Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Director, Threat Intelligence Research

Arctic Wolf Incident Response

Director, Threat Intelligence Research

At Arctic Wolf, you won't just watch the cybersecurity industry evolve – you'll help lead the change. Our global Pack is made up of people who thrive on solving hard problems, moving fast, and building technology that protects organizations around the world. We're proud to be recognized by Forbes, CNBC, Fortune, CRN, Bartner Peer Insights and IDC MarketScape – but what matters most is the work behind it: delivering real outcomes for customers through award winning innovation like our Aurora Platform.

If you're looking for meaningful work, smart teammates and the chance to make a real impact in a high-growth company that's redefining security operations, Arctic Wolf is the right place for you!

Our mission is simple: End Cyber Risk. We're looking for a Director, Threat Intelligence Research to be part of making that happen.

About the Role

This senior leadership role owns the strategy and execution of Cyber Threat Intelligence (CTI) at Arctic Wolf, an AI-native security operations company. The mission is singular: anticipate what will hurt our customers, and translate that foresight into prioritized, contextual intelligence that directly drives detection engineering, threat operations, and product outcomes. The Director leads multiple intelligence teams, sets collection and analytic priorities tied to Arctic Wolf's customer base, and builds an agentic-first operating model that transforms CTI into the engine of an AI-native security organization. The role is also a primary public face of Arctic Wolf threat research, driving rapid-response publications, executive briefings, media engagement, and industry keynotes that establish the company's authority in the threat landscape, on par with the standard set by leading research programs in the industry.

Job Scope

Owns the vision and execution of Arctic Wolf's Cyber Threat Intelligence function. Directs multiple intelligence teams, defines collection and analytic priorities tied to customer risk, and is accountable for the speed, relevance, and downstream impact of intelligence on detection engineering, threat operations, and product.

Key Responsibilities
  • Drive detection engineering through intelligence-led collection and prioritization, ensuring every campaign, TTP, and threat actor tracked translates into a ranked detection backlog tied to customer risk.
  • Anticipate what will hurt customers: define collection priorities, PIRs, and coverage goals grounded in Arctic Wolf's customer base, sectors, attack surface, and adversary landscape.
  • Lead the rapid-response function for high-severity events (zero-days, mass exploitation, breach disclosures, geopolitically driven campaigns), coordinating cross-functional response and public communications.
  • Partner with Data Science, Threat Operations, Detection Engineering, Product Management, and Engineering to productize intelligence, turning research into customer-facing capabilities, signals, and content.
  • Build an agentic-first operating model: codify intelligence workflows as agentic systems, evaluate and adopt frontier AI tooling, and lead the team's transformation into AI-native analysts.
  • Set the internal CTI frameworks (PIRs, ATT&CK alignment, attribution discipline, confidence and probability language, intel-to-detection pipeline) used across the company.
Expert Positioning Goal:
  • Establish Arctic Wolf as a recognized authority in threat research through rapid-response publications, blogs, podcasts, and original research reports.
  • Engage with PR, Communications, and Marketing to ensure timely, accurate, and high-impact external messaging during major incidents and disclosures, and to amplify research that defines the company's voice in the market.
  • Speak at top-tier industry and government forums (e.g., RSA, Black Hat, FIRST, SANS Summits, FS-ISAC, InfraGard, ISAC and government exchanges) and represent Arctic Wolf in public-private partnerships.
  • Brief customers, executives, and boards on the threats most relevant to their environment, sector, and risk profile.
Example Key Results:
  • Launched an intelligence-driven detection prioritization program that measurably increased coverage of customer-relevant TTPs and reduced time from intel surface to deployed detection.
  • Stood up a rapid-response capability that delivered authoritative public analysis of major incidents within hours, generating earned media, customer trust, and measurable share-of-voice in the threat research community.
  • Transformed CTI workflows to agentic-first, with documented gains in throughput and analyst leverage; established AI-native tradecraft as the team standard.
  • Productized intelligence outputs in partnership with Product, Data Science, and Engineering, shipping customer-facing capabilities, signals, and content packs that materially improved customer protection.
Complexity & Problem Solving

Leads strategic vision-setting at the intersection of threat research, detection engineering, AI and agentic systems, and product. Solves complex org-wide problems involving collection prioritization, intelligence-to-detection pipelines, attribution under uncertainty, AI-native workflow design, and cross-functional alignment with Data Science, Threat Operations, Detection Engineering, Product Management, and Engineering.

Knowledge & Experience
  • Demonstrated leadership of a regional or global CTI function with direct, measurable impact on detection engineering, threat operations, or product outcomes — ideally within an MDR, MSSP, EDR/XDR, or major incident response practice.
  • Expertise in threat actor attribution, campaign tracking, TTP analysis, and translating intelligence into ranked detection priorities and customer-relevant guidance.
  • Hands-on track record of operating in agentic and AI-native workflows: building, evaluating, or leading teams that use LLM agents, retrieval pipelines, and automation as a primary mode of work, not as an experiment.
  • Proven ability to partner with Data Science, Detection Engineering, Threat Operations, and Product Management to productize intelligence capabilities and ship customer-facing outcomes.
  • Experience leading rapid-response programs and serving as a public-facing voice during major incidents: blogs, briefings, podcasts, conference keynotes, and earned media engagement with PR and Communications.
  • Experience engaging with senior stakeholders, executive and board briefings, and public-private partnerships (e.g., ISACs, industry coalitions, government exchanges).
  • Has developed other managers; strong people leadership skills with a bias toward building small, senior, AI-leveraged teams.
  • Able to define and execute long-term intelligence strategies and metrics aligned with customer protection, detection coverage, time-to-detection for emerging threats, and product outcomes.
Collaboration & Interaction

Interfaces daily with Detection Engineering, Threat Operations, Data Science, Product Management, and Engineering leadership to align intelligence to customer protection. Engages senior leaders, customers, public/private coalitions, regulators, media, and the broader security community; shapes the team's external presence and reputation as a primary public face of Arctic Wolf threat research.

Achieve Results

Drives intelligence programs whose impact is measured in customer protection, detection coverage, time-to-detection for emerging threats, productized capabilities shipped, and earned authority in the threat research community. Develops managers and senior individual contributors operating natively with agentic systems.

About Arctic Wolf At Arctic Wolf, we foster a collaborative and inclusive work environment that thrives on diversity of thought, background, and culture. This is reflected in our multiple awards, including Top Workplace USA (2021-2024), Best Places to Work – USA (2021-2024), Great Place to Work – Canada (2021-2024), Great Place to Work – UK (2024), and Kununu Top Company – Germany (2024). Our commitment to bold growth and shaping the future of security operations is matched by our dedication to customer satisfaction, with over 7,000 customers worldwide and more than 2,000 channel partners globally. As we continue to expand globally and enhance our technology, Arctic Wolf remains the most trusted name in the industry. Our Values Arctic Wolf recognizes that success comes from delighting our customers, so we work together to ensure that happens every day. We believe in diversity and inclusion and truly value the unique qualities and unique perspectives all employees bring to the organization. And we appreciate that—by protecting people's and organizations' sensitive data and seeking to end cyber risk— we get to work in an industry that is fundamental to the greater good. We celebrate unique perspectives by creating a platform for all voices to be heard through our Pack Unity program. We encourage all employees to join or create a new alliance. See more about our Pack Unity here. We also believe and practice corporate responsibility, and have recently joined the Pledge 1% Movement, ensuring that we continue to give back to our community. We know

Vacancy posted 6 hours ago
Similar jobs that could be interesting for youBased on the Director, Threat Intelligence Research in United States vacancy
  •  ...driven insights to stay ahead of an evolving threat landscape. We foster a culture of...  ...company. Trust. Service. Security . Director, Information Security - Cyber Threat...  ...identified through incidents, cyber threat intelligence, red team activity, and regulatory findings... 
    Intelligence

    American Express

    Charlotte, NC
    1 day ago
  • $150k - $258.75k

     ...Description: We are seeking a dynamic and experienced Director of Threat Detection & Incident Response to join our global efforts in...  ...and processes and coordinate mitigation of them. Threat Intelligence and Analysis. Utilize threat intelligence to inform response... 
    Intelligence
    Temporary work
    Local area
    Immediate start
    Remote work

    Johnson and Johnson

    United States
    1 day ago
  •  ...Director, Cyber Threat Intelligence (CTI) The Director, Cyber Threat Intelligence (CTI) leads an adversary-focused intelligence capability that enables proactive defense of BNY's global platforms, clients, and critical financial operations. This leader builds an all... 
    Intelligence
    Shift work

    BNY

    Washington DC
    2 days ago
  • $243.8k - $334.58k

    A leading cybersecurity firm is seeking a Director of Rapid Response to lead threat research coordination and communication during global events. This role...  ...ability, and significant experience in the threat intelligence lifecycle. Ideal candidates will collaborate with... 
    Intelligence
    Remote job

    Palo Alto Networks, Inc.

    Santa Clara, CA
    3 days ago
  • $243.8k - $334.58k

    Palo Alto Networks, Inc. is seeking a Director of Rapid Response for the Unit 42 Threat Intelligence team. This key position involves coordinating threat research and product protection during significant global events, providing actionable threat intelligence to safeguard... 
    Intelligence
    Full time

    Palo Alto Networks, Inc.

    Santa Clara, CA
    2 days ago
  • $162.54k - $243.8k

     ...being a Great Place to Work.  About the Role The Director of Cyber Threat Intelligence will lead a highly technical CTI function within...  ...Detection Engineering, SOC/IR, OT Security, Clinical Ops, Research IT); ability to influence without authority.  ~ Education... 
    Intelligence
    Temporary work
    Work at office
    Flexible hours
    3 days per week

    AstraZeneca

    Gaithersburg, MD
    3 days ago
  • $314.8k - $359.3k

     ...Sr. Director, Cyber Technical (Cyber Hunt, Logging and Threat Detection) Cybersecurity is essential to Capital One's commitment to protect our customers...  ...Direct the integration and deployment of Artificial Intelligence and Machine Learning models to advance threat... 
    Intelligence
    Full time
    Part time
    Local area

    Capital One Financial Corp

    McLean, VA
    8 days ago
  • $140.4k - $372.3k

     ...want you to help change the way we secure GitHub. GitHub’s Threat Intelligence team investigates sophisticated threat activity targeting GitHub...  ...: 10+ years experience in security analysis, security research, cyber security, security engineering, or relevant area OR Associate... 
    Intelligence
    Remote work

    GitHub

    New York, NY
    1 day ago
  • $147k - $310k

     ...Cyber Threat Simulation – Global Lead At BNY, our culture allows us to run our company better and enables employees' growth and...  ...across Cyber Security to include but not limited to: SOC, Threat Intelligence, Learning, and Communications teams. In this role, you'll... 
    Intelligence
    Temporary work
    For contractors
    Work experience placement
    Worldwide
    Flexible hours

    BNY

    New York, NY
    12 hours ago
  •  ...Director, Threat Intelligence Collections Manager CLS is the trusted party at the centre of the global FX ecosystem. Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective. Trillions of dollars' worth of currency flows through... 
    Intelligence
    Work at office
    Local area
    Work from home
    Flexible hours
    2 days per week

    CLS Group.

    Iselin, NJ
    1 day ago
  • $70k - $170k

     ...WP Cloud, WPScan, and Jetpack Protect. The role involves analyzing threats, building detection tools, and mitigating security issues. Ideal candidates will have 3+ years of experience in security research, strong PHP skills, and familiarity with threat models.... 
    Intelligence

    Automattic Careers

    New York, NY
    1 day ago
  • $195k - $262.7k

     ...A financial technology company is seeking a Sr. Manager, Cyber Threat Researcher to leverage cyber threat intelligence. The position involves creating detection mechanisms and maintaining expertise in current threat landscapes. Ideal candidates should have extensive experience... 
    Intelligence
    Remote work

    DEV

    New York, NY
    3 days ago
  • $90k - $120k

     ...UltraViolet Cyber is seeking a Cyber Threat Researcher (Level II) to join our TIDE team. You will engage in threat hunts, create intelligence-based detections, and leverage your expertise to help protect our customers. The ideal candidate has at least 4 years of experience... 
    Intelligence

    Medium

    New York, NY
    1 day ago
  • CrowdStrike is offering a fully remote Intelligence Analyst Internship for students in their penultimate...  ...on malware analysis, cybersecurity threat intelligence, and software engineering. Interns will conduct open-source research, learn about threat actor tactics, and develop... 
    Intelligence
    Internship
    Remote work

    CrowdStrike

    New Bremen, OH
    3 days ago
  • $166k - $220k

    A defense technology company seeks a Senior Threat and Attack Research Engineer to enhance cybersecurity efforts. The ideal candidate will monitor complex threats, analyze threat actor campaigns, and develop advanced tracking systems. Proficiency in programming and strong... 
    Intelligence

    Slope

    Seattle, WA
    12 hours ago
  • A cutting-edge cybersecurity firm is seeking a Sr. Threat Intelligence Analyst to enhance cybersecurity through actionable intelligence. You will play a key role in the intelligence cycle, profiling adversaries and collaborating across teams. Ideal candidates have extensive... 
    Intelligence

    TENEX.AI

    Overland Park, KS
    2 days ago
  • $159.3k - $273.2k

     ...Sr Director Of Ai/Ml Engineering Optum Tech is a global leader in health care innovation...  ...the most important frontiers of AI/ML research and development Partner with world-...  ...degree in Machine Learning, Artificial Intelligence, Computer Science, or a related field... 
    Intelligence
    Minimum wage
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work

    UMR

    United States
    1 day ago
  • KnowBe4, located in Arlington, Virginia, is seeking a Threat Researcher Lead to oversee threat intelligence initiatives within the Threat Research Lab. The successful candidate will lead a team of cyber security researchers, analyze threats, and provide expertise to enhance... 
    Intelligence

    KnowBe4

    Arlington, VA
    1 day ago
  • $129k - $171k

    A defense technology firm is looking for a Senior Threat and Attack Research Engineer in Ohio. This role involves monitoring cyber threats, developing tracking systems, and collaborating with security teams. Candidates should have strong programming and analytical skills... 
    Intelligence

    Slope

    Ashville, OH
    12 hours ago
  • A leading cybersecurity firm is seeking a Principal Threat Intelligence Researcher to deliver critical intelligence insights for clients. This remote role requires at least 7 years in the cyber threat intelligence field, exceptional analytical and communication skills,... 
    Intelligence
    Remote work

    Palo Alto Networks

    Arlington, VA
    1 day ago
  •  ...defense technology company in Boston is seeking a Senior Threat and Attack Research Engineer to analyze sophisticated cyber threats and develop...  .... The ideal candidate will have experience in threat intelligence and programming skills in languages such as Python and Rust... 
    Intelligence

    Slope

    Boston, MA
    2 hours ago
  • $40 per hour

     ...content and solve technical problems. Candidates should have over 2 years in cybersecurity fields like penetration testing or threat intelligence, along with some coding skills. This position offers flexible work hours and hourly pay starting at $40. Ideal applicants are... 
    Intelligence
    Remote job
    Hourly pay
    Flexible hours

    DataAnnotation

    Nashville, TN
    4 days ago
  • A defense technology company is seeking a Senior Threat and Attack Research Engineer in Washington, D.C. to monitor and analyze cyber threats against its products and infrastructure. The ideal candidate should have proven experience in analyzing complex cyber threats and... 
    Intelligence

    Slope

    Washington DC
    4 days ago
  •  ...Operations Research Analyst (ORSA) As an Operations Research Analyst (ORSA), you will...  ...units, focused on countering improvised threats and the networks that finance, build, or...  ...through integration of data from diverse intelligence disciplines, including SIGINT, MASINT, GEOINT... 
    Intelligence
    For contractors

    Beyond SOF

    Reston, VA
    12 hours ago
  • $166k - $220k

     ...Senior Threat And Attack Research Engineer Costa Mesa, California, United States Anduril Industries is a defense technology company with...  ...organization. The ideal candidate will combine threat intelligence knowledge with strong engineering skills to develop and implement... 
    Intelligence
    Full time
    Work experience placement

    anduril

    Costa Mesa, CA
    12 hours ago
  • $50k - $90k

     ...Associate Cyber Threat Researcher (Level I) UltraViolet Cyber is a leading platform-enabled unified security operations company providing...  ...Cyber Threat Researcher (Level I) to join our Threat Intelligence & Detection Engineering (TIDE) team. Your primary responsibilities... 
    Intelligence
    Temporary work
    Remote work

    UltraViolet Cyber

    United States
    4 days ago
  • $174.7k - $218.4k

     ...innovative Oncology programs. The Associate Director, Clinical Science will ensure the...  ...and methodology to ensure alignment with research objectives, and actively participate in...  ..., participates in competitive intelligence and/or other market/industry assessment... 
    Intelligence
    Work at office
    Immediate start
    Remote work
    Worldwide
    Home office
    Flexible hours

    Natera

    New York, NY
    1 day ago
  • $192k - $236k

     ...About the Job The Associate Director, Medical Science Liaison develops and expands a strong...  ...foster education, collaboration, and research opportunities that align with FMI’s...  ...of publication strategy. Gather market intelligence on competitor products and new products... 
    Intelligence
    Work experience placement
    Local area
    Remote work
    Relocation

    Foundation Medicine

    New York, NY
    1 day ago
  • Capital One National Association is seeking a Manager of Research & Talent Insights in McLean, Virginia. This role involves strategic talent mapping, market intelligence, and executive engagement. The ideal candidate will have at least 5 years of experience in executive... 
    Intelligence

    Capital One National Association

    Mc Lean, VA
    12 hours ago
  • $80.2k - $137k

     ...Amazon Global Specialty Recruiting is looking for an Research Recruiter to help the business scale by identifying and recruiting top...  ...specialist will conduct extensive market research, competitive intelligence and talent mapping to find and engage top talent across business... 
    Intelligence
    Flexible hours

    Amazon

    Seattle, WA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Director, Threat Intelligence Research. Be the first to apply!