Team Lead, Cyber Threat Intelligence



Our Trust Intelligence Platform helps organizations connect data, teams, and processes. Discover how OneTrust builds and operationalizes trust in business.

View company page

Strength in Trust  

At OneTrust, we exist to unlock every company's potential to thrive by doing what's good for people and planet. Using cutting-edge technology and a real-world approach to privacy, GRC, ethics, and ESG, we’ve created a no-nonsense platform to help supercharge the global push for Trust Intelligence. 

The Challenge

  • You will help us build, lead, and mature our threat intelligence capabilities
  • You will also develop and maintain a comprehensive set of threat intelligence processes to support operational, tactical, and strategic decision making
  • You will collaborate with other team leads to build and refine our SOC/SIEM/SOAR integration process and capabilities

Your Mission

  • Perform highly specialized review and evaluation of incoming cyber security information to resolve its usefulness for intelligence
  • Analyze threat information from various internal and external sources and synthesize and places intelligence information in context; draw insights about implications
  • Prepare formal/informal analysis and briefings to define threats to the organization. Lead efforts for appropriate mitigation
  • Provide collection and analysis of cyber security information that may be used to develop intelligence.
  • Performs activities to gather TTP on cyber threat actors to mitigate possible or real-time threats, protect against espionage or insider threats, or to support other intelligence activities
  • Conduct operational-level planning across the full range of cyber defense operations
  • Investigate cyber security events or crimes related to information technology (IT) systems, networks, and digital evidence
  • Collect, processes, preserve, analyze, and present agent, cloud, host-based and dark web evidence in support of network vulnerability and threat mitigation and/or criminal, fraud, or law enforcement investigations
  • Identify, analyze, and mitigate threats to internal information IT systems and/or networks
  • Develop best practices and advanced solutions to collect, fuse, and analyze high volumes of open source and proprietary threat reporting to help produce and use predictive and actionable cyber threat intelligence
  • Develop policies, procedures, governance, and other guidance for building and evolving cyber threat intelligence, SOC (Security Operations Center) and incident response team integration
  • Integrate and apply CTI (Cyber Threat Intelligence) reporting and knowledge of adversary activity into cybersecurity operations systems and processes
  • Develop and scope tasks to support cyber operations to achieve red, blue, and purple missions 

You Are

  • Expertise in multiple aspects of intelligence and cyber security
  • Ability to communicate clearly, both verbally and in writing
  • Ability to collaborate and coordinate with multiple teams and vendors
  • Ability to work independently and as part of a team
  • Ability to multitask and prioritize effectively
  • Keen attention to details, while keeping the big picture in mind
  • Ability to work with minimal supervision
  • Ability to mentor, train, and educate other security personnel
  • Bachelor’s degree in a related field or equivalent experience required
  • Must have demonstrable experience as an IT security professional
  • Solid grasp and experience applying common tools and analytical frameworks used to identify and describe cyber threat actors, actions, and capabilities (Diamond, VERIS, MITRE ATT&CK, etc.) and share threat intelligence (STIX/TAXII)
  • In-depth knowledge in the following fields is required: cybersecurity principles used to manage risks related to the use, processing, storage, and transmission of information or data; common information technology (IT) security controls (e.g.: firewalls, demilitarized zones, encryption); new and emerging information technology (IT) and cybersecurity technologies and risks; information technology (IT) supply chain and vulnerability risk best practices
  • Advanced planning/organizational, problem-solving, analytical, consulting, time management and decision-making skills required
  • Ability to effectively communicate technical security plans, strategies, and designs to all levels of the company
  • Must be detail oriented and able to maintain a high degree of accuracy

Extra Awesome

  • 5+ years' experience as a CTI analyst supporting cyber operations and incident response, with demonstrated application of CTI principles to include adversary methodologies and TTPs, IOCs (Indicators of Compromise), and malware analysis
  • 5+ years' experience identifying threat actor TTPs and campaigns and to gather information for reconnaissance, including large and unstructured data sets to identify trends and anomalies indicative of malicious cyber activities
  • 3+ years of hands-on technical expertise in at least one of the following areas: applied CTI & sharing, adversary emulation, incident response, defensive cyber operations, cyber analytics & malware analysis, cyber deception and adversary engagement, cyber effects and reverse engineering, or cyber forensics
  • 1+ years of people management experience
  • >1 Cyber Intelligence, Cloud and/or Security Certifications such as Certified Ethical Hacker (CEH), GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Pentester (GPEN), GIAC Open-Source Intelligence (GOSI) preferred
  • Background dealing with cyber security, fraud, and complex investigations


As an employee at OneTrust, you will be a part of the OneTeam. That means equity, bonuses, unlimited PTO, and 100% paid medical benefits (and that’s just the beginning!).  

Our employee rewards philosophy spans mental, physical, and emotional well-being because we want our people to succeed both in and out of the office. Some benefits differ depending on region, but here’s what you can expect from our OneTeam Total Rewards Program: 

  • Competitive Compensation: We offer top pay for top talent with competitive total packages including equity for all, performance bonuses, and retirement savings with match. We’re also committed to fair and equitable pay practices. 
  • Workstyle Flexibility: At home or in the office, we trust you to get the job done. Our people have the option to work in the office, fully remote, or a hybrid based on their role. Go green with commuter program discounts and in-office perks.  
  • Career Development: You’re not just joining any company; you’re joining the company that built the category-defining software platform for trust. You can become an expert and earn industry certifications with training and exams paid for by us and access to our learning & development program and guest speaker series.  
  • Employee Recognition: We celebrate our accomplishments the best way we know how – together. Our people are invited to attend employee appreciation social events (including our awesome annual holiday party), participate in ticket giveaways for local city events based on your home office location, and celebrate one another through our #CheersforPeers channel. 
  • Focus on Wellbeing: Take the vacation or volunteer - we have unlimited PTO globally. You’ll also have access to ClassPass memberships, generous company holidays and your birthday off, paid sick days, Employee Resource Groups (or, as we call them, Employee Trust Groups), and other ways to get connected or support company diversity, equity, and inclusion goals.  
  • Health Benefits: No package is complete without great health benefits. This role may receive company-paid employee healthcare premiums, parental leave, and access to mental health benefits and employee assistance programs. Specific benefits differ by location, so please check with your recruiter to specify what this role will receive. 

Our Commitment to You

When you join OneTrust you are stepping onto a launching pad — the countdown has begun. The destination? A career without boundaries working alongside a diverse and inclusive crew who is passionate about doing meaningful work. As a pioneer, your voice and expertise will help chart the direction of an entirely new industry — Trust. Our commitment to putting people first starts with you. Your growth is part of the mission. Our goal is to give you the power to embark on the next phase of your uniquely, unique career.

OneTrust provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.


Check out the following to learn more about OneTrust and its people: 

* Salary range is an estimate based on our salary survey 💰

Tags: Analytics CEH Cloud Cyber defense Encryption Firewalls Forensics GCFA GCIH GIAC Governance GPEN Incident response Malware MITRE ATT&CK Open Source Privacy Reverse engineering SIEM SOAR SOC Threat intelligence TTPs

Perks/benefits: Career development Competitive pay Equity Flex vacation Health care Home office stipend Medical leave Parental leave Salary bonus Startup environment Team events Unlimited paid time off

Regions: Remote/Anywhere North America
Country: United States
Job stats:  10  1  0
  • Share this job via
  • or

More jobs like this

Explore more InfoSec/Cybersecurity career opportunities

Find open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Analysis, Cryptography, Digital Forensics and Cyber Security in general, filtered by job title or popular skill, toolset and products used.