Senior Director, Cyber Threat Intellignece
Cybersecurity
Cybersecurity | United States |
Share This
As the leading independent provider of risk and financial advisory solutions, Kroll leverages our unique insights, data, and technology to help clients stay ahead of complex cyber threats. Our Cyber Risk team partners with organizations around the world to deliver intelligence-driven security solutions that enable informed decision-making and proactive risk management.
We are seeking an experienced Threat Intelligence Platform Engineer to join our Cyber Threat Intelligence team. This role is ideal for a security professional who is passionate about engineering scalable threat intelligence capabilities through automation, data integration, and platform management.
The Intelligence Platform Engineer is responsible for designing, building, and maintaining the technology, automation, and data infrastructure that powers cyber threat intelligence operations. This role serves as the bridge between intelligence analysis, threat research, data engineering, and security operations by developing scalable solutions that automate the collection, enrichment, normalization, correlation, and dissemination of cyber threat intelligence.
The successful candidate will identify and integrate intelligence data sources from commercial providers, open-source intelligence (OSINT), internal security telemetry, dark web collections, government feeds, and industry-sharing communities. They will leverage automation, APIs, machine learning, and data engineering techniques to transform raw intelligence into actionable insights that support threat detection, incident response, vulnerability management, executive reporting, and strategic decision-making. This aligns with internal descriptions emphasizing ownership of a threat intelligence platform, automation, and multi-source intelligence integration.
Working closely with Threat Intelligence Analysts, Incident Responders, Detection Engineers, and Security Operations teams, the successful candidate will improve the organization’s ability to identify emerging threats through intelligent automation and data engineering.
Key Responsibilities:
Administer, maintain, and optimize Kroll’s Threat Intelligence Platform.
Design and develop automated workflows for collecting, enriching, correlating, and distributing cyber threat intelligence.
Build scalable automation to support dark web monitoring, credential exposure tracking, threat actor activity, and emerging threat detection.
Develop and maintain integrations with commercial threat intelligence providers, OSINT sources, government intelligence feeds, ISACs, and internal security platforms.
Design ETL pipelines to ingest, normalize, and organize structured and unstructured threat intelligence datasets.
Correlate indicators of compromise (IOCs), threat actors, malware families, vulnerabilities, and campaigns using industry standards such as STIX/TAXII and the MITRE ATT&CK Framework.
Develop dashboards, reporting, and visualizations that improve analyst efficiency and provide actionable intelligence to stakeholders.
Evaluate emerging technologies, intelligence sources, and AI-driven capabilities to continuously improve Kroll's threat intelligence operations.
Ensure data quality, governance, and security across all intelligence repositories.
Required Qualifications:
Education
Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related discipline, or equivalent professional experience.
Experience
Minimum of five (5) years of experience in cybersecurity, cyber threat intelligence, or security engineering.
Experience administering a Threat Intelligence Platform (EclecticIQ strongly preferred).
Experience integrating APIs and external data sources.
Hands-on experience with cyber threat intelligence workflows and intelligence lifecycle management.
Technical Qualifications
Experience working Threat Intelligence Platforms
STIX 2.x and TAXII
MITRE ATT&CK Framework
MISP (preferred)
Threat actor tracking
Campaign analysis
TTP analysis
Programming & Automation
Required:
Experience with:
REST APIs
Webhooks
Requests
BeautifulSoup
Selenium or Playwright
SQLAlchemy
Preferred:
PowerShell
Go
Experience with:
SQL
Elasticsearch/OpenSearch
MongoDB (preferred)
Ability to:
Build ETL pipelines
Normalize structured and unstructured datasets
Correlate multiple intelligence sources
Experience collecting and automating intelligence from:
Underground forums
Telegram channels
Credential leak repositories
Marketplace monitoring
Open-source intelligence sources
Experience with AWS services including:
Lambda
ECS
S3
IAM
EventBridge
Step Functions
Secrets Manager
Security Platforms
Experience integrating with technologies such as:
Splunk
CrowdStrike Falcon
VirusTotal
Shodan
Censys
Preferred Qualifications
Experience developing AI-assisted threat intelligence workflows.
Familiarity with Large Language Models (LLMs) for intelligence summarization and analysis.
Experience with graph databases such as Neo4j.
Knowledge of Retrieval-Augmented Generation (RAG) architectures.
Experience building knowledge graphs.
Familiarity with DevOps practices,
#J-18808-LjbffrSenior Director, Cyber Threat Intellignece in northern at Unknown Company
This position is listed as full time and onsite.