1 день назад
Threat Intelligence Lead (Cybersecurity)
240 000 - 280 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Threat Intelligence Lead (Cybersecurity): Building and scaling threat intelligence and threat hunting capabilities across SaaS, cloud, identity, corporate, and product environments with an accent on actionable intelligence, detection engineering, and MITRE ATT&CK mapping. Focus on correlating external reporting, conducting hypothesis-driven hunts, writing durable detections, and using the product as customer zero.
Location: Palo Alto, California, United States
Base salary: $240,000–$280,000 USD per year, plus equity and potential incentive compensation.
Company
provides a SaaS security platform that helps organizations reduce risk, detect and respond to threats, and prevent breaches across business applications such as Microsoft 365 and Salesforce.
What you will do
- Build and scale the threat intelligence and threat hunting function.
- Collect, correlate, and synthesize intelligence from commercial feeds, open-source reporting, ISACs, vendor advisories, research communities, and dark web sources.
- Assess emerging threats, campaigns, and vulnerabilities against the product and corporate infrastructure, then produce advisories, actor and campaign profiles, and leadership briefings.
- Track threats targeting SaaS, cloud, and identity infrastructure, maintaining TTPs mapped to MITRE ATT&CK.
- Run hypothesis-driven hunts across cloud, SaaS, endpoint, corporate, and product telemetry; operationalize IOCs into detections, playbooks, and response actions.
- Use as customer zero, identify product use cases, provide feature feedback, and support incident investigations and purple team exercises.
Requirements
- At least 6 years of experience in threat intelligence, threat hunting, detection engineering, incident response, or security operations.
- Ability to analyze threat data and produce clear, prioritized, actionable assessments for technical and leadership audiences.
- Hands-on experience hunting across cloud, SaaS, and endpoint telemetry, with fluency in MITRE ATT&CK and the intelligence lifecycle.
- Working knowledge of modern SaaS and IT systems including Okta, Google Workspace, Salesforce, Slack, Notion, and Jira.
- Experience with SIEM query languages and scripting for automation and enrichment, such as Python.
- Familiarity with STIX/TAXII, MISP, OpenCTI, or similar intelligence-sharing standards and tooling.
Culture & Benefits
- Team-first, low-ego, mission-focused environment within a high-growth cybersecurity startup.
- Opportunities for professional development and high-impact security contributions.
- Annual conference attendance budget and opportunities to publish research, share non-proprietary code, and present at conferences.
- Competitive compensation with equity and 401(k).
- Comprehensive healthcare with dental and vision coverage.
- Flexible paid time off, paid holidays, and 12 weeks of new parent or family leave.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 дней назад
Security Operations Lead (AI)
180 000 - 210 000$
3 дня назад
Security Engineer, Detection & Response (Cybersecurity)
237 600 - 297 000$
6 дней назад
Staff Security Operations Engineer (Cybersecurity)
128 000 - 200 000$
7 дней назад
Senior Detections Engineer (Cybersecurity)
100 000 - 180 000$
3 дня назад
Security Engineer, Public Sector
164 000 - 342 000$
7 дней назад
Threat Hunter / Security Analyst (Cybersecurity)
100 000 - 180 000$