SlipstreamJobsFresh Startup & VC-Backed Jobs

Manager, Threat Intelligence

PDI Technologies - Remote - Remote - posted 2026-10-01

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

PDI Technologies is seeking a Manager of Threat Intelligence to lead and grow a remote team of analysts, hunters, and detection engineers. You will own the full threat intelligence lifecycle—from defining intelligence requirements with SOC leadership and customers through collection, analysis, and feedback loops. The role combines people leadership with hands-on technical work: you'll spend time hunting, writing intelligence products, and building detections alongside your team of four. Key responsibilities include: **Team Leadership & Development**: Hire, coach, and develop remote team members with clear priorities and career paths. Partner with SOC, Incident Response, and Security Engineering leaders to improve detection, response, and customer outcomes. **Intelligence Program Building**: Define intelligence requirements and deliver strategic, operational, and tactical products including actor profiles, campaign analysis, industry threat briefs, and customer-specific reports. Track financially motivated groups, payment fraud operations, and ransomware crews targeting retail and hospitality. **Detection Strategy & Execution**: Own detection content strategy across SIEM and EDR/XDR platforms, including development, testing, tuning, and coverage measured against MITRE ATT&CK. Run hypothesis-driven threat hunts across customer environments and feed findings into new detections. Use automation and AI to scale enrichment, triage, and reporting. **Incident Support & Customer Engagement**: Provide intelligence context during major incidents and lead complex escalations. Serve as a trusted advisor to customers through briefings, reports, and presentations for technical and executive audiences. Run the team on clear metrics such as detection coverage, hunt findings, reporting timeliness, and customer satisfaction. **Success Milestones**: In the first 90 days, assess the team, tooling, and detection coverage while aligning on intelligence requirements. By 6 months, establish a regular cadence of industry threat reporting and an ATT&CK coverage baseline. By 12 months, achieve measurable gains in detection coverage and hunt-driven findings, positioning the team as the go-to source on threats to the industry. **Requirements** *Required:* - 8+ years in cybersecurity across threat intelligence, threat hunting, incident response, detection engineering, or security operations - 3+ years managing technical security teams, including hiring and developing people - Deep knowledge of adversary tactics and analysis frameworks (MITRE ATT&CK, intelligence lifecycle, Diamond Model) - Track record of producing finished intelligence for both technical and executive audiences - Hands-on experience with SIEM platforms (FortiSIEM, Microsoft Sentinel, Splunk, Google Chronicle, ArcSight) and EDR/XDR platforms with query languages (KQL, SPL, or similar) - Experience supporting complex investigations and incident response - Excellent written, verbal, and presentation communication skills; ability to translate technical findings into business risk - Bachelor's degree in a related field or equivalent experience *Nice to have:* - Experience at an MSSP or MDR provider serving many customers - Background in retail, hospitality, or payments environments, including POS systems or PCI DSS - Detection-as-code, Sigma, SOAR, or scripting (Python) - Experience with threat intelligence platforms and feeds (MISP, Recorded Future) - Cloud and SaaS investigations across Azure, AWS, or Microsoft 365 - Active involvement in intelligence-sharing communities such as RH-ISAC - Certifications such as GCTI, GCFA, GCIH, GREM, or CISSP

Similar roles