Director of Cyber Threat Intelligence (CTI)
USD 162K-243K Executive-level Full Time
Tasks
- Automate indicator enrichment and lifecycle management
- Build attack path models across IT to OT
- Compare MTTI with mean time to contain
- Conduct incident intelligence retrospectives
- Coordinate takedown requests when feasible
- Create detections as code and hunt hypotheses
- Develop adversary prioritization scoring rubric
- Develop detection use cases for detection engineering
- Estimate mean time to impact
- Identify control gaps and choke points
- Integrate threat findings into TIP and SIEM
- Lead CTI program strategy
- Maintain threat watchlists and escalation triggers
- Manage CTI analyst team
- Map TTPs to MITRE ATT&CK
- Monitor dark web and breach sources
- Optimize TIP SIEM EDR integrations
- Participate in threat sharing and external engagement
- Produce threat intelligence reporting for executives
- Provide real time adversary context for incident response
- Provide vulnerability intelligence for risk based patching
- Tune detections and reduce false positives
Perks/Benefits
- N/A
Skills/Tech-stack
Actor Profiling | Adversary Emulation | Adversary attribution | Attack Path | Attack path modeling | Automated enrichment | CTI Analytics | CVE risk analysis | Cyber Threat | Cyber Threat Intelligence | Dark Web | Dark web monitoring | Detection engineering | Detections-as-code | Diamond Model | EDR | Exploitability assessment | False Positive | False positive reduction | Indicator Lifecycle | Indicator Lifecycle Management | Kill Chain | Kill Chain Reconstruction | Lifecycle Management | MITRE ATT&CK | MITRE ATT&CK for ICS | Mean Time to Containment | Mean Time to Impact | Path modeling | Purple Teaming | Risk Analysis | SIEM | TTP analysis | TTP to Detection Mapping | Threat Actor | Threat Intelligence | Threat Intelligence Platform | Threat Prioritization | Threat actor profiling | Vulnerability Management | Weaponization Assessment | Web monitoring | “as-code”
Education
Related jobs
-
Security Engineer - Vuln Management (Code) USD 210K-270KApplication Security | CI/CD | CVSS | DevSecOps | Exploitability assessment401k match | Autonomous work environment | Commuter benefits | Dental insurance | Flexible time offMid-level Full TimeFoster City, CA10h ago
-
AI-native | AI-native security | Access Management | CISOs | Cloud SecurityFlexible working hours | Generous vacation | Hybrid work policy | Optional equity donation matching | Parental leaveSenior-level Full TimeSan Francisco, CA | New York …10h ago
-
Cybersecurity Engineer USD 123K-166K800-53 | ACAS | AWS | Access Control | Agile401k retirement plan | Company stock options | Conference reimbursement | Dental insurance | Disability insuranceMid-level Full TimeUnited States - Remote R10h ago
-
Cross-Functional Collaboration | Cross-functional | Data-Driven Decision Making | Data-driven | Decision MakingContinuous career development | Cross departmental buddy program | Employee stock purchase plan | Hybrid workplace | Mentor programSenior-level Full TimeNew York, New York, USA13h ago
-
Principal Detection and Response Engineer USD 295K-345KAmazon Athena | Apache Flink | Apache Kafka | Apache Spark | C#Equity compensation | Health benefits | Hybrid work environment | On-call rotationSenior-level Full TimeSan Mateo, CA, United States R13h ago
-
Active Directory | Azure Active Directory | Conditional Access | Duo | Entra IDDental insurance | Flexible time off | Home internet allowance | Medical insurance | Mobile phone allowanceSenior-level Full TimeRemote R13h ago
-
AI Assurance | Adversarial AI | Artificial Intelligence | Budget Management | CybersecurityMid-level Full TimeArlington, VA13h ago
-
Information Security Systems Engineer USD 133K-240K800-171 | 800-53 | Access Management | CI/CD | CI/CD Security401k match | Dental insurance | Disability insurance | Dog-friendly offices | EquityMid-level Full TimeKent, Washington13h ago
-
Security Communications Systems Architect USD 146K-194K5G | AES 256 | Dial Plan | Encryption | Event managementHealth benefits | Paid time off | Recovery Benefits | Security clearance sponsorshipSenior-level Full TimeWashington, District of Columbia, United States13h ago
-
Security Communications Systems Architect USD 113K-149K5G | AES 256 | Dial Plan | Event management | FCC Part 90Senior-level Full TimeAshville, Ohio, United States13h ago
-
Splunk Architect Lead USD 131K-216KBackup | Capacity Planning | Case management | Case management tools | Change ManagementSenior-level Full TimePortland, OR, United States17h ago
-
Senior Splunk Engineer USD 146K-219KAccess Control | Alerting | Dashboards | Data Ingestion | Data ModelSenior-level Full TimePortland, OR, United States17h ago
-
SOC Tier 2 Analyst USD 85K-104KAccess Management | Alert triage | Application Security | Cloud Security | Correlation rulesMid-level Full TimePortland, OR, United States17h ago
-
Security Engineer USD 125K-178KAccess Management | Automation | CIS Controls | Cloud Security | Configuration ManagementSenior-level Full TimePortland, OR, United States17h ago
-
SOC Chief USD 170K-230KAlert triage | Case management | Cybersecurity governance | Detection engineering | EDRExecutive-level Full TimePortland, OR, United States17h ago
-
Director, Information Security USD 149K-175KAccess Management | Application Security | Business Continuity | By Design | Cloud SecurityExecutive-level Full TimeAustin, Texas, United States19h ago
-
Senior Security Engineering Manager, Product Security USD 190K-263KAPI Security | AWS | Access Management | Adversarial Testing | Application SecurityEast West time zone flexibility | Remote work | Team onsite opportunitiesSenior-level Full TimeUnited States | Remote R19h ago
-
Senior Security Engineering Manager, Enterprise Security USD 190K-263KAWS | Access Management | CI/CD | CIEM | Detection engineeringSenior-level Full TimeUnited States | Remote R19h ago
-
CDAO - IT Cybersecurity Specialist USD 139K-191K800-53 | Cloud Security | Code Analysis | Continuous Monitoring | Control AssessmentSenior-level Full TimeArlington, VA20h ago
-
AlgoSec Resident Engineer, Americas USD 120KAWS | Ansible | Application Connectivity | Azure | Change ManagementCollaborative culture | Home office arrangement | Travel opportunitiesSenior-level Full TimeUnited states, New Jersey, US21h ago
-
Regional Security Operations Lead, Cloud USD 171K-257KAccess Control | Crisis management | Critical Infrastructure | Critical Infrastructure Protection | CybersecurityTravelSenior-level Full TimeGuam23h ago
-
Information Assurance Security, Lead Associate USD 80K-128K800-37 | 800-53 | Continuous Monitoring | DHCP | DNSSenior-level Full TimeBedford, NH, United States1d ago
-
Alert triage | Antivirus | DNS | Data Loss Prevention | Data loss401k matching | Flexible time off | Higher education/training reimbursement | Hybrid work | Medical Dental Vision and Life Insurance coverageMid-level Full TimeWashington D.C., DC 20530, USA1d ago
-
AI Cyber Defense | Artificial Intelligence | Business Continuity | Business Resilience | Cloud Security401k match | Dental insurance | Medical insurance | Paid time off | Vision insuranceExecutive-level Full TimeIN-INDIANAPOLIS, 220 VIRGINIA AVE, United States1d ago
-
Manager - Business Information Security Office USD 121K-213KAI RMF | AI Risk | AI risk management | Application Security | CSA STARMid-level Full TimeUS - North Carolina - HQ, …1d ago