet Insurance.
• Bonus.
ReWorks Solutions
Johnson & Johnson
Thermo Fisher Scientific
Get handpicked remote jobs straight to your inbox weekly.