Job DescriptionThe Fraud Threat Intelligence (FTI) Lead is a senior individual contributor responsible for the design, build, implementation, and management of a new U.S. Bank Fraud Threat Intelligence (FTI) framework and capability positioned within Enterprise Fraud Strategy. This role establishes a net new intelligence capability informed by proven, world class cyber threat intelligence (CTI) practices and tailored to fraud and scam threats targeting U.S. Bank and its customers.
Operating with a high degree of independence, this role owns the architecture, operating model, and execution of the fraud threat intelligence function, including bi directional intelligence exchange with internal stakeholders, industry partners, federal law enforcement, vendors, and intelligence sharing communities. The role serves as a core integration point for fraud fusion, internally and externally, and works in close partnership with the Financial Crime Disruption Fraud Threat Hunting capability to enable proactive detection and disruption.
This role is also accountable for shepherding the enterprise adoption and operationalization of the FS ISAC Cyber Fraud Prevention Framework as a fraud "kill chain," embedding it into fraud intelligence, prevention, and disruption workflows.
Key ResponsibilitiesFraud Threat Intelligence Framework Ownership• Design, build, and operationalize the U.S. Bank Fraud Threat Intelligence (FTI) framework using lifecycle based intelligence models and adversary behavior analysis adapted to fraud and scams.
• Define and document the FTI operating model, including intelligence requirements, collection strategies, analytic methodologies, and dissemination standards.
• Own execution of the FTI capability from initial design through operational maturity.
Bi Directional Intelligence Exchange & External Engagement• Build and maintain bi directional intelligence exchange with internal stakeholders across fraud operations, fraud strategy, scam prevention, risk, compliance, and technology teams.
• Coordinate intelligence sharing with industry partners, vendors, FS ISAC, and federal law enforcement, ensuring appropriate governance, handling, and use of shared intelligence.
• Serve as a key contributor to external intelligence sharing forums, representing U.S. Bank's fraud intelligence interests.
Fraud Fusion (Internal & External)• Enable fraud fusion by synthesizing intelligence across internal fraud, cyber, scam, and financial crime sources, and external intelligence feeds.
• Translate intelligence into actionable insights that inform fraud prevention strategies, detection enhancements, and investigative priorities.
• Support convergence between fraud and cyber intelligence disciplines through shared language, frameworks, and analytic methods.
• Drive structured collaboration rather than ad hoc information sharing.
Fraud Threat Hunting Integration and Collaboration• Partner closely with the Financial Crime Disruption Fraud Threat Hunting function to provide intelligence driven hypotheses, indicators, and contextual insights.
• Ensure intelligence outputs directly inform proactive hunting, detection tuning, and disruption activities.
FS ISAC Cyber Fraud Prevention Framework Implementation• Lead the operational adoption of the FS ISAC Cyber Fraud Prevention Framework, applying its lifecycle based model as a fraud "kill chain" across fraud and scam use cases.
• Align fraud intelligence outputs to the framework's phases to support earlier detection, improved coordination, and more effective disruption of fraud schemes.
• Partner with internal teams to integrate the framework into fraud detection, investigation, and response workflows.
Intelligence Production & Stakeholder Communication• Produce strategic, operational, and tactical intelligence products (e.g., threat assessments, trend reports, tactical alerts) tailored to senior and operational audiences.
• Communicate intelligence clearly and concisely to technical, operational, and non technical audiences.
• Continuously evaluate and refine intelligence processes to improve timeliness, relevance, and impact.
Basic Qualifications- Bachelor's degree, or equivalent work experience
- Typically more than eight years of applicable experience
Preferred Skills/Experience - 7+ years experience in fraud intelligence, cyber threat intelligence, fusion centers, financial crime, or related disciplines
- Demonstrated experience building or standing up new intelligence capabilities
- Strong analytic, written, and verbal communication skills
- Experience applying cyber threat intelligence concepts (e.g., kill chains, TTP analysis, lifecycle models) to fraud or financial crime.
- Familiarity with FS-ISAC intelligence sharing and the Cyber Fraud Prevention Framework.
- Experience supporting or partnering with threat hunting or investigative teams.
- Knowledge of intelligence sharing standards, information handling, and governance practices.
LOCATION EXPECTATIONS: This role requires working from a U.S. Bank Location three (3) or more days per week.NOTE: This position is not eligible for current or future visa sponsorship.Benefits:Our approach to benefits and total rewards considers our team members' whole selves and what may be needed to thrive in and outside work. That's why our benefits are designed to help you and your family boost your health, protect your financial security and give you peace of mind. Our benefits include the following:
- Healthcare (medical, dental, vision)
- Basic term and optional term life insurance
- Short-term and long-term disability
- Pregnancy disability and parental leave
- 401(k) and employer-funded retirement plan
- Paid vacation (from two to five weeks depending on salary grade and tenure)
- Up to 11 paid holiday opportunities
- Adoption assistance
- Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law
Review our full benefits available by employment status here.
Posting may be closed earlier due to high volume of applicants.