As the leading independent provider of risk and financial advisory solutions, Kroll leverages our unique insights, data, and technology to help clients stay ahead of complex cyber threats. Our Cyber Risk team partners with organizations around the world to deliver intelligence-driven security solutions that enable informed decision-making and proactive risk management.
We are seeking an experienced Threat Intelligence Platform Engineer to join our Cyber Threat Intelligence team. This role is ideal for a security professional who is passionate about engineering scalable threat intelligence capabilities through automation, data integration, and platform management.
The Intelligence Platform Engineer is responsible for designing, building, and maintaining the technology, automation, and data infrastructure that powers cyber threat intelligence operations. This role serves as the bridge between intelligence analysis, threat research, data engineering, and security operations by developing scalable solutions that automate the collection, enrichment, normalization, correlation, and dissemination of cyber threat intelligence.
The successful candidate will identify and integrate intelligence data sources from commercial providers, open-source intelligence (OSINT), internal security telemetry, dark web collections, government feeds, and industry-sharing communities. They will leverage automation, APIs, machine learning, and data engineering techniques to transform raw intelligence into actionable insights that support threat detection, incident response, vulnerability management, executive reporting, and strategic decision-making. This aligns with internal descriptions emphasizing ownership of a threat intelligence platform, automation, and multi-source intelligence integration.
Working closely with Threat Intelligence Analysts, Incident Responders, Detection Engineers, and Security Operations teams, the successful candidate will improve the organization's ability to identify emerging threats through intelligent automation and data engineering.
Key Responsibilities:
Administer, maintain, and optimize Kroll’s Threat Intelligence Platform.
Design and develop automated workflows for collecting, enriching, correlating, and distributing cyber threat intelligence.
Build scalable automation to support dark web monitoring, credential exposure tracking, threat actor activity, and emerging threat detection.
Develop and maintain integrations with commercial threat intelligence providers, OSINT sources, government intelligence feeds, ISACs, and internal security platforms.
Design ETL pipelines to ingest, normalize, and organize structured and unstructured threat intelligence datasets.
Correlate indicators of compromise (IOCs), threat actors, malware families, vulnerabilities, and campaigns using industry standards such as STIX/TAXII and the MITRE ATT&CK Framework.
Develop dashboards, reporting, and visualizations that improve analyst efficiency and provide actionable intelligence to stakeholders.
Evaluate emerging technologies, intelligence sources, and AI-driven capabilities to continuously improve Kroll's threat intelligence operations.
Ensure data quality, governance, and security across all intelligence repositories.
Required Qualifications:
Education
Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related discipline, or equivalent professional experience.
Experience
Minimum of five (5) years of experience in cybersecurity, cyber threat intelligence, or security engineering.
Experience administering a Threat Intelligence Platform (EclecticIQ strongly preferred).
Proven experience designing automation solutions using Python.
Experience integrating APIs and external data sources.
Hands-on experience with cyber threat intelligence workflows and intelligence lifecycle management.
Technical Qualifications
Threat Intelligence
Experience working Threat Intelligence Platforms
STIX 2.x and TAXII
MITRE ATT&CK Framework
MISP (preferred)
IOC lifecycle management
Threat actor tracking
Campaign analysis
Malware intelligence
TTP analysis
Programming & Automation
Required:
Advanced Python development
Experience with:
REST APIs
Webhooks
Async programming
Requests
Pandas
BeautifulSoup
Selenium or Playwright
SQLAlchemy
Preferred:
JavaScript
PowerShell
Go
Data Engineering
Experience with:
SQL
PostgreSQL
Elasticsearch/OpenSearch
MongoDB (preferred)
Ability to:
Build ETL pipelines
Normalize structured and unstructured datasets
Correlate multiple intelligence sources
Design scalable data ingestion workflows
Dark Web Intelligence
Experience collecting and automating intelligence from:
Underground forums
Telegram channels
Credential leak repositories
Marketplace monitoring
Paste sites
Open-source intelligence sources
Cloud & Infrastructure
Experience with AWS services including:
Lambda
ECS
S3
IAM
EventBridge
Step Functions
Secrets Manager
Security Platforms
Experience integrating with technologies such as:
Splunk
CrowdStrike Falcon
VirusTotal
GreyNoise
Shodan
Censys
Preferred Qualifications
Experience developing AI-assisted threat intelligence workflows.
Familiarity with Large Language Models (LLMs) for intelligence summarization and analysis.
Experience with graph databases such as Neo4j.
Knowledge of Retrieval-Augmented Generation (RAG) architectures.
Experience building knowledge graphs.
Familiarity with DevOps practices, Docker, Kubernetes, and CI/CD pipelines.
Preferred Certifications
GIAC Cyber Threat Intelligence (GCTI)
SANS FOR578 Cyber Threat Intelligence
CISSP
AWS Certified Security – Specialty
AWS Certified Developer – Associate
Security+
GSEC
What Success Looks Like
The successful candidate will:
Build scalable automation that significantly reduces manual intelligence collection and analysis.
Improve analyst productivity through efficient data integration and workflow automation.
Expand Kroll's ability to monitor the dark web and emerging threat landscape.
Deliver actionable, high-quality intelligence through a modern, integrated Threat Intelligence Platform.
Help position Kroll as an industry leader in intelligence-driven cybersecurity services through continuous innovation and operational excellence.
Why Join Kroll?
At Kroll, you'll work alongside some of the industry's most respected cyber professionals, solving complex challenges for organizations around the world. We foster a collaborative, innovation-driven environment where your expertise directly contributes to protecting clients from evolving cyber threats. You'll have the opportunity to work with cutting-edge technologies, influence the evolution of our threat intelligence capabilities, and make a meaningful impact across our global Cyber Risk practice.
Your recruiter will be happy to walk you through your U.S.-specific benefits, which include:
Healthcare Coverage: Comprehensive medical, dental, and vision plans.
Time Off and Leave Policies: Generous paid time off (PTO), paid company holidays, generous parental and family leave.
Protective Insurances: Life insurance, short- and long-term disability coverage, and accident protection.
Compensation and Rewards: Competitive salary structures, performance-based incentives, and merit-based compensation reviews.
Retirement Plans: 401(k) plans with company matching.
Please note that benefits may vary by region, department and role. We encourage you to speak with your recruiter to learn more about the specific benefits available for your position.
About Kroll
Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll.
In order to be considered for a position, you must formally apply via careers.kroll.com.
We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability.
The current salary range for this position is $200,000 to $300,000
#LI-CN1
#LI-Remote
Skills Required
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, a related discipline, or equivalent professional experience
- At least five years of experience in cybersecurity, cyber threat intelligence, or security engineering
- Experience administering a Threat Intelligence Platform; EclecticIQ strongly preferred
- Advanced Python development and automation solution design
- Experience integrating REST APIs and external data sources
- Hands-on experience with cyber threat intelligence workflows and intelligence lifecycle management
- Experience with Threat Intelligence Platforms, STIX 2.x, TAXII, MITRE ATT&CK, and IOC lifecycle management
- Experience with threat actor tracking, campaign analysis, malware intelligence, and TTP analysis
- Experience with SQL, PostgreSQL, Elasticsearch or OpenSearch, and ETL pipeline development
- Experience collecting and automating intelligence from underground forums, Telegram channels, credential leak repositories, marketplaces, paste sites, and OSINT sources
- Experience with AWS Lambda, ECS, S3, IAM, EventBridge, Step Functions, and Secrets Manager
- Experience integrating security platforms including Splunk, CrowdStrike Falcon, VirusTotal, GreyNoise, Shodan, or Censys
- Experience with webhooks, asynchronous programming, Requests, Pandas, BeautifulSoup, Selenium or Playwright, and SQLAlchemy
- Experience with MISP
- Experience with JavaScript, PowerShell, or Go
- Experience developing AI-assisted threat intelligence workflows and using LLMs for summarization and analysis
- Experience with graph databases such as Neo4j, knowledge graphs, and RAG architectures
- Familiarity with DevOps, Docker, Kubernetes, and CI/CD pipelines
- GIAC Cyber Threat Intelligence, SANS FOR578, CISSP, AWS Certified Security Specialty, AWS Certified Developer Associate, Security+, or GSEC certification
Kroll Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Kroll and has not been reviewed or approved by Kroll.
-
Healthcare Strength — Medical, dental, and vision coverage with HSA/FSA options are part of the U.S. package, alongside life and AD&D. Breadth across core health benefits is positioned as competitive for a large advisory firm.
-
Retirement Support — A 401(k) plan with company match is a core element of the package. Retirement support is consistently highlighted as competitive within total rewards.
-
Leave & Time Off Breadth — Paid holidays, sick leave, and PTO are included, with generous time off and parental/family leave for U.S. roles. Some roles also offer hybrid/WFH flexibility that complements time-off usability.
Kroll Insights
What We Do
Kroll is the world’s premier provider of services and digital products related to valuation, governance, risk and transparency. We work with clients across diverse sectors in the areas of valuation, expert services, investigations, cyber security, corporate finance, restructuring, legal and business solutions, data analytics and regulatory compliance. Our firm has nearly 5,000 professionals in 30 countries and territories around the world. For more information, visit www.kroll.com.








