Senior Director, Cyber Threat Intellignece

Posted 5 Hours Ago
Be an Early Applicant
Hiring Remotely in United States
Remote
200K-300K Annually
Senior level
Big Data • Security • Software • Analytics • Cybersecurity
The Role
Design, administer, and optimize a cyber threat intelligence platform. Build Python automation, ETL pipelines, APIs, and integrations that collect, enrich, normalize, correlate, and distribute intelligence from commercial, open-source, government, dark web, and internal sources. Apply STIX/TAXII and MITRE ATT&CK to track indicators, actors, malware, vulnerabilities, and campaigns. Develop dashboards and AI-assisted capabilities while ensuring data quality, governance, and security across intelligence repositories.
Summary Generated by Built In

As the leading independent provider of risk and financial advisory solutions, Kroll leverages our unique insights, data, and technology to help clients stay ahead of complex cyber threats. Our Cyber Risk team partners with organizations around the world to deliver intelligence-driven security solutions that enable informed decision-making and proactive risk management.

 

We are seeking an experienced Threat Intelligence Platform Engineer to join our Cyber Threat Intelligence team. This role is ideal for a security professional who is passionate about engineering scalable threat intelligence capabilities through automation, data integration, and platform management.

 

The Intelligence Platform Engineer is responsible for designing, building, and maintaining the technology, automation, and data infrastructure that powers cyber threat intelligence operations. This role serves as the bridge between intelligence analysis, threat research, data engineering, and security operations by developing scalable solutions that automate the collection, enrichment, normalization, correlation, and dissemination of cyber threat intelligence.

 

The successful candidate will identify and integrate intelligence data sources from commercial providers, open-source intelligence (OSINT), internal security telemetry, dark web collections, government feeds, and industry-sharing communities. They will leverage automation, APIs, machine learning, and data engineering techniques to transform raw intelligence into actionable insights that support threat detection, incident response, vulnerability management, executive reporting, and strategic decision-making. This aligns with internal descriptions emphasizing ownership of a threat intelligence platform, automation, and multi-source intelligence integration.

 

Working closely with Threat Intelligence Analysts, Incident Responders, Detection Engineers, and Security Operations teams, the successful candidate will improve the organization's ability to identify emerging threats through intelligent automation and data engineering.

 

Key Responsibilities:

  • Administer, maintain, and optimize Kroll’s Threat Intelligence Platform. 

  • Design and develop automated workflows for collecting, enriching, correlating, and distributing cyber threat intelligence. 

  • Build scalable automation to support dark web monitoring, credential exposure tracking, threat actor activity, and emerging threat detection. 

  • Develop and maintain integrations with commercial threat intelligence providers, OSINT sources, government intelligence feeds, ISACs, and internal security platforms. 

  • Design ETL pipelines to ingest, normalize, and organize structured and unstructured threat intelligence datasets. 

  • Correlate indicators of compromise (IOCs), threat actors, malware families, vulnerabilities, and campaigns using industry standards such as STIX/TAXII and the MITRE ATT&CK Framework. 

  • Develop dashboards, reporting, and visualizations that improve analyst efficiency and provide actionable intelligence to stakeholders. 

  • Evaluate emerging technologies, intelligence sources, and AI-driven capabilities to continuously improve Kroll's threat intelligence operations. 

  • Ensure data quality, governance, and security across all intelligence repositories. 

 

Required Qualifications:

Education

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related discipline, or equivalent professional experience. 

Experience

  • Minimum of five (5) years of experience in cybersecurity, cyber threat intelligence, or security engineering. 

  • Experience administering a Threat Intelligence Platform (EclecticIQ strongly preferred). 

  • Proven experience designing automation solutions using Python. 

  • Experience integrating APIs and external data sources. 

  • Hands-on experience with cyber threat intelligence workflows and intelligence lifecycle management. 

Technical Qualifications

Threat Intelligence

  • Experience working Threat Intelligence Platforms 

  • STIX 2.x and TAXII 

  • MITRE ATT&CK Framework 

  • MISP (preferred) 

  • IOC lifecycle management 

  • Threat actor tracking 

  • Campaign analysis 

  • Malware intelligence 

  • TTP analysis 

Programming & Automation

Required:

  • Advanced Python development 

Experience with:

  • REST APIs 

  • Webhooks 

  • Async programming 

  • Requests 

  • Pandas 

  • BeautifulSoup 

  • Selenium or Playwright 

  • SQLAlchemy 

Preferred:

  • JavaScript 

  • PowerShell 

  • Go 

Data Engineering

Experience with:

  • SQL 

  • PostgreSQL 

  • Elasticsearch/OpenSearch 

  • MongoDB (preferred) 

Ability to:

  • Build ETL pipelines 

  • Normalize structured and unstructured datasets 

  • Correlate multiple intelligence sources 

  • Design scalable data ingestion workflows 

Dark Web Intelligence

Experience collecting and automating intelligence from:

  • Underground forums 

  • Telegram channels 

  • Credential leak repositories 

  • Marketplace monitoring 

  • Paste sites 

  • Open-source intelligence sources 

Cloud & Infrastructure

Experience with AWS services including:

  • Lambda 

  • ECS 

  • S3 

  • IAM 

  • EventBridge 

  • Step Functions 

  • Secrets Manager 

Security Platforms

Experience integrating with technologies such as:

  • Splunk 

  • CrowdStrike Falcon 

  • VirusTotal 

  • GreyNoise 

  • Shodan 

  • Censys 

Preferred Qualifications

  • Experience developing AI-assisted threat intelligence workflows. 

  • Familiarity with Large Language Models (LLMs) for intelligence summarization and analysis. 

  • Experience with graph databases such as Neo4j. 

  • Knowledge of Retrieval-Augmented Generation (RAG) architectures. 

  • Experience building knowledge graphs. 

  • Familiarity with DevOps practices, Docker, Kubernetes, and CI/CD pipelines. 

Preferred Certifications

  • GIAC Cyber Threat Intelligence (GCTI) 

  • SANS FOR578 Cyber Threat Intelligence 

  • CISSP 

  • AWS Certified Security – Specialty 

  • AWS Certified Developer – Associate 

  • Security+ 

  • GSEC 

What Success Looks Like

The successful candidate will:

  • Build scalable automation that significantly reduces manual intelligence collection and analysis. 

  • Improve analyst productivity through efficient data integration and workflow automation. 

  • Expand Kroll's ability to monitor the dark web and emerging threat landscape. 

  • Deliver actionable, high-quality intelligence through a modern, integrated Threat Intelligence Platform. 

  • Help position Kroll as an industry leader in intelligence-driven cybersecurity services through continuous innovation and operational excellence. 

 

Why Join Kroll?

 

At Kroll, you'll work alongside some of the industry's most respected cyber professionals, solving complex challenges for organizations around the world. We foster a collaborative, innovation-driven environment where your expertise directly contributes to protecting clients from evolving cyber threats. You'll have the opportunity to work with cutting-edge technologies, influence the evolution of our threat intelligence capabilities, and make a meaningful impact across our global Cyber Risk practice.

 

Your recruiter will be happy to walk you through your U.S.-specific benefits, which include:

 

  • Healthcare Coverage: Comprehensive medical, dental, and vision plans.

  • Time Off and Leave Policies: Generous paid time off (PTO), paid company holidays, generous parental and family leave.

  • Protective Insurances: Life insurance, short- and long-term disability coverage, and accident protection.

  • Compensation and Rewards: Competitive salary structures, performance-based incentives, and merit-based compensation reviews.

  • Retirement Plans: 401(k) plans with company matching.

 

Please note that benefits may vary by region, department and role. We encourage you to speak with your recruiter to learn more about the specific benefits available for your position.

 

About Kroll 

 

Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll. 

 

In order to be considered for a position, you must formally apply via careers.kroll.com.

 

We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability.

 

The current salary range for this position is $200,000 to $300,000

 

 

#LI-CN1

#LI-Remote

Skills Required

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, a related discipline, or equivalent professional experience
  • At least five years of experience in cybersecurity, cyber threat intelligence, or security engineering
  • Experience administering a Threat Intelligence Platform; EclecticIQ strongly preferred
  • Advanced Python development and automation solution design
  • Experience integrating REST APIs and external data sources
  • Hands-on experience with cyber threat intelligence workflows and intelligence lifecycle management
  • Experience with Threat Intelligence Platforms, STIX 2.x, TAXII, MITRE ATT&CK, and IOC lifecycle management
  • Experience with threat actor tracking, campaign analysis, malware intelligence, and TTP analysis
  • Experience with SQL, PostgreSQL, Elasticsearch or OpenSearch, and ETL pipeline development
  • Experience collecting and automating intelligence from underground forums, Telegram channels, credential leak repositories, marketplaces, paste sites, and OSINT sources
  • Experience with AWS Lambda, ECS, S3, IAM, EventBridge, Step Functions, and Secrets Manager
  • Experience integrating security platforms including Splunk, CrowdStrike Falcon, VirusTotal, GreyNoise, Shodan, or Censys
  • Experience with webhooks, asynchronous programming, Requests, Pandas, BeautifulSoup, Selenium or Playwright, and SQLAlchemy
  • Experience with MISP
  • Experience with JavaScript, PowerShell, or Go
  • Experience developing AI-assisted threat intelligence workflows and using LLMs for summarization and analysis
  • Experience with graph databases such as Neo4j, knowledge graphs, and RAG architectures
  • Familiarity with DevOps, Docker, Kubernetes, and CI/CD pipelines
  • GIAC Cyber Threat Intelligence, SANS FOR578, CISSP, AWS Certified Security Specialty, AWS Certified Developer Associate, Security+, or GSEC certification

Kroll Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Kroll and has not been reviewed or approved by Kroll.

  • Healthcare Strength Medical, dental, and vision coverage with HSA/FSA options are part of the U.S. package, alongside life and AD&D. Breadth across core health benefits is positioned as competitive for a large advisory firm.
  • Retirement Support A 401(k) plan with company match is a core element of the package. Retirement support is consistently highlighted as competitive within total rewards.
  • Leave & Time Off Breadth Paid holidays, sick leave, and PTO are included, with generous time off and parental/family leave for U.S. roles. Some roles also offer hybrid/WFH flexibility that complements time-off usability.

Kroll Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
5,001 Employees
Year Founded: 1932

What We Do

Kroll is the world’s premier provider of services and digital products related to valuation, governance, risk and transparency. We work with clients across diverse sectors in the areas of valuation, expert services, investigations, cyber security, corporate finance, restructuring, legal and business solutions, data analytics and regulatory compliance. Our firm has nearly 5,000 professionals in 30 countries and territories around the world. For more information, visit www.kroll.com.

Similar Jobs

BAE Systems, Inc. Logo BAE Systems, Inc.

Senior Principal Program Planner (Hybrid Preferred, Remote Work Considered)

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Remote or Hybrid
Nashua, NH, USA
40000 Employees
119K-202K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Electrical Engineer

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Remote or Hybrid
New Hampshire, USA
40000 Employees
133K-226K Annually

GC AI Logo GC AI

Recruiting Coordinator

Artificial Intelligence • Legal Tech
Remote or Hybrid
San Mateo, CA, USA
130 Employees
80K-110K Annually

Samsara Logo Samsara

Sr. Manager, Business Operations

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
119K-180K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account