> Markdown version of [/jobs/ext/2270283-social-engineering-and-threat-intelligence-lead](https://www.wearedevelopers.com/jobs/ext/2270283-social-engineering-and-threat-intelligence-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Social Engineering and Threat Intelligence Lead - **Company:** Insight Global - **Location:** Smyrna, GA, United States - **Experience:** Expert - **Salary:** $124,800.0 - $156,000.0 - **Contract:** Contract - **Skills:** Artificial Intelligence, Cyber Security, Computer Telephony Integration, Intrusion Detection and Prevention, Open Source Technology, Open Source Intelligence, Recommender Systems, Phishing, Security Information and Event Management, Mitre Att&ck, Cyber Threat Analysis, Cybercrime, Vulnerability Analysis - **Published:** August 27, 2026 - **Apply:** https://dejobs.org/x/x/D901B24B743B47579E193A38F4C05DDC/job/ ## About the Role · Experience: 7+ years in Cybersecurity, Cyber Threat Intelligence (CTI), Security Awareness, Threat Hunting, or Security Risk Management. This is a senior, experienced-level role - not an entry point. · Threat Intelligence & Frameworks: Hands-on experience with threat intelligence collection lifecycles, tracking adversary TTPs, social engineering trends, and applying the MITRE ATT&CK framework (specifically Initial Access and Reconnaissance tactics). · Technical & Analytical Skills: Experience analyzing threat intelligence feeds, indicator extraction, and leveraging SIEM, Threat Intelligence Platforms (TIPs), or Security Operations Center reporting. · Platform & Vendor Experience: Experience working with a Security Awareness Training (SAT) / phishing simulation platform (e.g., Proofpoint, KnowBe4), including directing a vendor's managed-service team - translating internal priorities and threat intelligence into what the vendor executes, and reviewing their output for quality. Contract negotiation experience is a plus but not required. · Operations Background: Strong operations background - demonstrated experience identifying inefficiencies and leading cross-functional process improvements from idea through implementation. · Communication & Education: Exceptional verbal and written communication skills; demonstrated ability to translate highly complex cyber threats into clear, actionable guidance for non-technical employees, security awareness leads, and senior management. Strong executive presence is required. · Experience directly integrating threat intelligence into enterprise Security Awareness, Phishing Simulation, or Human Risk Management programs. · Familiarity with AI-assisted threat analysis and content creation workflows. · Experience with compliance-driven training programs (e.g. regulatory training requirements). · Demonstrated potential or prior experience mentoring others or serving as a Team Lead. Experience owning a vendor contract or leading contract renewal/negotiation directly. ## Description The Cybersecurity Staff Analyst is the most senior individual-contributor role on the Training and Awareness Team. The person in this seat is expected to operate with minimal oversight, exercise independent and sound judgment to solve ambiguous problems, and serve as a strong and collaborative team member, as well as thought partner to the Manager. The role supports and matures the organization's Human Risk Management Program by applying deep cyber threat intelligence (CTI) expertise. This person independently collects, analyzes, and translates threat actor tactics, techniques, and procedures (TTPs), social engineering trends, and MITRE ATT&CK-mapped behavior into timely, actionable input that directly informs Simulation scenario design and Awareness campaign content. Process and operational improvement, training advisory work, and team mentoring are responsibilities this person grows into within roughly the first six months, although demonstrated experience is required upon hire. Key Responsibilities Threat Intelligence & Landscape Analysis · Collect, evaluate, and track cyber threat intelligence from open-source (OSINT), commercial, and technical channels; analyze threat actor behavior and social engineering TTPs (e.g., spear-phishing, pretexting, MFA fatigue, vishing, AI-driven impersonation, deepfakes) mapped to the MITRE ATT&CK framework. · Own applied threat intelligence for the human risk program internally, translating raw intelligence into simulation themes, awareness content angles, and training-content recommendations. · Deliver a recurring threat-landscape briefings to team members, highlighting emerging risks relevant to associates and contractors. Vendor & Platform Management (ZenGuide/Proofpoint) · Serve as the primary day-to-day point of contact for teams dedicated simulation platform managed-service resource - directing which social engineering simulations run and what training gets delivered based on current threat intelligence, and reviewing their reporting for quality and relevance before it's used. · Coordinate technical support requests and roadmap/strategy sessions with the simulation vendor, looping in the Manager for anything requiring a contract or investment decision. · Maintain deep, current working knowledge of the platform roadmap (FY26/FY27), proactively flagging milestones, new capabilities, and relevant risks or opportunities to the Manager. · Recommend platform enhancements or complementary tools (e.g., deepfake simulation capability) based on threat intelligence findings, for the Manager's evaluation. Simulation & Awareness Integration · Design realistic, threat-informed social engineering simulation scenarios based on observed active adversary behavior. · Translate threat intelligence into timely, actionable content recommendations for both broad and targeted Awareness campaigns, threat-based content, and seasonal/high-risk-period messaging. Cross-Pillar Thought Partnership · Serve as an informal technical resource and thought partner for analysts across Training, Simulation, and Awareness pillars when cross-pillar input is useful. Stakeholder Collaboration & Reporting · Partner with Security Operations (SOC), CTI, Incident Response, Threat Detection, Communications, and other stakeholder teams to align threat intelligence and messaging with real-time enterprise risk. · Deliver threat-informed security awareness briefings, trend metrics, risk insights, and KPI's to cybersecurity leadership. Growth Responsibilities (Expected by ~6 Months in Role) · Process & Operational Excellence: Keep an eye out for ways the team can work better - process, tools, handoffs, documentation - and take the lead on making those improvements happen, partnering with the right people to get it done. Document changes so improvements stick and keep the Manager posted on what is being improved and why. · Training Advisory: Advise the Training pillar on emerging threats and recommend where compliance and role-based training content should evolve to address current TTPs (e.g., AI-driven impersonation, deepfakes, executive/high-privilege targeting). Provide input and quality review; the Training pillar owns content development, delivery, and Contractor Compliance execution directly. · Team Mentorship: Informally mentor Analyst I/II and Sr. Analyst team members across Training, Simulation, and Awareness, raising the team's technical and analytical rigor. · Thought Leadership: Serve as a strategic thought partner to the Cybersecurity Manager, contributing to prioritization, problem-solving, and program direction. · Team Leadership: Serve as acting manager on an as needed basis, providing interim/short term leadership and direction to the team when the manager is unavailable. ## Related Videos - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere)