Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Director, Threat Intelligence

As the leading independent provider of risk and financial advisory solutions, Kroll leverages our unique insights, data, and technology to help clients stay ahead of complex cyber threats. Our Cyber Risk team partners with organizations around the world to deliver intelligence-driven security solutions that enable informed decision-making and proactive risk management.

We are seeking an experienced Threat Intelligence Platform Engineer to join our Cyber Threat Intelligence team. This role is ideal for a security professional who is passionate about engineering scalable threat intelligence capabilities through automation, data integration, and platform management.

The Intelligence Platform Engineer is responsible for designing, building, and maintaining the technology, automation, and data infrastructure that powers cyber threat intelligence operations. This role serves as the bridge between intelligence analysis, threat research, data engineering, and security operations by developing scalable solutions that automate the collection, enrichment, normalization, correlation, and dissemination of cyber threat intelligence.

The successful candidate will identify and integrate intelligence data sources from commercial providers, open-source intelligence (OSINT), internal security telemetry, dark web collections, government feeds, and industry-sharing communities. They will leverage automation, APIs, machine learning, and data engineering techniques to transform raw intelligence into actionable insights that support threat detection, incident response, vulnerability management, executive reporting, and strategic decision-making. This aligns with internal descriptions emphasizing ownership of a threat intelligence platform, automation, and multi-source intelligence integration.

Working closely with Threat Intelligence Analysts, Incident Responders, Detection Engineers, and Security Operations teams, the successful candidate will improve the organization's ability to identify emerging threats through intelligent automation and data engineering.

Key Responsibilities:

  • Administer, maintain, and optimize Kroll’s Threat Intelligence Platform.

  • Design and develop automated workflows for collecting, enriching, correlating, and distributing cyber threat intelligence.

  • Build scalable automation to support dark web monitoring, credential exposure tracking, threat actor activity, and emerging threat detection.

  • Develop and maintain integrations with commercial threat intelligence providers, OSINT sources, government intelligence feeds, ISACs, and internal security platforms.

  • Design ETL pipelines to ingest, normalize, and organize structured and unstructured threat intelligence datasets.

  • Correlate indicators of compromise (IOCs), threat actors, malware families, vulnerabilities, and campaigns using industry standards such as STIX/TAXII and the MITRE ATT&CK Framework.

  • Develop dashboards, reporting, and visualizations that improve analyst efficiency and provide actionable intelligence to stakeholders.

  • Evaluate emerging technologies, intelligence sources, and AI-driven capabilities to continuously improve Kroll's threat intelligence operations.

  • Ensure data quality, governance, and security across all intelligence repositories.

Required Qualifications:

Education

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related discipline, or equivalent professional experience.

Experience

  • Minimum of five (5) years of experience in cybersecurity, cyber threat intelligence, or security engineering.

  • Experience administering a Threat Intelligence Platform (EclecticIQ strongly preferred).

  • Proven experience designing automation solutions using Python.

  • Experience integrating APIs and external data sources.

  • Hands-on experience with cyber threat intelligence workflows and intelligence lifecycle management.

Technical Qualifications

Threat Intelligence

  • Experience working Threat Intelligence Platforms

  • STIX 2.x and TAXII

  • MITRE ATT&CK Framework

  • MISP (preferred)

  • IOC lifecycle management

  • Threat actor tracking

  • Campaign analysis

  • Malware intelligence

  • TTP analysis

Programming & Automation

Required:

  • Advanced Python development

Experience with:

  • REST APIs

  • Webhooks

  • Async programming

  • Requests

  • Pandas

  • BeautifulSoup

  • Selenium or Playwright

  • SQLAlchemy

Preferred:

  • JavaScript

  • PowerShell

  • Go

Data Engineering

Experience with:

  • SQL

  • PostgreSQL

  • Elasticsearch/OpenSearch

  • MongoDB (preferred)

Ability to:

  • Build ETL pipelines

  • Normalize structured and unstructured datasets

  • Correlate multiple intelligence sources

  • Design scalable data ingestion workflows

Dark Web Intelligence

Experience collecting and automating intelligence from:

  • Underground forums

  • Telegram channels

  • Credential leak repositories

  • Marketplace monitoring

  • Paste sites

  • Open-source intelligence sources

Cloud & Infrastructure

Experience with AWS services including:

  • Lambda

  • ECS

  • S3

  • IAM

  • EventBridge

  • Step Functions

  • Secrets Manager

Security Platforms

Experience integrating with technologies such as:

  • Splunk

  • CrowdStrike Falcon

  • VirusTotal

  • GreyNoise

  • Shodan

  • Censys

Preferred Qualifications

  • Experience developing AI-assisted threat intelligence workflows.

  • Familiarity with Large Language Models (LLMs) for intelligence summarization and analysis.

  • Experience with graph databases such as Neo4j.

  • Knowledge of Retrieval-Augmented Generation (RAG) architectures.

  • Experience building knowledge graphs.

  • Familiarity with DevOps practices, Docker, Kubernetes, and CI/CD pipelines.

Preferred Certifications

  • GIAC Cyber Threat Intelligence (GCTI)

  • SANS FOR578 Cyber Threat Intelligence

  • CISSP

  • AWS Certified Security – Specialty

  • AWS Certified Developer – Associate

  • Security+

  • GSEC

What Success Looks Like

The successful candidate will:

  • Build scalable automation that significantly reduces manual intelligence collection and analysis.

  • Improve analyst productivity through efficient data integration and workflow automation.

  • Expand Kroll's ability to monitor the dark web and emerging threat landscape.

  • Deliver actionable, high-quality intelligence through a modern, integrated Threat Intelligence Platform.

  • Help position Kroll as an industry leader in intelligence-driven cybersecurity services through continuous innovation and operational excellence.

Why Join Kroll?

At Kroll, you'll work alongside some of the industry's most respected cyber professionals, solving complex challenges for organizations around the world. We foster a collaborative, innovation-driven environment where your expertise directly contributes to protecting clients from evolving cyber threats. You'll have the opportunity to work with cutting-edge technologies, influence the evolution of our threat intelligence capabilities, and make a meaningful impact across our global Cyber Risk practice.

  • Healthcare Coverage: Comprehensive medical, dental, and vision plans.

  • Time Off and Leave Policies: Generous paid time off (PTO), paid company holidays, generous parental and family leave.

  • Protective Insurances: Life insurance, short- and long-term disability coverage, and accident protection.

  • Compensation and Rewards: Competitive salary structures, performance-based incentives, and merit-based compensation reviews.

  • Retirement Plans: 401(k) plans with company matching.

Please note that benefits may vary by region, department and role. We encourage you to speak with your recruiter to learn more about the specific benefits available for your position.

About Kroll

Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll.

We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability.

#LI-CN1

#LI-Remote

Vacancy posted 8 days ago
Similar jobs that could be interesting for youBased on the Senior Director, Threat Intelligence in United States vacancy
  • $168.4k - $252.6k

    Job Summary: The Director of Threat Management is responsible for leading the enterprise detection...  ...Operations Center (SOC), Cyber Threat Intelligence (CTI), Detection Engineering, and...  ...operations or threat functions at the Senior Manager or Director level.Demonstrated... 
    Senior
    Intelligence
    Hourly pay
    Minimum wage
    Full time
    Local area
    Shift work

    Ecolab

    Saint Paul, MN
    4 days ago
  •  ...Kroll’s Cyber Threat Intelligence (CTI) team is seeking a highly experienced Senior Director, Cyber Threat Intelligence Embedded Advisor Program to lead the development, execution, and growth of a strategic intelligence advisory function embedded across Kroll’s Cyber... 
    Senior
    Intelligence
    New York, NY
    11 days ago
  • $190k - $304k

     ...Responsibilities Peraton is seeking an ambitious Senior Director of Capture Management with...  ...customers; -Civil -Enterprise IT -Classified/ Intelligence Community -NOAA -Space/ NRO• Proven...  ...traditional and nontraditional threats across all domains: land, sea, space,... 
    Senior
    Intelligence
    Contract work
    For subcontractor
    Local area
    Shift work

    Peraton Corporation

    Reston, VA
    4 days ago
  • $190.96k - $286.44k

    Senior Director, Cyber Exposure ManagementIntroduction to role:Are you ready to turn exposure...  ...evolve offensive testing into a continuous, intelligence-led capability. How would you partner...  ...asset criticality, exploitability and threat intelligence; implement enterprise... 
    Senior
    Intelligence
    Full time
    Work at office
    Worldwide
    Flexible hours
    3 days per week

    AstraZeneca

    Gaithersburg, MD
    2 days ago
  • $264k - $363k

     ...Position Overview:We are seeking a visionary Senior Director, Governance, Risk and Compliance (GRC)...  ...collection, automated risk scoring, intelligent policy mapping, and continuous audit...  ...evolving business priorities and emerging threats.Third-Party & SaaS Risk Governance:... 
    Senior
    Intelligence
    Local area
    Worldwide
    Flexible hours

    Okta

    San Francisco, CA
    3 days ago
  • $200k - $235k

     ...missions in the world!Job Description: Senior Director of Subject Matter Expert - CTEM, RBVM,...  ...customers to operationalize Continuous Threat Exposure Management (CTEM) and modern risk...  ...:• VMDR vulnerability telemetry• Asset intelligence from CSAM• External attack surface data... 
    Senior
    Intelligence
    Full time

    Qualys

    Foster, CA
    1 day ago
  • The Sr. Director, Cybersecurity Architecture is the senior leader responsible for enterprise cybersecurity architecture, solution...  ...experience in monitoring and vulnerability & threat management technologies as well as threat intelligence services and practices Demonstratable... 
    Senior
    Intelligence
    Contract work
    For contractors
    Work experience placement
    Local area
    Remote work

    Sherwin-Williams

    Cleveland, OH
    1 day ago
  • $176.9k - $332.4k

     ...is looking for a cleared and talented Senior Technical Director to join our growing team!In this role...  ...activities in defense of emerging threats in the cybersecurity domain. You will...  ...Bring:Experience working within the Intelligence Community.Experience designing/implementing... 
    Senior
    Intelligence
    Full time

    Parsons

    Annapolis Junction, MD
    2 days ago
  •  ...Senior Technical Program Manager (TPM) TENEX is an AI-native, automation-first, built...  ...cybersecurity posture through advanced threat detection, rapid response, and continuous...  ...cybersecurity domain, including threat intelligence, SIEM/SOAR integration, and security operations... 
    Senior
    Intelligence
    Remote work

    TenEx

    United States
    3 days ago
  • $172k - $202.5k

     ...people.Subject Matter Expertise: The Sr. Director Analyst will apply in-depth knowledge of...  ...and product capabilitiesIdentity threat detection and response architecture, tools...  ...for how organizations leverage artificial intelligence to drive meaningful impact. You’ll have... 
    Senior
    Intelligence
    Full time
    Immediate start
    Remote work
    Worldwide

    Gartner

    Texas
    4 days ago
  • $146k - $234k

    Responsibilities Peraton is seeking a Senior Technical Program Manager to lead our...  ...size and scope, and managing/supervising intelligence analysts and technical staff.5+ years of...  ...between traditional and nontraditional threats across all domains: land, sea, space, air... 
    Senior
    Intelligence
    Contract work
    For contractors
    For subcontractor
    Shift work

    Peraton Corporation

    McLean, VA
    3 days ago
  • $172k - $202.5k

     ...range of world-leading organizations. A Senior Director serves as a leader within Gartner’s...  ...Post-Quantum Cryptography, Continuous Threat Exposure Management etc into clear, strategic...  ...how organizations leverage artificial intelligence to drive meaningful impact. You’ll have... 
    Senior
    Intelligence
    Full time
    Local area
    Immediate start
    Remote work
    Worldwide
    Shift work

    Gartner

    Stamford, CT
    15 hours ago
  • $176k - $282k

     ...ResponsibilitiesPeraton is seeking a Senior Technical Manager to support our customer...  ...QualificationsExperience with zero-trust.Experience supporting Intelligence Community (IC) or DoD customers in a...  ...between traditional and nontraditional threats across all domains: land, sea, space,... 
    Senior
    Intelligence
    Contract work
    For contractors
    Work experience placement
    For subcontractor
    Shift work

    Peraton

    Washington, VA
    1 day ago
  •  ...AV is seeking a Cyber Threat Intelligence Analyst to identify, analyze, and communicate cyber threats impacting the organization. The role blends traditional threat intelligence with hands-on cybersecurity to produce actionable intelligence for detections, investigations... 
    Senior
    Intelligence

    A/V Services LLC

    Dayton, OH
    3 days ago
  •  ...AV is seeking a Cyber Threat Intelligence Analyst to identify, analyze, and communicate cyber threats that affect the organization. The role blends traditional threat intelligence with strong technical cybersecurity skills to create actionable intelligence for detections... 
    Senior
    Intelligence

    A/V Services LLC

    Germantown, MD
    4 days ago
  •  ...AV is seeking a Cyber Threat Intelligence Analyst to identify and communicate cyber threats impacting the organization and its operations. The role blends traditional threat intelligence with strong technical cybersecurity skills to produce detections, investigations,... 
    Senior
    Intelligence

    A/V Services LLC

    Florida, NY
    4 days ago
  •  ...Peraton is seeking to hire a Senior Cyber Threat Analyst for its Federal Strategic Cyber division, located in Warrenton, VA. The role focuses on researching threat trends, producing threat intelligence products, and coordinating with government partners to enhance situational... 
    Senior
    Intelligence

    Peraton

    Warrenton, VA
    3 days ago
  •  ...AV is seeking a Cyber Threat Intelligence Analyst to identify, analyze, and communicate cyber threats affecting the organization. The role blends traditional threat intelligence with strong technical cybersecurity to drive actionable detections, investigations, and defense... 
    Senior
    Intelligence

    A/V Services LLC

    Albuquerque, NM
    1 day ago
  •  ...Leidos is seeking a Tier 3 Cyber Threat Intelligence Analyst to join our team supporting DHS NOSC services. You will identify and investigate high-priority threat campaigns, track adversaries and TTPs, and deliver actionable intelligence to improve cyber resiliency across... 
    Senior
    Intelligence

    Leidos

    Washington DC
    2 days ago
  •  ...AV is seeking a Cyber Threat Intelligence (CTI) Analyst to identify, analyze, and communicate cyber threats that could impact its people, systems, and operations. The role blends traditional threat intelligence with strong technical cybersecurity skills to drive actionable... 
    Senior
    Intelligence

    A/V Services LLC

    Melbourne, FL
    1 day ago
  •  ...Senior Technical Content Manager Remote (US) Company Background Censys' mission...  ...by the lack of trustworthy Internet intelligence, we set out to create the industry's most...  ...time Internet intelligence and actionable threat insights to global governments, over 50%... 
    Senior
    Intelligence
    Remote work
    Worldwide

    Censys

    United States
    2 days ago
  •  ...leading conservation organizations, seeks a Senior Director, Africa. The Senior Director for...  ...development to staff; has high emotional intelligence ~ Able to juggle multiple tasks,...  ...and institutions to tackle the greatest threats to nature and the future of the planet... 
    Senior
    Intelligence
    Full time
    Temporary work
    Relocation

    World Wildlife Fund, Inc.

    Washington DC
    27 days ago
  • $166k - $220k

     ...and modular payloads, to address growing threats in space and ensure our Guardians...  ...warfighting domain.ABOUT THE JOBWe are hiring a Senior Technical Program Manager for our Space...  ...-party service provider provides risk-intelligence services that may include analysis of sanctions... 
    Senior
    Intelligence
    Full time
    Work experience placement
    Immediate start

    Anduril Industries

    Costa Mesa, CA
    1 day ago
  •  ...BCMC is seeking a seasoned Incident Manager to support cyber threat intelligence efforts for a critical VM program. The role focuses on gathering and analyzing CTI to guide operational decisions, identify emerging threats and collaborate with stakeholders to implement... 
    Senior
    Intelligence

    BCMC, LLC

    Arlington, VA
    15 hours ago
  •  ...AV is seeking a Cyber Threat Intelligence Analyst to identify, analyze, and communicate cyber threats affecting the organization, employees, systems, data, and operations. The role blends traditional threat intelligence with strong technical cybersecurity skills to translate... 
    Senior
    Intelligence

    A/V Services LLC

    Herndon, VA
    4 days ago
  • $195k - $262.7k

     ...A financial technology company is seeking a Sr. Manager, Cyber Threat Researcher to leverage cyber threat intelligence. The position involves creating detection mechanisms and maintaining expertise in current threat landscapes. Ideal candidates should have extensive experience... 
    Senior
    Intelligence
    Remote work

    DEV

    New York, NY
    4 days ago
  •  ...Booz Allen Hamilton seeks a Senior Cyber Threat Analyst to support attribution and identification of adversary infrastructure for partner agencies in the United States. You will analyze NetFlow data, develop findings, and deliver briefs to field offices and IC peers. Qualifications... 
    Senior
    Intelligence

    Booz Allen Hamilton

    Huntsville, AL
    4 days ago
  •  ...AV is seeking a Cyber Threat Intelligence Analyst to identify, analyze, and communicate cyber threats impacting the organization’s employees, systems, data, and operations. The role blends traditional threat intelligence with hands-on security aptitude to produce actionable... 
    Senior
    Intelligence

    A/V Services LLC

    Annapolis, MD
    1 day ago
  •  ...Senior Technical Account Manager As a Senior Technical Account Manager at Clutch Security...  ...a trusted security advisor, and conduct threat-hunting and risk analysis across diverse...  ...emerging threats. Enhance Platform Intelligence: Develop and integrate cybersecurity... 
    Senior
    Intelligence
    Remote work

    Clutch Security

    United States
    4 days ago
  • $150k - $258.75k

     ...DePuy Synthes is recruiting for a(n) Director, Incident Response & Threat; this Hybrid position will be in...  ...OverviewThe Director, Cyber Defense is a senior cybersecurity leadership role...  ...defense engineering, and cyber threat intelligence capabilities, with accountability... 
    Intelligence
    Full time
    Internship
    Local area
    Immediate start

    Johnson & Johnson

    Raynham, MA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Director, Threat Intelligence. Be the first to apply!