Director, Senior Cyber Security Engineer
Role details
Job location
Tech stack
Job description
- Lead the enterprise threat intelligence program, overseeing the end-to-end collection, analysis, and dissemination of actionable intelligence to executive leadership, Technology, Security Operations, and Cybersecurity stakeholders.
- Continuously monitor and analyze the global cyber threat landscape, providing contextualized intelligence on threat actors, TTPs, IOCs, and emerging attack vectors relevant to the organization's risk profile.
- Design, own, and continuously mature intelligence collection, validation, and sharing processes, ensuring SOC and Technology teams receive timely, relevant, and operationally useful intelligence.
- Proactively monitor vendor advisories, security bulletins, and zero-day disclosures, assessing relevance and potential impact across the organisation's technology estate.
- Lead risk-based vulnerability assessments and ensure remediation activities meet defined SLAs.
- Manage vulnerability management standards and operational procedures.
- Collaborate with system owners, application owners, infrastructure teams to assess potential impact, prioritize risk, and drive timely remediation efforts.
- Develop and present executive-level reports highlighting trends, risk exposure, remediation status, and key security metrics.
- Continuously improve threat intelligence ingestion, vulnerability tracking, reporting, and remediation coordination through automation, orchestration, and AI to reduce manual effort and improve response times.
- Manage and administer technologies associated with threat intelligence collection, aggregation, enrichment, and distribution (e.g., TIP platforms, threat feeds, SIEM integrations).
Requirements
As a member of the Information Security team, this role will participate in driving Threat Intelligence and Vulnerability Management initiatives while supporting the implementation and optimization of security technologies across Tradeweb's enterprise technology landscape. The ideal candidate will be knowledgeable in multiple domains of cybersecurity and should be able to design and implement high impacting solutions across the organization. The role will also have an opportunity to work with subject matter experts not only within cybersecurity, but across infrastructure and business/technology teams.
We look to hire people who are comfortable in working with minimal supervision as part of a team that has consistently delivered ground-breaking and innovative solutions in one of the most exciting and fast-moving areas of the of the financial markets We need people who are able to prioritize and can effectively communicate complex issues to non-technical team members. We are seeking a candidate with experience in the financial services industry who can engage effectively with internal teams and external clients, confidently communicate our Vulnerability Management and Threat Intelligence programs, and help align business objectives with our cybersecurity priorities., * Bachelor's degree in IT, Cybersecurity, Computer Science or Engineering
- At least 10 years of experience in cybersecurity engineering or operations role with at least 5 years of hands-on experience in Threat Intelligence and Vulnerability Management.
- Strong experience in threat intelligence lifecycle including collection, analysis, enrichment, correlation, and dissemination of actionable intelligence.
- Good understanding of cyber threat landscape, attacker techniques (MITRE ATT&CK).
- Hands-on experience managing Threat Intelligence Platforms (TIP), threat feeds, OSINT sources, and integration with SIEM and SOAR technologies.
- Experience in vulnerability management programs including vulnerability scanning tools, vendor advisories tracking, risk-based prioritization, and remediation coordination.
- Strong understanding of common vulnerabilities (OWASP Top 10, CVEs, zero-days) and experience working with infrastructure and application teams to drive remediation.
- Experience in automating security workflows using Python, PowerShell, or similar, including API integrations.
- Experience building metrics, and executive-level reports to communicate risk posture, threat trends, and remediation status.
- Strong knowledge of security industry standards and best practices (NIST CSF, MITRE ATT&CK) and ability to align threat intelligence and vulnerability processes to these frameworks.
- Ability to manage multiple initiatives simultaneously, prioritize effectively, and operate with minimal supervision in a fast-paced environment.
- Relevant industry certifications such as CISSP, CISM or equivalent are preferred.