Threat Intelligence Lead

Motion Recruitment
Coppell, TX, United States
4 days ago
Apply on www.disabledperson.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Cyber Security Intrusion Detection and Prevention Red Team (Cyber Security) Security Information and Event Management Software Vulnerability Management Software Security Mitre Att&ck Cyber Threat Analysis Information Technology Purple Team (Cyber Security)

Job description

Our Irving, TX Client is seeking a Threat Intelligence Lead for a 12+ Month fully onsite contract opportunity., * Set intelligence collection priorities and requirements based on organizational risk, industry targeting, and stakeholder needs

  • Own the threat intelligence roadmap, including program maturity, tooling, staffing, and process improvements
  • Establish and enforce standards for finished intelligence products, source reliability, and confidence-level reporting
  • Define and track program KPIs, such as report timeliness, actionability, detection coverage, and stakeholder satisfaction

Manage and develop the analyst team

  • Hire, coach, and manage threat intelligence analysts, including workload prioritization and quality review of their work
  • Set individual and team goals, conduct performance reviews, and build career development plans for analysts
  • Run the team’s intelligence cycle end to end: tasking, collection, analysis, production, and dissemination
  • Build team proficiency in structured analytic techniques, adversary tracking, and the MITRE ATT&CK framework

Deliver strategic and operational intelligence

  • Personally author and quality-check high-stakes intelligence products, including executive and board-level briefings
  • Lead intelligence support during major incidents, providing attribution, actor intent, and containment guidance to IR leadership
  • Direct the organization’s threat landscape assessment, including sector-specific and geopolitical risk
  • Prioritize vulnerability remediation guidance in partnership with Vulnerability Management using exploitation and actor-interest data

Own detection enablement and adversary emulation

  • Partner with detection engineering to convert intelligence into SIEM/EDR detection logic and hunting programs
  • Direct threat-informed red team, purple team, and adversary emulation exercises using current TTPs
  • Review and approve detection and hunting priorities to ensure they reflect the current threat landscape

Vendor, platform, and cross-functional leadership

  • Own the threat intelligence platform (TIP) strategy, feed and vendor selection, licensing, and renewal decisions
  • Build and maintain relationships with industry ISACs/ISAOs, law enforcement, and peer intelligence leads for information sharing
  • Represent threat intelligence in leadership, risk, and governance forums, including budget and staffing discussions
  • Partner with Security Architecture, IR, Vulnerability Management, and Product Security leads to align intelligence with broader security strategy

Expectations

  • Set the team’s quarterly collection priorities based on a shift in the organization’s threat landscape or business footprint
  • Lead intelligence support for a major incident, briefing executive leadership on likely actor, objectives, and containment status
  • Negotiate and onboard a new commercial threat intelligence feed, defining success metrics before renewal
  • Review and elevate an analyst’s actor profile before it goes to the CISO and board
  • Direct a purple team exercise built around a threat actor actively targeting the organization’s sector

Requirements

Years of Experience6+ years of experience in threat intelligence, security operations, or incident response, including prior experience mentoring or leading analysts, * Deep working knowledge of MITRE ATT&CK, the intelligence cycle, and structured analytic techniques

  • Demonstrated experience producing and delivering intelligence to executive and board-level audiences
  • Experience directing threat intelligence platform and vendor strategy, including feed evaluation and management
  • Experience partnering with detection engineering, incident response, and vulnerability management on intelligence-driven prioritization
  • Strong people-leadership skills, including hiring, coaching, and performance management of analysts
  • Excellent written and verbal communication skills, with the ability to translate technical findings into business risk
  • Sound analytic judgment, including the ability to state and defend confidence levels under scrutiny

Education & Certification Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Intelligence Studies, or related field, or equivalent experience

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.disabledperson.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 ¡ World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ World Congress 2022

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber ¡ World Congress 2026 Europe

1:32 min

Pairing with teams for continuous threat modeling

Nazneen Rupawalla ¡ World Congress 2022

3:55 min

Establishing blameless dialogue surrounding critical software security vulnerabilities

Chris Heilmann +2 ¡ LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger ¡ LIVE

Videos

See all

Related articles

See all