Threat Intel Lead
Role details
Job location
Tech stack
Job description
Serve as the Lead Threat Intelligence Analyst for South Carolina Critical Infrastructure Cybersecurity (SC CIC), providing senior-level technical leadership, leading strategic threat intelligence projects, and mentoring junior analysts. Partner with executive leadership, government agencies, and private sector stakeholders to address complex cybersecurity challenges and drive the maturity of SC CIC's threat intelligence service through process improvement, tradecraft standardization, and advanced analytic methodologies. Oversee the collection, analysis, and dissemination of cyber threat intelligence to prevent, detect, and mitigate attacks, and promotes cybersecurity awareness. Specific Duties
- Lead collection and advanced analysis of cyber threat data from OSINT, commercial feeds, ISAC/ISAO partnerships, government, and internal telemetry to identify adversary techniques and emerging threats. Set analytic priorities, validate junior analysts' work, and provide strategic insight to strengthen the state's security posture.
- Serve as senior SME on adversary TTPs affecting SC critical infrastructure, delivering timely briefings to analysts and stakeholders. Lead special projects, oversee intelligence gathering for investigations, and represent the SC CIC with local, state, federal, and private sector partners.
- Lead strategic projects to mature SC CIC's threat intelligence service - intelligence requirements, collection plans, tradecraft standards, workflows, tooling, and dissemination - identifying gaps and driving solutions from concept through measurement.
- Mentors junior analysts, review their products for quality and tradecraft, develop training and development plans, and foster a culture of continuous learning.
- Partner with IT, SOC, and Incident Response to hunt threat actor behavior, provide senior analytic support during incidents, and ensure intelligence informs detection and response.
- Provide SC CIC agencies with SIEM management expertise and support to strengthen their security posture and incident response readiness.
- Engage critical infrastructure participants, executive stakeholders, and task force partners to ascertain intelligence needs and deliver reports, briefings, and alerts that enable proactive decision-making and risk mitigation. Provide strategic content direction for SC CIC monthly webinars and hosted events, and deliver select briefings to build community awareness of emerging threats and countermeasures.
Requirements
- Bachelor's degree in a related field OR a minimum of four (4) years of relevant work experience in the areas of information technology, information security, and risk management.
- Expertise in cybersecurity, threat intelligence tradecraft, and intelligence operations.
- A comprehensive understanding of adversary tactics, techniques, and procedures (TTPs) and the treat landscape affecting critical infrastructure.
- Must have the ability to lead intelligence projects, mentor analysts, and develop analytic workflows.
- Strong problem-solving, critical thinking, communication, and leadership skills are essential to this position.
Benefits & conditions
- This is an in-person position based in Columbia, South Carolina.
- Position is on 24/7 call and statewide travel will be required.
South Carolina Law Enforcement Division (SLED) is committed to providing equal employment opportunities to all applicants and does not discriminate on the basis of race, color, religion, sex (including pregnancy, childbirth, or related medical conditions, including, but not limited, to lactation), national origin, age (40 or older), disability or genetic information. SLED offers an exceptional benefits package for FTE positions that includes:
- Health, Dental, Vision, Long Term Disability, and Life Insurance for Employee, Spouse, and Children
- 15 days annual (vacation) leave per year
- 15 days sick leave per year
- 13 paid holidays
- Paid Parental Leave
- State Retirement Plan and Deferred Compensation Programs