
Manager, Threat Intelligence
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
• Lead and expand a remote team of analysts, hunters, and detection engineers.
• Recruit, mentor, and nurture team members with well-defined priorities and career progression.
• Balance responsibilities between team leadership and active involvement in threat hunting, intelligence creation, and detection development.
• Collaborate with SOC, Incident Response, and Security Engineering leaders to enhance detection, response, and customer outcomes.
• Define intelligence needs in partnership with SOC leadership and clients.
• Manage the entire intelligence lifecycle from data collection to feedback implementation.
• Produce strategic, operational, and tactical intelligence products, such as actor profiles, campaign analyses, industry threat briefs, and tailored reports for customers.
• Monitor financially motivated groups, payment fraud operations, and ransomware gangs targeting retail and hospitality sectors.
• Oversee the detection content strategy across SIEM and EDR/XDR platforms.
• Develop, test, fine-tune, and evaluate detection coverage based on MITRE ATT&CK framework.
• Conduct hypothesis-driven threat hunts within customer environments.
• Utilize automation and AI for data enrichment, triage assistance, and reporting.
• Provide intelligence context during significant incidents and manage complex escalations.
• Counsel customers through briefings, reports, and presentations tailored for both technical and executive audiences.
• Track metrics such as detection coverage, hunt findings, reporting timeliness, and customer satisfaction.
• Contribute to service planning and the development of new offerings.
• Evaluate the team, tools, and detection coverage within the first 90 days.
• Establish industry threat reporting and an ATT&CK coverage roadmap within six months.
• Achieve measurable detection coverage and improvements driven by hunts within 12 months.
• Over 8 years of experience in cybersecurity, encompassing threat intelligence, threat hunting, incident response, detection engineering, or security operations.
• More than 3 years of experience managing technical security teams, including recruitment and development of personnel.
• Extensive understanding of adversary tactics and MITRE ATT&CK, the intelligence lifecycle, and the Diamond Model.
• Proven history of delivering finished intelligence suitable for both technical and executive audiences.
• Practical experience with SIEM platforms such as FortiSIEM, Microsoft Sentinel, Splunk, Google Chronicle, or ArcSight.
• Familiarity with EDR/XDR platforms and query languages like KQL or SPL.
• Experience in supporting complex investigations and incident response activities.
• Exceptional written, verbal, and presentation communication skills.
• Capability to translate technical findings into business risks.
• A bachelor's degree in a relevant field or equivalent experience.
• Nice to have: Experience with MSSP or MDR providers.
• Nice to have: Background in retail, hospitality, or payments, including knowledge of POS systems or PCI DSS.
• Nice to have: Familiarity with detection-as-code, Sigma, SOAR, or scripting languages such as Python.
• Nice to have: Experience with threat intelligence platforms and feeds like MISP or Recorded Future.
• Nice to have: Experience in cloud and SaaS investigations across Azure, AWS, or Microsoft 365.
• Nice to have: Participation in intelligence-sharing communities such as RH-ISAC.
• Certifications such as GCTI, GCFA, GCIH, GREM, or CISSP are appreciated but not mandatory.
• Competitive salary.
• Market-competitive benefits.
• Quarterly perks program.
• Generous time off [time away].
• Hybrid work arrangements where applicable.
• Opportunities for continuous learning.
• Support for professional certifications.
• Leadership development programs.
• A supportive, diverse, and inclusive global culture.
ALB Conciergerie
Global Payments Inc.
ALB Conciergerie
Get handpicked remote jobs straight to your inbox weekly.