Manager, Threat Intelligence
United States · Remote · Full-time
- Posted 1w ago
- From PDI Technologies’s careers page
- Location
- United States
- Work mode
- Remote
- Type
- Full-time
- Level
- Senior
- Experience
- 8+ years
- Department
- Information Technology
Apply on PDI Technologies’s site
Opens the listing on jobs.lever.co
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
What you'll own
- Lead and grow the team
- Hire, coach, and develop a remote team of analysts, hunters, and detection engineers, with clear priorities and career paths.
- With a team of four, you'll split your time between leading and doing: hunting, writing intelligence, and building detections alongside the team.
- Partner with SOC, Incident Response, and Security Engineering leaders to improve detection, response, and customer outcomes.
Build the intelligence program
- Define intelligence requirements with SOC leadership and customers and run the full intelligence lifecycle from collection through feedback.
- Deliver strategic, operational, and tactical products: actor profiles, campaign analysis, industry threat briefs, and customer-specific reports.
- Track the actors that matter most to our customers, including financially motivated groups, payment fraud operations, and ransomware crews targeting retail and hospitality.
Turn intelligence into detection
- Own detection content strategy across SIEM and EDR/XDR, including development, testing, tuning, and coverage measured against MITRE ATT&CK.
- Run hypothesis-driven threat hunts across customer environments and feed what you find back into new detections.
- Use automation and AI to scale enrichment, triage support, and reporting so the team can focus on analysis, not busywork.
Step in when it matters
- Provide intelligence context during major incidents and lead during complex escalations.
Be the voice of the team
- Serve as a trusted advisor to customers through briefings, reports, and presentations for both technical and executive audiences.
- Run the team on clear metrics such as detection coverage, hunt findings, reporting timeliness, and customer satisfaction, and contribute to service planning and new offerings.
What success looks like
- First 90 days: Assess the team, tooling, and current detection coverage. Agree on intelligence requirements with SOC leadership and key customers.
- By 6 months: A regular cadence of industry threat reporting, plus an ATT&CK coverage baseline and roadmap.
- By 12 months: Measurable gains in detection coverage and hunt-driven findings, and a team customers see as the go-to source on threats to their industry.
What you bring
Required
- 8+ years in cybersecurity across threat intelligence, threat hunting, incident response, detection engineering, or security operations.
- 3+ years managing technical security teams, including hiring and developing people.
- Deep knowledge of adversary tactics and the frameworks used to analyze them, such as MITRE ATT&CK, the intelligence lifecycle, and the Diamond Model.
- A track record of producing finished intelligence for both technical and executive audiences.
- Hands-on experience with SIEM (FortiSIEM, Microsoft Sentinel, Splunk, Google Chronicle, or ArcSight) and EDR/XDR platforms and their query languages (KQL, SPL, or similar). Our environment includes FortiSIEM; equivalent experience is welcome.
- Experience supporting complex investigations and incident response.
- Excellent written, verbal, and presentation communication skills.
- Clear writing and speaking skills, with the ability to translate technical findings into business risk.
Nice to have
- Experience at an MSSP or MDR provider serving many customers.
- Background in retail, hospitality, or payments environments, including POS systems or PCI DSS.
- Detection-as-code, Sigma, SOAR, or scripting (e.g., Python).
- Experience with threat intelligence platforms and feeds, such as MISP or Recorded Future.
- Cloud and SaaS investigations across Azure, AWS, or Microsoft 365.
- Active involvement in intelligence-sharing communities such as RH-ISAC.
- Certifications such as GCTI, GCFA, GCIH, GREM, or CISSP are welcome but not required.
A bachelor's degree in a related field or equivalent experience. If you're close on the requirements and excited about the work, we'd still like to hear from you.
Skills they ask for
Pick one to see other roles that ask for it.
About PDI Technologies
Software for fuel and convenience retailPDI Technologies provides software and services for convenience retailers, fuel wholesalers, carriers, consumer brands, and restaurants, covering retail operations, logistics, payments, and data.
See all 19 roles at PDI TechnologiesMore roles at PDI Technologies
See all 19- HR GeneralistAlpharetta · HybridHuman Resources · HybridAlpharetta, United States1d
- Business Systems Developer IIChennai · HybridSoftware Development · HybridChennai, India1d
- Senior CounselAlpharetta · Senior · HybridLegal and Compliance · Senior · HybridAlpharetta, United States1w
- Business Systems Developer IIIAlpharetta · Senior · HybridSoftware Development · Senior · HybridAlpharetta, United States1w
Share this role
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.