SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Obsidian Security is a leading SaaS security platform protecting 200+ global enterprises including Fortune 1000 companies like Snowflake, T-Mobile, and Algolia. Founded in 2017 and backed by top-tier investors like Greylock, Obsidian uniquely detects anomalous OAuth token activity and manages integration risks across SaaS applications like Microsoft 365 and Salesforce.
We are seeking a Threat Intelligence Lead to build and mature our threat intelligence function. This is a critical, high-impact role reporting to the Head of Security within the Trust Team, partnering closely with IT, Engineering, Product, GRC, and the Threat Research Lab.
Key responsibilities include:
**Threat Intelligence:** Collect and synthesize threat intelligence from commercial feeds, open-source reporting, ISACs, vendor advisories, researcher communities, and dark web sources. Assess applicability of emerging threats, campaigns, and vulnerabilities to both the Obsidian product and corporate infrastructure. Produce decision-grade intelligence products including threat advisories, actor and campaign profiles, and periodic briefings for technical teams and leadership. Track threat actors targeting SaaS, cloud, and identity infrastructure, maintaining a living view of relevant TTPs mapped to MITRE ATT&CK. Own the intelligence requirements process, defining collection priorities rather than reacting to incoming data.
**Threat Hunting and Detection:** Run structured, hypothesis-driven threat hunts across corporate and product environments based on IOCs, TTPs, and intelligence-derived leads. Operationalize indicators into detections and manage IOC lifecycle. Write and tune detection logic, playbooks, and response actions in partnership with incident response. Support incident investigations with attribution context and actor tradecraft analysis. Contribute to purple team exercises validating control effectiveness.
**Product Integration:** Be a power user of the Obsidian product, securing corporate assets and pressure-testing it like demanding customers. Identify use cases, provide feedback on in-development features, and reshape product workflows based on real-world threat intelligence needs.
The ideal candidate is highly technical, mission-driven, with deep analytical expertise, sound judgment, and the ability to separate signal from noise. You should thrive in dynamic, high-growth startup environments and operate effectively across cloud-native organizations with modern tech stacks. Ownership mentality, personal responsibility, and initiative are essential.