Unknown Company

Senior Director, Cyber Threat Intellignece

northern, ky • Posted 2 weeks ago
Onsite Full Time Human Resources

Senior Director, Cyber Threat Intellignece

Cybersecurity

Cybersecurity | United States |

Share This

As the leading independent provider of risk and financial advisory solutions, Kroll leverages our unique insights, data, and technology to help clients stay ahead of complex cyber threats. Our Cyber Risk team partners with organizations around the world to deliver intelligence-driven security solutions that enable informed decision-making and proactive risk management.

We are seeking an experienced Threat Intelligence Platform Engineer to join our Cyber Threat Intelligence team. This role is ideal for a security professional who is passionate about engineering scalable threat intelligence capabilities through automation, data integration, and platform management.

The Intelligence Platform Engineer is responsible for designing, building, and maintaining the technology, automation, and data infrastructure that powers cyber threat intelligence operations. This role serves as the bridge between intelligence analysis, threat research, data engineering, and security operations by developing scalable solutions that automate the collection, enrichment, normalization, correlation, and dissemination of cyber threat intelligence.

The successful candidate will identify and integrate intelligence data sources from commercial providers, open-source intelligence (OSINT), internal security telemetry, dark web collections, government feeds, and industry-sharing communities. They will leverage automation, APIs, machine learning, and data engineering techniques to transform raw intelligence into actionable insights that support threat detection, incident response, vulnerability management, executive reporting, and strategic decision-making. This aligns with internal descriptions emphasizing ownership of a threat intelligence platform, automation, and multi-source intelligence integration.

Working closely with Threat Intelligence Analysts, Incident Responders, Detection Engineers, and Security Operations teams, the successful candidate will improve the organization’s ability to identify emerging threats through intelligent automation and data engineering.

Key Responsibilities:

Administer, maintain, and optimize Kroll’s Threat Intelligence Platform.

Design and develop automated workflows for collecting, enriching, correlating, and distributing cyber threat intelligence.

Build scalable automation to support dark web monitoring, credential exposure tracking, threat actor activity, and emerging threat detection.

Develop and maintain integrations with commercial threat intelligence providers, OSINT sources, government intelligence feeds, ISACs, and internal security platforms.

Design ETL pipelines to ingest, normalize, and organize structured and unstructured threat intelligence datasets.

Correlate indicators of compromise (IOCs), threat actors, malware families, vulnerabilities, and campaigns using industry standards such as STIX/TAXII and the MITRE ATT&CK Framework.

Develop dashboards, reporting, and visualizations that improve analyst efficiency and provide actionable intelligence to stakeholders.

Evaluate emerging technologies, intelligence sources, and AI-driven capabilities to continuously improve Kroll's threat intelligence operations.

Ensure data quality, governance, and security across all intelligence repositories.

Required Qualifications:

Education

Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related discipline, or equivalent professional experience.

Experience

Minimum of five (5) years of experience in cybersecurity, cyber threat intelligence, or security engineering.

Experience administering a Threat Intelligence Platform (EclecticIQ strongly preferred).

Experience integrating APIs and external data sources.

Hands-on experience with cyber threat intelligence workflows and intelligence lifecycle management.

Technical Qualifications

Experience working Threat Intelligence Platforms

STIX 2.x and TAXII

MITRE ATT&CK Framework

MISP (preferred)

Threat actor tracking

Campaign analysis

TTP analysis

Programming & Automation

Required:

Experience with:

REST APIs

Webhooks

Requests

BeautifulSoup

Selenium or Playwright

SQLAlchemy

Preferred:

PowerShell

Go

Experience with:

SQL

Elasticsearch/OpenSearch

MongoDB (preferred)

Ability to:

Build ETL pipelines

Normalize structured and unstructured datasets

Correlate multiple intelligence sources

Experience collecting and automating intelligence from:

Underground forums

Telegram channels

Credential leak repositories

Marketplace monitoring

Open-source intelligence sources

Experience with AWS services including:

Lambda

ECS

S3

IAM

EventBridge

Step Functions

Secrets Manager

Security Platforms

Experience integrating with technologies such as:

Splunk

CrowdStrike Falcon

VirusTotal

Shodan

Censys

Preferred Qualifications

Experience developing AI-assisted threat intelligence workflows.

Familiarity with Large Language Models (LLMs) for intelligence summarization and analysis.

Experience with graph databases such as Neo4j.

Knowledge of Retrieval-Augmented Generation (RAG) architectures.

Experience building knowledge graphs.

Familiarity with DevOps practices,

#J-18808-Ljbffr

Senior Director, Cyber Threat Intellignece in northern at Unknown Company

This position is listed as full time and onsite.

Back to Job Search