> Markdown version of [/jobs/ext/2312380-threat-intelligence-lead](https://www.wearedevelopers.com/jobs/ext/2312380-threat-intelligence-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Threat Intelligence Lead - **Company:** Motion Recruitment - **Location:** Coppell, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Intrusion Detection and Prevention, Red Team (Cyber Security), Security Information and Event Management, Software Vulnerability Management, Software Security, Mitre Att&ck, Cyber Threat Analysis, Information Technology, Purple Team (Cyber Security) - **Published:** August 30, 2026 - **Apply:** https://www.disabledperson.com/jobs/74637856-threat-intelligence-lead ## About the Role Years of Experience6+ years of experience in threat intelligence, security operations, or incident response, including prior experience mentoring or leading analysts, * Deep working knowledge of MITRE ATT&CK, the intelligence cycle, and structured analytic techniques * Demonstrated experience producing and delivering intelligence to executive and board-level audiences * Experience directing threat intelligence platform and vendor strategy, including feed evaluation and management * Experience partnering with detection engineering, incident response, and vulnerability management on intelligence-driven prioritization * Strong people-leadership skills, including hiring, coaching, and performance management of analysts * Excellent written and verbal communication skills, with the ability to translate technical findings into business risk * Sound analytic judgment, including the ability to state and defend confidence levels under scrutiny Education & Certification Requirements * Bachelor's degree in Cybersecurity, Computer Science, Intelligence Studies, or related field, or equivalent experience ## Description Our Irving, TX Client is seeking a Threat Intelligence Lead for a 12+ Month fully onsite contract opportunity., * Set intelligence collection priorities and requirements based on organizational risk, industry targeting, and stakeholder needs * Own the threat intelligence roadmap, including program maturity, tooling, staffing, and process improvements * Establish and enforce standards for finished intelligence products, source reliability, and confidence-level reporting * Define and track program KPIs, such as report timeliness, actionability, detection coverage, and stakeholder satisfaction Manage and develop the analyst team * Hire, coach, and manage threat intelligence analysts, including workload prioritization and quality review of their work * Set individual and team goals, conduct performance reviews, and build career development plans for analysts * Run the team's intelligence cycle end to end: tasking, collection, analysis, production, and dissemination * Build team proficiency in structured analytic techniques, adversary tracking, and the MITRE ATT&CK framework Deliver strategic and operational intelligence * Personally author and quality-check high-stakes intelligence products, including executive and board-level briefings * Lead intelligence support during major incidents, providing attribution, actor intent, and containment guidance to IR leadership * Direct the organization's threat landscape assessment, including sector-specific and geopolitical risk * Prioritize vulnerability remediation guidance in partnership with Vulnerability Management using exploitation and actor-interest data Own detection enablement and adversary emulation * Partner with detection engineering to convert intelligence into SIEM/EDR detection logic and hunting programs * Direct threat-informed red team, purple team, and adversary emulation exercises using current TTPs * Review and approve detection and hunting priorities to ensure they reflect the current threat landscape Vendor, platform, and cross-functional leadership * Own the threat intelligence platform (TIP) strategy, feed and vendor selection, licensing, and renewal decisions * Build and maintain relationships with industry ISACs/ISAOs, law enforcement, and peer intelligence leads for information sharing * Represent threat intelligence in leadership, risk, and governance forums, including budget and staffing discussions * Partner with Security Architecture, IR, Vulnerability Management, and Product Security leads to align intelligence with broader security strategy Expectations * Set the team's quarterly collection priorities based on a shift in the organization's threat landscape or business footprint * Lead intelligence support for a major incident, briefing executive leadership on likely actor, objectives, and containment status * Negotiate and onboard a new commercial threat intelligence feed, defining success metrics before renewal * Review and elevate an analyst's actor profile before it goes to the CISO and board * Direct a purple team exercise built around a threat actor actively targeting the organization's sector ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) ## Related Articles - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)