Назад
Company hidden
1 день назад

Threat Intelligence Lead (Cybersecurity)

240 000 - 280 000$
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Threat Intelligence Lead (Cybersecurity): Building and scaling threat intelligence and threat hunting capabilities across SaaS, cloud, identity, corporate, and product environments with an accent on actionable intelligence, detection engineering, and MITRE ATT&CK mapping. Focus on correlating external reporting, conducting hypothesis-driven hunts, writing durable detections, and using the product as customer zero.

Location: Palo Alto, California, United States

Base salary: $240,000–$280,000 USD per year, plus equity and potential incentive compensation.

Company

hirify.global provides a SaaS security platform that helps organizations reduce risk, detect and respond to threats, and prevent breaches across business applications such as Microsoft 365 and Salesforce.

What you will do

  • Build and scale the threat intelligence and threat hunting function.
  • Collect, correlate, and synthesize intelligence from commercial feeds, open-source reporting, ISACs, vendor advisories, research communities, and dark web sources.
  • Assess emerging threats, campaigns, and vulnerabilities against the product and corporate infrastructure, then produce advisories, actor and campaign profiles, and leadership briefings.
  • Track threats targeting SaaS, cloud, and identity infrastructure, maintaining TTPs mapped to MITRE ATT&CK.
  • Run hypothesis-driven hunts across cloud, SaaS, endpoint, corporate, and product telemetry; operationalize IOCs into detections, playbooks, and response actions.
  • Use hirify.global as customer zero, identify product use cases, provide feature feedback, and support incident investigations and purple team exercises.

Requirements

  • At least 6 years of experience in threat intelligence, threat hunting, detection engineering, incident response, or security operations.
  • Ability to analyze threat data and produce clear, prioritized, actionable assessments for technical and leadership audiences.
  • Hands-on experience hunting across cloud, SaaS, and endpoint telemetry, with fluency in MITRE ATT&CK and the intelligence lifecycle.
  • Working knowledge of modern SaaS and IT systems including Okta, Google Workspace, Salesforce, Slack, Notion, and Jira.
  • Experience with SIEM query languages and scripting for automation and enrichment, such as Python.
  • Familiarity with STIX/TAXII, MISP, OpenCTI, or similar intelligence-sharing standards and tooling.

Culture & Benefits

  • Team-first, low-ego, mission-focused environment within a high-growth cybersecurity startup.
  • Opportunities for professional development and high-impact security contributions.
  • Annual conference attendance budget and opportunities to publish research, share non-proprietary code, and present at conferences.
  • Competitive compensation with equity and 401(k).
  • Comprehensive healthcare with dental and vision coverage.
  • Flexible paid time off, paid holidays, and 12 weeks of new parent or family leave.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →