Hiring.Camp

Senior Threat Intelligence Analyst

Idme

·

Today

Location
McLean, Virginia; Mountain View, California, United States · McLean, Virginia · Mountain View, California, United States
Workplace
Remote, Onsite
Department
Fraud
Seniority
Senior
Experience
5+ years
Source
Greenhouse

Description

Company Overview

ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly login across websites without having to create a new login and verify their identity again. Over 152 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600+ consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships. ID.me’s technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to “No Identity Left Behind” to enable all people to have a secure digital identity. To learn more, visit https://network.id.me/.

ID.me is a full-time, in-office culture. Unless a specific job description explicitly states otherwise, all roles are on-site five days per week at one of our offices in McLean, VA; Mountain View, CA; New York City, NY; or Tampa, FL. Certain roles — such as field-based sales or other remote-by-design positions — may have different work arrangements as noted in their individual postings.

At ID.me, we embrace the thoughtful use of AI tools in our daily work and there are even occasions where we leverage AI in our hiring process. However, during the interview process, we want to understand your individual skills and experiences. Therefore, we have guidelines on how AI can be appropriately used during your application and interviews which can be found here.

ID.me is looking for a senior threat intelligence professional to lead technical tracking of the adversaries targeting the identity verification ecosystem, and to turn that tracking into decisions the business acts on. Identity fraud is an industrialized market of credential and document vendors, injection and deepfake tooling, synthetic identity brokers, and organized account takeover crews. This role sits directly across from it.

You will own intelligence coverage for a defined set of threats end to end: setting the collection strategy, running the research, building the models and tooling, and delivering the finished product to the people who need it, from detection engineers to executives and government partners. This is a senior individual-contributor role with high autonomy and real influence over security and product direction. You will also be a technical mentor to the analysts around you and a standard-setter for how the team does analysis.

Responsibilities

  • Own an intelligence portfolio. Take end-to-end responsibility for tracking a set of threat actors, fraud typologies, or ecosystems targeting ID.me and our partners, from collection through analysis to delivery and follow-up.
  • Set collection strategy. Define and prioritize intelligence requirements in partnership with security, fraud, product, and company leadership. Identify gaps in current coverage and close them.
  • Run technical collection at depth. Conduct sustained collection and source development across deep and dark web forums, illicit marketplaces, encrypted messaging platforms, and closed communities, using sound tradecraft and operational security.
  • Hunt emerging activity. Proactively hunt for new actor activity, tooling, and TTPs across internal telemetry and external sources, and pull threads before they become incidents.
  • Produce finished intelligence. Write assessments that hold up to scrutiny, with clear judgments, stated confidence levels, articulated assumptions, and specific recommendations, for audiences ranging from engineers to the executive team to external partners.
  • Make intelligence operational. Convert research into detections, fraud signals, blocklists, enrichment, and platform data. Work with detection engineering, data science, and product to get it deployed and measure whether it worked.
  • Advance the team's analytic tradecraft. Improve threat modeling standards, structured analytic methods, reporting templates, source evaluation, and the team's use of frameworks such as MITRE ATT&CK and the Diamond Model.
  • Build tooling and automation. Identify where manual work is limiting coverage and build or specify the tooling, pipelines, and enrichment to remove it.
  • Mentor and raise the bar. Coach analysts on collection tradecraft, analytic writing, and structured analysis. Review their work and help develop their judgment.
  • Represent the function. Brief senior leadership, partners, and where appropriate, industry peer groups, law enforcement, and information-sharing communities.

Qualifications

  • 5+ years of experience in threat intelligence, cyber threat hunting, fraud intelligence, or a closely related discipline, including experience producing finished intelligence for decision-makers.
  • 3+ years of hands-on collection across the deep and dark web, including illicit marketplaces and encrypted communication platforms, with demonstrated tradecraft and operational security practices.
  • Deep, applied experience with common analysis models and frameworks (MITRE ATT&CK, the Diamond Model, kill chain, structured analytic techniques). Not just familiarity, but a track record of using them to reach and defend analytic judgments.
  • Demonstrated ability to take ambiguous, fragmentary, and conflicting information and produce a clear assessment with appropriately expressed confidence.
  • Exceptional written and verbal communication, including experience writing for both deeply technical and executive audiences.
  • Track record of working independently: scoping your own problems, setting priorities, and driving work to a result without close direction.
  • Proven ability to influence stakeholders outside of security, and to translate intelligence into changes other teams actually make.

Preferred Qualifications

  • Experience with identity fraud, account takeover, synthetic identity, document and biometric fraud, or the fraud-as-a-service ecosystem.
  • Strong SQL skills for independent data analysis at scale, and scripting in Python or similar for collection, enrichment, and automation.
  • Experience turning intelligence into production detections or fraud controls alongside engineering and data science teams.
  • Experience mentoring analysts or leading intelligence projects across multiple contributors.
  • Relevant certifications such as GCTI, GREM, GCFA, GOSI, CISSP, or Security+.
  • Working proficiency in a foreign language relevant to threat actor communities.
  • Experience in a regulated or government-facing environment, or supporting external partners with intelligence products.

ID.me maintains a work environment free from discrimination, where employees are treated with dignity and respect. All ID.me employees share in the responsibility for fulfilling our commitment to equal employment opportunity. ID.me does not discriminate against any employee or applicant on the basis of age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. ID.me adheres to these principles in all aspects of employment, including recruitment, hiring, training, compensation, promotion, benefits, social and recreational programs, and discipline. In addition, ID.me's policy is to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations and ordinances where a particular employee works. Upon request we will provide you with more information about such accommodations.

Please review our Privacy Policy, including our CCPA policy, at id.me/privacy. If you provide ID.me with any personally identifiable information you confirm that you have read and agree to be bound by the terms and conditions set out in our Privacy Policy.

ID.me participates in E-Verify.

Skills

PythonSQLData ScienceCISSP

Similar Jobs

30

Senior Manager, Threat Intelligence

Kroll · United States, US

Yesterday

Senior Associate, Threat Intelligence

Kroll · United States, US

Yesterday

Senior Director, Product - Threat Intelligence & Detections

Arcticwolf · Office - CAN - Ontario, Waterloo, Canada +1 · Remote

Yesterday

Senior Director, Cyber Threat Intelligence

Kroll · New York, NY, United States, US

2 days ago

Senior Cyber Threat Intelligence Analyst

Keybank · 4910 Tiedeman Road, Brooklyn, OH, United States of America +1 · Remote

2 days ago

Sr. Manager, Cyber Threat Research & Intelligence

Adobe · San Jose, United States of America +2

1 week ago

Senior Cyber Threat Intelligence Analyst

Job Listings · Bangalore, India

1 week ago

Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response

Xplor Technologies · Auckland, Auckland, New Zealand · Remote

1 week ago

Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response

Xplor Technologies · Atlanta, GA, United States · Remote

1 week ago

Sr Threat Intelligence Investigator

Oracle · Nashville, TN, United States, US

2 weeks ago

Senior Manager, Head of Cyber Threat Intelligence

Globe · NCR - WGC, Philippines

2 weeks ago

Sr. Security Engineer , European Sovereign Cloud (ESC) Threat Intelligence

Amazon

2 weeks ago

Senior Cyber Threat Intelligence (CTI) Analyst

Livenation · Remote - United Kingdom +1 · Remote

2 weeks ago

Senior Research Engineer, Threat Intelligence

SecurityScorecard · Remote (United States) · Remote

3 weeks ago

Senior Threat Intelligence Analyst

Mastercard · Waterloo, Belgium

3 weeks ago

Senior Cybersecurity Expert (Threat Intelligence) m/f

Robert Bosch · Warszawa, Województwo mazowieckie, Poland · Hybrid

4 weeks ago

Sr. Threat Hunting Intelligence Analyst II

Crowdstrike · SAU Remote, Saudi Arabia +1 · Remote

1 month ago

Senior Threat Intelligence Analyst -UK

Team Cymru · London, United Kingdom · Remote

1 month ago

Sr. Threat Hunting Intelligence Analyst (Remote, East/Central)

Crowdstrike · USA VA Remote, United States of America +36 · Remote

1 month ago

Senior Full Stack Software Engineer, Threat Intelligence Services 

Proofpoint · Arizona, United States of America +10

1 month ago

Senior Threat Intelligence Analyst

Trellix · US, Virginia, Reston, United States of America · Onsite

1 month ago

Sr.Product Manager - Threat Intelligence Analytics

Recordedfuture · London, UK +1

1 month ago

Cyberspace Intelligence Threat Analyst, Senior

Leidos · 2586 Fort Meade MD, United States of America · Onsite

1 month ago

Senior Cyber Threat Intelligence (CTI) Engineer (f/m)

Robert Bosch · Warszawa, Województwo mazowieckie, Poland · Hybrid

2 months ago

Senior Research Engineer, Threat Intelligence

SecurityScorecard · Remote (Atlanta, GA) · Remote

2 months ago

Senior Research Engineer, Threat Intelligence

SecurityScorecard · Remote (Pittsburgh, PA) · Remote

2 months ago

Senior Research Engineer, Threat Intelligence

SecurityScorecard · Remote (Boston, MA) · Remote

2 months ago

Senior Research Engineer, Threat Intelligence

SecurityScorecard · Remote (Colorado Springs, CO) · Remote

2 months ago

Senior Research Engineer, Threat Intelligence

SecurityScorecard · Remote (Raleigh, NC) · Remote

2 months ago

Senior Research Engineer, Threat Intelligence

SecurityScorecard · Hybrid (Austin, TX) · Remote, Hybrid

2 months ago