SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Threat Intelligence Analyst

ID.me - McLean, VA, United States - In-office - posted 2026-09-16

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

ID.me is seeking a Senior Threat Intelligence Analyst to lead technical tracking of adversaries targeting the identity verification ecosystem and translate that intelligence into business decisions. The identity fraud market is industrialized, spanning credential and document vendors, deepfake tooling, synthetic identity brokers, and organized account takeover crews. This senior individual-contributor role sits at the center of defending against these threats. You will own end-to-end intelligence coverage for a defined set of threats: setting collection strategy, running research, building models and tooling, and delivering finished intelligence to detection engineers, executives, and government partners. This is a high-autonomy role with real influence over security and product direction. You will mentor analysts on the team and set standards for how the organization conducts analysis. Key responsibilities include owning an intelligence portfolio tracking threat actors and fraud typologies; setting collection strategy in partnership with security, fraud, product, and leadership; conducting sustained collection across deep and dark web forums, illicit marketplaces, and encrypted platforms using sound tradecraft; proactively hunting for new actor activity and TTPs; producing finished intelligence assessments with clear judgments and confidence levels for diverse audiences; converting research into detections, fraud signals, and blocklists; advancing the team's analytic tradecraft through improved threat modeling and structured methods; building tooling and automation to remove manual bottlenecks; mentoring analysts; and representing the function to senior leadership and external partners. ID.me is a full-time, in-office culture with five days per week at offices in McLean, VA; Mountain View, CA; New York City, NY; or Tampa, FL (unless a specific role states otherwise). Requirements: - 5+ years of experience in threat intelligence, cyber threat hunting, fraud intelligence, or closely related discipline, including producing finished intelligence for decision-makers - 3+ years of hands-on collection across deep and dark web, including illicit marketplaces and encrypted communication platforms, with demonstrated tradecraft and operational security - Deep, applied experience with analysis models and frameworks (MITRE ATT&CK, Diamond Model, kill chain, structured analytic techniques)—not just familiarity, but a track record of using them to reach and defend judgments - Demonstrated ability to take ambiguous, fragmentary, and conflicting information and produce clear assessments with appropriately expressed confidence - Exceptional written and verbal communication for both technical and executive audiences - Track record of working independently: scoping problems, setting priorities, driving work to completion without close direction - Proven ability to influence stakeholders outside security and translate intelligence into changes other teams implement Preferred qualifications include experience with identity fraud, account takeover, synthetic identity, document and biometric fraud, or fraud-as-a-service ecosystems; strong SQL skills and Python/scripting for data analysis and automation; experience turning intelligence into production detections alongside engineering and data science teams; experience mentoring analysts or leading multi-contributor intelligence projects; relevant certifications (GCTI, GREM, GCFA, GOSI, CISSP, Security+); foreign language proficiency relevant to threat actor communities; and experience in regulated or government-facing environments.

Similar roles