Director, Threat Intelligence Research
Arctic Wolf Incident Response
Director, Threat Intelligence Research
At Arctic Wolf, you won't just watch the cybersecurity industry evolve – you'll help lead the change. Our global Pack is made up of people who thrive on solving hard problems, moving fast, and building technology that protects organizations around the world. We're proud to be recognized by Forbes, CNBC, Fortune, CRN, Bartner Peer Insights and IDC MarketScape – but what matters most is the work behind it: delivering real outcomes for customers through award winning innovation like our Aurora Platform.
If you're looking for meaningful work, smart teammates and the chance to make a real impact in a high-growth company that's redefining security operations, Arctic Wolf is the right place for you!
Our mission is simple: End Cyber Risk. We're looking for a Director, Threat Intelligence Research to be part of making that happen.
About the Role
This senior leadership role owns the strategy and execution of Cyber Threat Intelligence (CTI) at Arctic Wolf, an AI-native security operations company. The mission is singular: anticipate what will hurt our customers, and translate that foresight into prioritized, contextual intelligence that directly drives detection engineering, threat operations, and product outcomes. The Director leads multiple intelligence teams, sets collection and analytic priorities tied to Arctic Wolf's customer base, and builds an agentic-first operating model that transforms CTI into the engine of an AI-native security organization. The role is also a primary public face of Arctic Wolf threat research, driving rapid-response publications, executive briefings, media engagement, and industry keynotes that establish the company's authority in the threat landscape, on par with the standard set by leading research programs in the industry.
Job Scope
Owns the vision and execution of Arctic Wolf's Cyber Threat Intelligence function. Directs multiple intelligence teams, defines collection and analytic priorities tied to customer risk, and is accountable for the speed, relevance, and downstream impact of intelligence on detection engineering, threat operations, and product.
Key Responsibilities
- Drive detection engineering through intelligence-led collection and prioritization, ensuring every campaign, TTP, and threat actor tracked translates into a ranked detection backlog tied to customer risk.
- Anticipate what will hurt customers: define collection priorities, PIRs, and coverage goals grounded in Arctic Wolf's customer base, sectors, attack surface, and adversary landscape.
- Lead the rapid-response function for high-severity events (zero-days, mass exploitation, breach disclosures, geopolitically driven campaigns), coordinating cross-functional response and public communications.
- Partner with Data Science, Threat Operations, Detection Engineering, Product Management, and Engineering to productize intelligence, turning research into customer-facing capabilities, signals, and content.
- Build an agentic-first operating model: codify intelligence workflows as agentic systems, evaluate and adopt frontier AI tooling, and lead the team's transformation into AI-native analysts.
- Set the internal CTI frameworks (PIRs, ATT&CK alignment, attribution discipline, confidence and probability language, intel-to-detection pipeline) used across the company.
Expert Positioning Goal:
- Establish Arctic Wolf as a recognized authority in threat research through rapid-response publications, blogs, podcasts, and original research reports.
- Engage with PR, Communications, and Marketing to ensure timely, accurate, and high-impact external messaging during major incidents and disclosures, and to amplify research that defines the company's voice in the market.
- Speak at top-tier industry and government forums (e.g., RSA, Black Hat, FIRST, SANS Summits, FS-ISAC, InfraGard, ISAC and government exchanges) and represent Arctic Wolf in public-private partnerships.
- Brief customers, executives, and boards on the threats most relevant to their environment, sector, and risk profile.
Example Key Results:
- Launched an intelligence-driven detection prioritization program that measurably increased coverage of customer-relevant TTPs and reduced time from intel surface to deployed detection.
- Stood up a rapid-response capability that delivered authoritative public analysis of major incidents within hours, generating earned media, customer trust, and measurable share-of-voice in the threat research community.
- Transformed CTI workflows to agentic-first, with documented gains in throughput and analyst leverage; established AI-native tradecraft as the team standard.
- Productized intelligence outputs in partnership with Product, Data Science, and Engineering, shipping customer-facing capabilities, signals, and content packs that materially improved customer protection.
Complexity & Problem Solving
Leads strategic vision-setting at the intersection of threat research, detection engineering, AI and agentic systems, and product. Solves complex org-wide problems involving collection prioritization, intelligence-to-detection pipelines, attribution under uncertainty, AI-native workflow design, and cross-functional alignment with Data Science, Threat Operations, Detection Engineering, Product Management, and Engineering.
Knowledge & Experience
- Demonstrated leadership of a regional or global CTI function with direct, measurable impact on detection engineering, threat operations, or product outcomes — ideally within an MDR, MSSP, EDR/XDR, or major incident response practice.
- Expertise in threat actor attribution, campaign tracking, TTP analysis, and translating intelligence into ranked detection priorities and customer-relevant guidance.
- Hands-on track record of operating in agentic and AI-native workflows: building, evaluating, or leading teams that use LLM agents, retrieval pipelines, and automation as a primary mode of work, not as an experiment.
- Proven ability to partner with Data Science, Detection Engineering, Threat Operations, and Product Management to productize intelligence capabilities and ship customer-facing outcomes.
- Experience leading rapid-response programs and serving as a public-facing voice during major incidents: blogs, briefings, podcasts, conference keynotes, and earned media engagement with PR and Communications.
- Experience engaging with senior stakeholders, executive and board briefings, and public-private partnerships (e.g., ISACs, industry coalitions, government exchanges).
- Has developed other managers; strong people leadership skills with a bias toward building small, senior, AI-leveraged teams.
- Able to define and execute long-term intelligence strategies and metrics aligned with customer protection, detection coverage, time-to-detection for emerging threats, and product outcomes.
Collaboration & Interaction
Interfaces daily with Detection Engineering, Threat Operations, Data Science, Product Management, and Engineering leadership to align intelligence to customer protection. Engages senior leaders, customers, public/private coalitions, regulators, media, and the broader security community; shapes the team's external presence and reputation as a primary public face of Arctic Wolf threat research.
Achieve Results
Drives intelligence programs whose impact is measured in customer protection, detection coverage, time-to-detection for emerging threats, productized capabilities shipped, and earned authority in the threat research community. Develops managers and senior individual contributors operating natively with agentic systems.
About Arctic Wolf At Arctic Wolf, we foster a collaborative and inclusive work environment that thrives on diversity of thought, background, and culture. This is reflected in our multiple awards, including Top Workplace USA (2021-2024), Best Places to Work – USA (2021-2024), Great Place to Work – Canada (2021-2024), Great Place to Work – UK (2024), and Kununu Top Company – Germany (2024). Our commitment to bold growth and shaping the future of security operations is matched by our dedication to customer satisfaction, with over 7,000 customers worldwide and more than 2,000 channel partners globally. As we continue to expand globally and enhance our technology, Arctic Wolf remains the most trusted name in the industry. Our Values Arctic Wolf recognizes that success comes from delighting our customers, so we work together to ensure that happens every day. We believe in diversity and inclusion and truly value the unique qualities and unique perspectives all employees bring to the organization. And we appreciate that—by protecting people's and organizations' sensitive data and seeking to end cyber risk— we get to work in an industry that is fundamental to the greater good. We celebrate unique perspectives by creating a platform for all voices to be heard through our Pack Unity program. We encourage all employees to join or create a new alliance. See more about our Pack Unity here. We also believe and practice corporate responsibility, and have recently joined the Pledge 1% Movement, ensuring that we continue to give back to our community. We know
- ...driven insights to stay ahead of an evolving threat landscape. We foster a culture of... ...company. Trust. Service. Security . Director, Information Security - Cyber Threat... ...identified through incidents, cyber threat intelligence, red team activity, and regulatory findings...Intelligence
$150k - $258.75k
...Description: We are seeking a dynamic and experienced Director of Threat Detection & Incident Response to join our global efforts in... ...and processes and coordinate mitigation of them. Threat Intelligence and Analysis. Utilize threat intelligence to inform response...IntelligenceTemporary workLocal areaImmediate startRemote work- ...Director, Cyber Threat Intelligence (CTI) The Director, Cyber Threat Intelligence (CTI) leads an adversary-focused intelligence capability that enables proactive defense of BNY's global platforms, clients, and critical financial operations. This leader builds an all...IntelligenceShift work
$243.8k - $334.58k
A leading cybersecurity firm is seeking a Director of Rapid Response to lead threat research coordination and communication during global events. This role... ...ability, and significant experience in the threat intelligence lifecycle. Ideal candidates will collaborate with...IntelligenceRemote job$243.8k - $334.58k
Palo Alto Networks, Inc. is seeking a Director of Rapid Response for the Unit 42 Threat Intelligence team. This key position involves coordinating threat research and product protection during significant global events, providing actionable threat intelligence to safeguard...IntelligenceFull time$162.54k - $243.8k
...being a Great Place to Work. About the Role The Director of Cyber Threat Intelligence will lead a highly technical CTI function within... ...Detection Engineering, SOC/IR, OT Security, Clinical Ops, Research IT); ability to influence without authority. ~ Education...IntelligenceTemporary workWork at officeFlexible hours3 days per week$314.8k - $359.3k
...Sr. Director, Cyber Technical (Cyber Hunt, Logging and Threat Detection) Cybersecurity is essential to Capital One's commitment to protect our customers... ...Direct the integration and deployment of Artificial Intelligence and Machine Learning models to advance threat...IntelligenceFull timePart timeLocal area$140.4k - $372.3k
...want you to help change the way we secure GitHub. GitHub’s Threat Intelligence team investigates sophisticated threat activity targeting GitHub... ...: 10+ years experience in security analysis, security research, cyber security, security engineering, or relevant area OR Associate...IntelligenceRemote work$147k - $310k
...Cyber Threat Simulation – Global Lead At BNY, our culture allows us to run our company better and enables employees' growth and... ...across Cyber Security to include but not limited to: SOC, Threat Intelligence, Learning, and Communications teams. In this role, you'll...IntelligenceTemporary workFor contractorsWork experience placementWorldwideFlexible hours- ...Director, Threat Intelligence Collections Manager CLS is the trusted party at the centre of the global FX ecosystem. Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective. Trillions of dollars' worth of currency flows through...IntelligenceWork at officeLocal areaWork from homeFlexible hours2 days per week
$70k - $170k
...WP Cloud, WPScan, and Jetpack Protect. The role involves analyzing threats, building detection tools, and mitigating security issues. Ideal candidates will have 3+ years of experience in security research, strong PHP skills, and familiarity with threat models....Intelligence$195k - $262.7k
...A financial technology company is seeking a Sr. Manager, Cyber Threat Researcher to leverage cyber threat intelligence. The position involves creating detection mechanisms and maintaining expertise in current threat landscapes. Ideal candidates should have extensive experience...IntelligenceRemote work$90k - $120k
...UltraViolet Cyber is seeking a Cyber Threat Researcher (Level II) to join our TIDE team. You will engage in threat hunts, create intelligence-based detections, and leverage your expertise to help protect our customers. The ideal candidate has at least 4 years of experience...Intelligence- CrowdStrike is offering a fully remote Intelligence Analyst Internship for students in their penultimate... ...on malware analysis, cybersecurity threat intelligence, and software engineering. Interns will conduct open-source research, learn about threat actor tactics, and develop...IntelligenceInternshipRemote work
$166k - $220k
A defense technology company seeks a Senior Threat and Attack Research Engineer to enhance cybersecurity efforts. The ideal candidate will monitor complex threats, analyze threat actor campaigns, and develop advanced tracking systems. Proficiency in programming and strong...Intelligence- A cutting-edge cybersecurity firm is seeking a Sr. Threat Intelligence Analyst to enhance cybersecurity through actionable intelligence. You will play a key role in the intelligence cycle, profiling adversaries and collaborating across teams. Ideal candidates have extensive...Intelligence
$159.3k - $273.2k
...Sr Director Of Ai/Ml Engineering Optum Tech is a global leader in health care innovation... ...the most important frontiers of AI/ML research and development Partner with world-... ...degree in Machine Learning, Artificial Intelligence, Computer Science, or a related field...IntelligenceMinimum wageFull timeWork experience placementWork at officeLocal areaRemote work- KnowBe4, located in Arlington, Virginia, is seeking a Threat Researcher Lead to oversee threat intelligence initiatives within the Threat Research Lab. The successful candidate will lead a team of cyber security researchers, analyze threats, and provide expertise to enhance...Intelligence
$129k - $171k
A defense technology firm is looking for a Senior Threat and Attack Research Engineer in Ohio. This role involves monitoring cyber threats, developing tracking systems, and collaborating with security teams. Candidates should have strong programming and analytical skills...Intelligence- A leading cybersecurity firm is seeking a Principal Threat Intelligence Researcher to deliver critical intelligence insights for clients. This remote role requires at least 7 years in the cyber threat intelligence field, exceptional analytical and communication skills,...IntelligenceRemote work
- ...defense technology company in Boston is seeking a Senior Threat and Attack Research Engineer to analyze sophisticated cyber threats and develop... .... The ideal candidate will have experience in threat intelligence and programming skills in languages such as Python and Rust...Intelligence
$40 per hour
...content and solve technical problems. Candidates should have over 2 years in cybersecurity fields like penetration testing or threat intelligence, along with some coding skills. This position offers flexible work hours and hourly pay starting at $40. Ideal applicants are...IntelligenceRemote jobHourly payFlexible hours- A defense technology company is seeking a Senior Threat and Attack Research Engineer in Washington, D.C. to monitor and analyze cyber threats against its products and infrastructure. The ideal candidate should have proven experience in analyzing complex cyber threats and...Intelligence
- ...Operations Research Analyst (ORSA) As an Operations Research Analyst (ORSA), you will... ...units, focused on countering improvised threats and the networks that finance, build, or... ...through integration of data from diverse intelligence disciplines, including SIGINT, MASINT, GEOINT...IntelligenceFor contractors
$166k - $220k
...Senior Threat And Attack Research Engineer Costa Mesa, California, United States Anduril Industries is a defense technology company with... ...organization. The ideal candidate will combine threat intelligence knowledge with strong engineering skills to develop and implement...IntelligenceFull timeWork experience placement$50k - $90k
...Associate Cyber Threat Researcher (Level I) UltraViolet Cyber is a leading platform-enabled unified security operations company providing... ...Cyber Threat Researcher (Level I) to join our Threat Intelligence & Detection Engineering (TIDE) team. Your primary responsibilities...IntelligenceTemporary workRemote work$174.7k - $218.4k
...innovative Oncology programs. The Associate Director, Clinical Science will ensure the... ...and methodology to ensure alignment with research objectives, and actively participate in... ..., participates in competitive intelligence and/or other market/industry assessment...IntelligenceWork at officeImmediate startRemote workWorldwideHome officeFlexible hours$192k - $236k
...About the Job The Associate Director, Medical Science Liaison develops and expands a strong... ...foster education, collaboration, and research opportunities that align with FMI’s... ...of publication strategy. Gather market intelligence on competitor products and new products...IntelligenceWork experience placementLocal areaRemote workRelocation- Capital One National Association is seeking a Manager of Research & Talent Insights in McLean, Virginia. This role involves strategic talent mapping, market intelligence, and executive engagement. The ideal candidate will have at least 5 years of experience in executive...Intelligence
$80.2k - $137k
...Amazon Global Specialty Recruiting is looking for an Research Recruiter to help the business scale by identifying and recruiting top... ...specialist will conduct extensive market research, competitive intelligence and talent mapping to find and engage top talent across business...IntelligenceFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Threat Intelligence Research. Be the first to apply!
- research lab manager United States
- research finance manager United States
- senior research manager United States
- research supervisor United States
- clinical research director United States
- research manager United States
- account manager market research United States
- research coordinator remote United States
- qualitative research director United States
- research operations manager United States

