> Markdown version of [/jobs/ext/2014821-lead-tactical-intelligence-threat-informed-defense](https://www.wearedevelopers.com/jobs/ext/2014821-lead-tactical-intelligence-threat-informed-defense). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead, Tactical Intelligence & Threat-Informed Defense - **Company:** Prudential Financial, Inc. - **Location:** Newark, NJ, United States - **Experience:** Expert - **Salary:** $123,700.0 - $204,100.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Data Analysis, Software as a Service, Cloud Computing Security, Cyber Security, Data Visualization, Query Languages, Statistical Hypothesis Testing, Intelligence Analysis, Intrusion Detection and Prevention, Python (Programming Language), Pattern Recognition, Windows PowerShell, Power BI, Security Information and Event Management, Tableau (Software), Enterprise Software Applications, Mitre Att&ck, Cybercrime, Cyber Warfare - **Published:** August 10, 2026 - **Apply:** https://pru.wd5.myworkdayjobs.com/Careers/job/Newark-NJ-USA/Lead--Tactical-Intelligence---Threat-Informed-Defense_R-124741-1 ## About the Role * Strong experience in Cyber Threat Intelligence, Threat Hunting, Security Operations, Incident Response, or related defensive disciplines. * Deep understanding of adversary tactics, techniques, and procedures and how attacks are executed across modern technology environments. * Experience applying MITRE ATT&CK, ATLAS, D3FEND, and related frameworks to intelligence and defensive use cases. * Experience analyzing attack paths and understanding adversary behavior across identity, cloud, endpoint, SaaS, and enterprise environments. * Ability to translate intelligence findings into actionable defensive recommendations and technical guidance. * Strong understanding of detection engineering principles and threat hunting methodologies. * Experience assessing vulnerabilities, exposures, and security controls through an adversarial lens. * Ability to conduct structured intelligence analysis using methodologies such as hypothesis testing, pattern analysis, and intelligence-driven risk assessment. * Excellent written and verbal communication skills, with the ability to explain complex technical risks to diverse audiences. * Experience mentoring analysts and improving analytical quality across intelligence programs. * Strong stakeholder management and partnership skills with the ability to influence defensive priorities across multiple security functions. * Experience evaluating and applying AI-driven capabilities, including MCP-enabled tools and agents, to improve intelligence operations, analytical efficiency, and defensive outcomes., * Familiarity with EDR technologies and telemetry analysis, including experience with query languages used to identify suspicious behaviors and attacker tradecraft. * Familiarity with SIEM platforms and security telemetry analysis. * Experience with data visualization tools (e.g., Power BI, Tableau). * GIAC certifications (GCTI, GSOC, GREM, GPEN, GCFA, GCFE). * Cloud security certifications (AWS Security, AZ-500). * Experience leveraging Python and PowerShell to support threat intelligence research, data analysis, and process automation. ## Description As the Lead for Tactical Intelligence & Threat-Informed Defense, you will help establish and mature a capability focused on understanding how adversaries operate and translating that knowledge into actionable defensive outcomes. You will analyze adversary tactics, techniques, procedures (TTPs), attack paths, and tradecraft to identify how threats may impact the organization and where defensive improvements are needed. Using frameworks such as MITRE ATT&CK, ATLAS, and the Insider Threat Matrix, you will assess adversary behaviors and provide intelligence-driven recommendations that strengthen detection, prevention, response, and resilience. You will work closely with Cyber Defense, Technology Owners, and business stakeholders to improve the organization's ability to detect and mitigate real-world threats. You will produce intelligence products that help stakeholders understand what threats are relevant, how attacks are executed, where defensive gaps exist, and what actions should be prioritized. Your work will enable security teams to make informed decisions based on adversary activity rather than generic risk assumptions. As a lead, you will mentor analysts, establish analytical standards and methodologies, and help mature the organization's Threat-Informed Defense capability through continuous collaboration with defensive stakeholders. Here is What You Can Expect on a Typical Day * Analyze adversary tactics, techniques, and procedures (TTPs) to understand how attacks are executed and how threat activity is evolving. * Assess attack paths and exposures across identity, cloud, endpoint, SaaS, and other enterprise technologies. * Map adversary behavior to security controls, identify defensive gaps, and recommend improvements. * Translate intelligence insights into actionable guidance that strengthens detection, threat hunting, and defensive capabilities. * Provide context on vulnerabilities, exposures, and adversary exploitation trends to support risk-based prioritization. * Produce intelligence products such as threat assessments, TTP analyses, attack path reviews, and briefings. * Brief stakeholders and translate complex intelligence into actionable recommendations. * Partner with Information Security, Technology owners, and Business teams to strengthen intelligence-informed defensive strategies and decision-making. * Incorporate lessons learned from incidents and operational activities to continuously improve intelligence analysis and recommendations. * Define and track metrics that demonstrate the effectiveness and impact of Threat-Informed Defense activities. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Beyond Dashboards: Fixing Text-to-SQL with Semantic RAG](https://www.wearedevelopers.com/videos/2036-beyond-dashboards-fixing-text-to-sql-with-semantic-rag) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [REST, GraphQL, gRPC, and more: A comparison of modern API styles](https://www.wearedevelopers.com/videos/100247-rest-graphql-grpc-and-more-a-comparison-of-modern-api-styles) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production)