CronJobs

security jobs

Senior Threat Intelligence Analyst

ID.me · McLean, Virginia; Mountain View, California, United States

onsiteseniorPosted Sep 16, 2026PythonSQLMITRE ATT&CKDiamond ModelDark Web AnalysisThreat Hunting

Apply on the employer site

About this role

**Senior Threat Intelligence Analyst** **About ID.me** ID.me is a next-generation digital identity wallet used by over 152 million users across 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. We're committed to secure digital identity verification. **The Role** Lead technical tracking of adversaries targeting the identity verification ecosystem and turn that intelligence into business decisions. Own end-to-end intelligence coverage for defined threat sets: collection strategy, research, modeling, tooling, and delivery to detection engineers, executives, and government partners. **Key Responsibilities** • Own an intelligence portfolio tracking threat actors, fraud typologies, and ecosystems • Set collection strategy and identify coverage gaps • Conduct sustained technical collection across deep/dark web forums, marketplaces, and encrypted platforms • Hunt emerging activity and proactively identify new TTPs • Produce finished intelligence with clear judgments and confidence levels • Convert research into detections, fraud signals, and blocklists • Advance team analytic tradecraft and frameworks (MITRE ATT&CK, Diamond Model) • Build tooling and automation to scale coverage • Mentor analysts and raise team standards • Brief leadership, partners, and external stakeholders **Required Qualifications** • 5+ years threat intelligence, cyber threat hunting, or fraud intelligence experience • 3+ years hands-on deep/dark web collection with strong tradecraft • Applied expertise with MITRE ATT&CK, Diamond Model, and structured analysis • Ability to produce clear assessments from ambiguous/conflicting information • Exceptional written and verbal communication • Track record of independent work and stakeholder influence **Preferred Qualifications** • Identity fraud, account takeover, or synthetic identity experience • SQL and Python scripting skills • Experience operationalizing intelligence into production detections • Analyst mentoring or project leadership experience • Relevant certifications (GCTI, GREM, GCFA, CISSP, Security+) • Foreign language proficiency relevant to threat actors • Government or regulated environment experience **Work Environment** Full-time, in-office (5 days/week) at McLean VA, Mountain View CA, New York City NY, or Tampa FL locations.

Listing freshness

CronJobs last confirmed this listing 58m ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord