Threat Intelligence Lead

Posted 8 Days Ago
Be an Early Applicant
London, Greater London, England, GBR
In-Office
Entry level
Information Technology
The Role
Own and develop Anaplan’s Threat Intelligence function, including strategy, lifecycle, tooling, integrations, threat hunting, incident response support, intelligence research, detection content, and executive briefings. Build automated workflows across SIEM, SOAR, and EDR/XDR platforms; develop hunt methodologies and detections aligned with MITRE ATT&CK; and communicate actionable findings to technical and CISO-level stakeholders.
Summary Generated by Built In

At Anaplan, we are a team of innovators focused on optimizing business decision-making through our leading AI-infused scenario planning and analysis platform so our customers can outpace their competition and the market.

What unites Anaplanners across teams and geographies is our collective commitment to our customers’ success and to our Winning Culture.

Our customers rank among the who’s who in the Fortune 50. Coca-Cola, LinkedIn, Adobe, LVMH and Bayer are just a few of the 2,400+ global companies who rely on our best-in-class platform.

Our Winning Culture is the engine that drives our teams of innovators. We champion diversity of thought and ideas, we behave like leaders regardless of title, we are committed to achieving ambitious goals, and we love celebrating our wins – big and small.

Supported by operating principles of being strategy-led, values-based and disciplined in execution, you’ll be inspired, connected, developed and rewarded here. Everything that makes you unique is welcome; join us and let’s build what’s next - together!

Role Summary

As Anaplan's Threat Intelligence Lead, you will own and shape the company's Threat Intelligence function from the ground up. This is a senior, hands-on role at the heart of Anaplan's security organisation — you will set the TI strategy and lifecycle, build and mature the threat hunting programme, and act as the primary intelligence partner to the SOC, Product Security, and Incident Response teams. You'll be both a practitioner and a programme owner: conducting deep research, running hunts, building integrations, and presenting findings to CISO-level stakeholders.

Your Impact

  • Own and lead Anaplan's Threat Intelligence function — defining the TI strategy, lifecycle (planning, collection, processing, analysis, dissemination, and feedback), and operational cadence across the security organisation
  • Manage and administer TI platforms and tooling, and drive their integration with the SOC, Product Security, and other security teams' existing solutions
  • Own and mature Anaplan's threat hunting programme — designing and developing hunt methodologies, playbooks, and hypotheses for use across Security Operations and the broader security organisation, and executing hunts end-to-end
  • Serve as the primary TI partner during active incidents — providing timely, actionable intelligence to the incident response team by researching adversary TTPs, campaigns, IOCs, and attribution to support triage and containment decisions
  • Conduct structured threat intelligence research into threat actors, campaigns, and emerging risks relevant to Anaplan's threat landscape, producing intelligence products pitched appropriately for both technical teams and executive audiences
  • Build and maintain integrations between TI platforms and existing security tooling (SIEM, SOAR, EDR/XDR), leveraging scripting and engineering skills to automate intelligence collection, enrichment, and dissemination workflows
  • Author, contribute to, and validate detection content — including SIEM queries, hunt logic, and custom detection rules — informed by current threat intelligence and aligned to the MITRE ATT&CK framework
  • Communicate threat intelligence findings, programme maturity updates, and emerging risk briefings clearly and confidently to senior and executive stakeholders, up to and including CISO level

Your Qualifications

  • Deep understanding of what an effective Threat Intelligence function requires — including the intelligence lifecycle, operational cadence, and how TI integrates and delivers value across a security organisation
  • Hands-on experience with commercial and open-source TI platforms and tooling, spanning threat intelligence aggregation, enrichment, and sharing
  • Strong threat hunting experience — designing and executing structured, hypothesis-driven hunts using frameworks such as MITRE ATT&CK, and translating hunt findings into actionable detections
  • Practical experience supporting incident response with threat intelligence — comfortable researching adversary tradecraft, attribution, and IOCs under time pressure alongside an IR team
  • Engineering and scripting proficiency to build integrations, automate TI workflows, and develop or enhance hunt tooling
  • Experience authoring detection content — including SIEM query languages and custom detection rule formats
  • Solid working knowledge of SIEM, SOAR, and EDR/XDR platforms and how threat intelligence enriches their capabilities
  • Ability to communicate complex intelligence clearly and confidently to senior and executive audiences, including CISO-level stakeholders, adapting technical detail to the audience's context
  • Strong understanding of adversary tradecraft, threat actor groups, and the evolving threat landscape relevant to SaaS and enterprise environments

Our Commitment to Diversity, Equity, Inclusion and Belonging (DEIB)

We believe attracting and retaining the best talent and fostering an inclusive culture strengthens our business. DEIB improves our workforce, enhances trust with our partners and customers, and drives business success. Build your career in a place where diversity, equity, inclusion and belonging aren’t just words on paper – this is what drives our innovation, it’s how we connect, and it contributes to what makes us a market leader. We believe in a hiring and working environment where all people are respected and valued, regardless of gender identity or expression, sexual orientation, religion, ethnicity, age, neurodiversity, disability status, citizenship, or any other aspect which makes people unique. We hire you for who you are, and we want you to bring your authentic self to work every day! 

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, perform essential job functions, and receive equitable benefits and all privileges of employment. Please contact us to request accommodation.  

Fraud Recruitment Disclaimer  

It has come to our attention that fraudulent and fictitious job opportunities are being circulated on the Internet. Prospective candidates are being contacted by certain individuals, mainly through telephone calls, emails and correspondence, claiming they are representatives of Anaplan. The main purpose of these correspondences and announcements is to obtain privileged information from individuals.  

Anaplan does not:  

  • Extend offers to candidates without an extensive interview process with a member of our recruitment team and a hiring manager via video or in person.   
  • Send job offers via email. All offers are first extended verbally by a member of our internal recruitment team whenever possible and then followed up via written communication.  

All emails from Anaplan would come from an @anaplan.com email address. Should you have any doubts about the authenticity of an email, letter or telephone communication purportedly from, for, or on behalf of Anaplan, please send an email to [email protected] before taking any further action in relation to the correspondence.   

Candidate data processed during our recruitment activities is handled in accordance with our Candidate Privacy Notice. This may include the use of artificial intelligence or automated tools to assist our team in evaluating qualifications.


Skills Required

  • Deep understanding of effective Threat Intelligence functions, including the intelligence lifecycle, operational cadence, and integration across security teams
  • Hands-on experience with commercial and open-source threat intelligence platforms and tooling
  • Strong threat hunting experience using structured, hypothesis-driven methodologies and frameworks such as MITRE ATT&CK
  • Practical experience supporting incident response through adversary tradecraft, attribution, and IOC research
  • Engineering and scripting proficiency for integrations, workflow automation, and hunt tooling
  • Experience authoring detection content, SIEM queries, and custom detection rules
  • Working knowledge of SIEM, SOAR, and EDR/XDR platforms
  • Ability to communicate complex intelligence to senior and executive audiences, including CISO-level stakeholders
  • Strong understanding of adversary tradecraft, threat actor groups, and the threat landscape affecting SaaS and enterprise environments

Anaplan Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Anaplan and has not been reviewed or approved by Anaplan.

  • Strong & Reliable Incentives Earnings potential in sales is considered good or fair, with on‑target earnings achievable when plans are met. This indicates variable pay can meaningfully boost total compensation when targets are hit.
  • Healthcare Strength Medical, dental, and vision coverage are described as strong, complemented by mental‑health resources and EAP support. Company‑wide paid wellbeing days reinforce the health and wellness focus.
  • Parental & Family Support Equitable parental and caregiver leave are highlighted alongside fertility and adoption support. Family‑forming programs such as Carrot are part of the offering.

Anaplan Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Miami, FL
2,194 Employees
Year Founded: 2006

What We Do

Anaplan is building a future where connected leaders and teams are able to constantly adapt, transform and reinvent their businesses. We make it possible to share actionable insights, empower and unleash creativity, and drive innovation. With Anaplan, finance and operational leaders across the organization can model complex scenarios, forecast continuously with added intelligence, and make agile decisions with confidence.

Similar Jobs

In-Office
London, Greater London, England, GBR
2359 Employees
88K-93K Annually
In-Office or Remote
7 Locations
880 Employees
2K-2K Annually
Hybrid
London, Greater London, England, GBR
289097 Employees

Mastercard Logo Mastercard

Partner Success Manager - Media Industry

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
London, Greater London, England, GBR
38800 Employees

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account