Lead, Tactical Intelligence & Threat-Informed Defense
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+9 more
Job description
As the Lead for Tactical Intelligence & Threat-Informed Defense, you will help establish and mature a capability focused on understanding how adversaries operate and translating that knowledge into actionable defensive outcomes. You will analyze adversary tactics, techniques, procedures (TTPs), attack paths, and tradecraft to identify how threats may impact the organization and where defensive improvements are needed.
Using frameworks such as MITRE ATT&CK, ATLAS, and the Insider Threat Matrix, you will assess adversary behaviors and provide intelligence-driven recommendations that strengthen detection, prevention, response, and resilience. You will work closely with Cyber Defense, Technology Owners, and business stakeholders to improve the organization’s ability to detect and mitigate real-world threats.
You will produce intelligence products that help stakeholders understand what threats are relevant, how attacks are executed, where defensive gaps exist, and what actions should be prioritized. Your work will enable security teams to make informed decisions based on adversary activity rather than generic risk assumptions.
As a lead, you will mentor analysts, establish analytical standards and methodologies, and help mature the organization’s Threat-Informed Defense capability through continuous collaboration with defensive stakeholders.
Here is What You Can Expect on a Typical Day
- Analyze adversary tactics, techniques, and procedures (TTPs) to understand how attacks are executed and how threat activity is evolving.
- Assess attack paths and exposures across identity, cloud, endpoint, SaaS, and other enterprise technologies.
- Map adversary behavior to security controls, identify defensive gaps, and recommend improvements.
- Translate intelligence insights into actionable guidance that strengthens detection, threat hunting, and defensive capabilities.
- Provide context on vulnerabilities, exposures, and adversary exploitation trends to support risk-based prioritization.
- Produce intelligence products such as threat assessments, TTP analyses, attack path reviews, and briefings.
- Brief stakeholders and translate complex intelligence into actionable recommendations.
- Partner with Information Security, Technology owners, and Business teams to strengthen intelligence-informed defensive strategies and decision-making.
- Incorporate lessons learned from incidents and operational activities to continuously improve intelligence analysis and recommendations.
- Define and track metrics that demonstrate the effectiveness and impact of Threat-Informed Defense activities.
Requirements
- Strong experience in Cyber Threat Intelligence, Threat Hunting, Security Operations, Incident Response, or related defensive disciplines.
- Deep understanding of adversary tactics, techniques, and procedures and how attacks are executed across modern technology environments.
- Experience applying MITRE ATT&CK, ATLAS, D3FEND, and related frameworks to intelligence and defensive use cases.
- Experience analyzing attack paths and understanding adversary behavior across identity, cloud, endpoint, SaaS, and enterprise environments.
- Ability to translate intelligence findings into actionable defensive recommendations and technical guidance.
- Strong understanding of detection engineering principles and threat hunting methodologies.
- Experience assessing vulnerabilities, exposures, and security controls through an adversarial lens.
- Ability to conduct structured intelligence analysis using methodologies such as hypothesis testing, pattern analysis, and intelligence-driven risk assessment.
- Excellent written and verbal communication skills, with the ability to explain complex technical risks to diverse audiences.
- Experience mentoring analysts and improving analytical quality across intelligence programs.
- Strong stakeholder management and partnership skills with the ability to influence defensive priorities across multiple security functions.
- Experience evaluating and applying AI-driven capabilities, including MCP-enabled tools and agents, to improve intelligence operations, analytical efficiency, and defensive outcomes., * Familiarity with EDR technologies and telemetry analysis, including experience with query languages used to identify suspicious behaviors and attacker tradecraft.
- Familiarity with SIEM platforms and security telemetry analysis.
- Experience with data visualization tools (e.g., Power BI, Tableau).
- GIAC certifications (GCTI, GSOC, GREM, GPEN, GCFA, GCFE).
- Cloud security certifications (AWS Security, AZ-500).
- Experience leveraging Python and PowerShell to support threat intelligence research, data analysis, and process automation.
Benefits & conditions
Prudential is required by state specific laws to include the salary range for this role when hiring a resident in applicable locations. The salary range for this role is from $123,700.00 to $204,100.00. Specific pricing for the role may vary within the above range based on many factors including geographic location, candidate experience, and skills.
- Market competitive base salaries, with a yearly bonus potential at every level.
- Medical, dental, vision, life insurance, disability insurance, Paid Time Off (PTO), and leave of absences, such as parental and military leave.
- 401(k) plan with company match (up to 4%).
- Company-funded pension plan.
- Wellness Programs including up to $1,600 a year for reimbursement of items purchased to support personal wellbeing needs.
- Work/Life Resources to help support topics such as parenting, housing, senior care, finances, pets, legal matters, education, emotional and mental health, and career development.
- Education Benefit to help finance traditional college enrollment toward obtaining an approved degree and many accredited certificate programs.
- Employee Stock Purchase Plan: Shares can be purchased at 85% of the lower of two prices (Beginning or End of the purchase period).
| Eligibility to participate in a discretionary annual incentive program is subject to the rules governing the program, whereby an award, if any, depends on various factors including, without limitation, individual and organizational performance. To find out more about our Total Rewards package, visit Work Life Balance | Prudential Careers. Some of the above benefits may not apply to part-time employees scheduled to work less than 20 hours per week. |
Prudential Financial, Inc. of the United States is not affiliated with Prudential plc. which is headquartered in the United Kingdom.
About the company
Are you interested in building capabilities that enable the organization with innovation, speed, agility, scalability, and efficiency? The Global Technology Operations team takes great pride in our culture where digital transformation is built into our DNA! When you join our organization at Prudential, you’ll unlock an exciting and impactful career - all while growing your skills and advancing your profession at one of the world’s leading financial services institutions.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on pru.wd5.myworkdayjobs.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Everything a Developer Needs to Know About MCP with Neo4j
Dev Digest 134 - Where pixels sing?
Stephan Gillich - Bringing AI Everywhere
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.