> Markdown version of [/jobs/ext/3252538-manager-threat-intelligence](https://www.wearedevelopers.com/jobs/ext/3252538-manager-threat-intelligence). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager, Threat Intelligence - **Company:** KROLL CYBER SECURITY, LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Cyber Security, Databases, Open Source Intelligence, Microsoft PowerPoint, Security Information and Event Management, Mitre Att&ck, Malware, Cyber Threat Analysis, Vulnerability Analysis - **Published:** September 16, 2026 - **Apply:** https://www.builtincolorado.com/job/senior-manager-threat-intelligence/11192680?handler=ApplyRedirect ## About the Role * Bachelor's degree required; Master's degree or similar advanced degree is preferred * 5 years+ of relevant work experience in cyber security and/or threat intelligence * Understand prevailing threats and how to mitigate them with EDR and SIEM. * Aptitude with analyzing threats using malware analysis, sandboxing, static code examination or similar. * Familiarity with the Mitre ATT&CK framework. * In-depth knowledge of the security threat landscape including types of malware, threat actors, their methods of operation and common TTPs. * Experience in relaying complex technical subject matter to non-technical stakeholders. * Proven ability to thrive and respond to frequent demands of multiple constituents, both internal and external, in a high demand, customer-centric environment. * Ability to condense complex information into concise, relevant reporting. * Proficient in a broad variety of investigative methods. * Must be proficient in MS office products, i.e. Word, Excel, PowerPoint. * Ability to handle difficult situations in a productive manner * Ability to multi-task, prioritize, and manage time effectively * Experience working with diverse teams ## Description * Lead and support a variety of global cyber operations and investigations * Keep abreast of cyber market trends and competitive intelligence through research and the culling of resources from our partners * Ability to clearly communicate technical findings to a variety of clients and internal stakeholders * Assist in developing the capabilities of the Threat Intelligence team, creating scalable processes through automation, contributing to malware and threat actor research, and working with the Applied Intelligence group to protect customers. * Be intelligence-led and work with the detection engineering team mitigate the latest threats. * Maintain and contribute to an ever-growing knowledge base of threat intelligence information, write-ups, malware and vulnerability research. * Work with customers to communicate risks, present changes in the threat landscape and identify potential areas of improvement based on real world incidents and reporting. * Be an SME point of contact for internal and customer queries about threats and vulnerabilities. * Automate and triage OSINT intelligence collection to our centralized database of indicators of compromise. * Produce all-source intelligence reports and threat assessments * Build presentations for diverse audiences, ranging from private industry to law enforcement * Perform weekly, quarterly and yearly statistical analysis of trends in cyber analytics * Escalate client issues appropriately that could threaten or enhance opportunity to the Kroll/client relationship * Assist the Head of Threat Intelligence in maturing threat intelligence methodologies ## Related Videos - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)