Threat Intelligence Lead

Irving, TX, US • Posted 1 day ago • Updated 1 day ago
Contract W2
12 Months
No Travel Required
On-site
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • MITRE ATT&CK
  • Threat Intelligence
  • MISP
  • ThreatConnect
  • Anomali
  • Recorded Future
  • Splunk
  • Palo Alto
  • Cortex XSOAR
  • CVE/NVD
  • EPSS
  • CISA KEV

Summary

Job title: Threat Intelligence Lead
Location: Irving, TX - 5 days onsite
12 months contract
 
Position Summary (Summary of the Role)
You own the threat intelligence function, setting collection priorities, intelligence standards, and reporting cadence for the organization. You lead a team of analysts, direct their day-to-day work, and are personally accountable for the quality, timeliness, and actionability of intelligence delivered to Security Operations, Incident Response, Vulnerability Management, and executive stakeholders. You represent threat intelligence in leadership forums, own vendor and feed decisions, and build the program's maturity year over year.
Key Responsibilities
Lead the threat intelligence program
  • Set intelligence collection priorities and requirements based on organizational risk, industry targeting, and stakeholder needs
  • Own the threat intelligence roadmap, including program maturity, tooling, staffing, and process improvements
  • Establish and enforce standards for finished intelligence products, source reliability, and confidence-level reporting
  • Define and track program KPIs, such as report timeliness, actionability, detection coverage, and stakeholder satisfaction
Manage and develop the analyst team
  • Hire, coach, and manage threat intelligence analysts, including workload prioritization and quality review of their work
  • Set individual and team goals, conduct performance reviews, and build career development plans for analysts
  • Run the team's intelligence cycle end to end: tasking, collection, analysis, production, and dissemination
  • Build team proficiency in structured analytic techniques, adversary tracking, and the MITRE ATT&CK framework
Deliver strategic and operational intelligence
  • Personally author and quality-check high-stakes intelligence products, including executive and board-level briefings
  • Lead intelligence support during major incidents, providing attribution, actor intent, and containment guidance to IR leadership
  • Direct the organization's threat landscape assessment, including sector-specific and geopolitical risk
  • Prioritize vulnerability remediation guidance in partnership with Vulnerability Management using exploitation and actor-interest data
Own detection enablement and adversary emulation
  • Partner with detection engineering to convert intelligence into SIEM/EDR detection logic and hunting programs
  • Direct threat-informed red team, purple team, and adversary emulation exercises using current TTPs
  • Review and approve detection and hunting priorities to ensure they reflect the current threat landscape
Vendor, platform, and cross-functional leadership
  • Own the threat intelligence platform (TIP) strategy, feed and vendor selection, licensing, and renewal decisions
  • Build and maintain relationships with industry ISACs/ISAOs, law enforcement, and peer intelligence leads for information sharing
  • Represent threat intelligence in leadership, risk, and governance forums, including budget and staffing discussions
  • Partner with Security Architecture, IR, Vulnerability Management, and Product Security leads to align intelligence with broader security strategy
Required Qualifications (Non-Negotiable) 
 
  • Deep working knowledge of MITRE ATT&CK, the intelligence cycle, and structured analytic techniques
  • Demonstrated experience producing and delivering intelligence to executive and board-level audiences
  • Experience directing threat intelligence platform and vendor strategy, including feed evaluation and management
  • Experience partnering with detection engineering, incident response, and vulnerability management on intelligence-driven prioritization
  • Strong people-leadership skills, including hiring, coaching, and performance management of analysts
  • Excellent written and verbal communication skills, with the ability to translate technical findings into business risk
  • Sound analytic judgment, including the ability to state and defend confidence levels under scrutiny
 
 
Nice-to-Have Qualifications (Desired but Not Required)
  • Threat Intelligence Platforms (TIPs): MISP, ThreatConnect, Anomali, Recorded Future
  • SIEM/SOAR: Splunk, Palo Alto Cortex XSOAR
  • Malware and sandbox analysis: VirusTotal, Any.Run, Hybrid Analysis, Joe Sandbox
  • Frameworks: MITRE ATT&CK, Diamond Model, Cyber Kill Chain, Traffic Light Protocol (TLP)
  • OSINT and dark web tooling: Maltego, Shodan, Censys, dark web monitoring services
  • Vulnerability and exposure data: CVE/NVD, EPSS, CISA KEV catalog
  • Program and reporting: KPI dashboards, ticketing/workflow tools, executive reporting templates
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91088983
  • Position Id: 9086700
  • Posted 1 day ago
Contact the job poster
JD

Jaffar Deen

Recruiter @ XFORIA Inc
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Irving, Texas

Yesterday

Easy Apply

Contract

50 - 60

Remote or Dallas, Texas

Today

Full-time

Remote

Today

Full-time

Compensation information provided in the description

No location provided

Today

Full-time

USD 152,000.00 per year

Search all similar jobs