Threat Intelligence ManagerThe OpportunityThe Threat Intelligence Manager oversees the strategic and operational activities of the Threat Intelligence program, ensuring alignment with organizational goals and industry best practices. This role is responsible for managing personnel, maturing intelligence capabilities, driving intelligence-driven decision-making, and fostering cross-departmental collaboration. The manager provides leadership for the organization's cyber threat intelligence (CTI) program, ensuring actionable intelligence is delivered to stakeholders to strengthen the organization's security posture and support informed risk management. What You'll Do- Monitor and analyze the global threat landscape to identify emerging threats, adversary TTPs, vulnerabilities, and industry-specific risks.
- Collect, analyze, and produce actionable cyber threat intelligence at the tactical and operational level.
- Produce threat reports, indicators of compromise (IOCs), adversary profiles, and briefings for security operations, incident response, and vulnerability management stakeholders.
- Track phishing, business email compromise (BEC), and other email-borne social engineering campaigns targeting Mimecast customers.
- Analyze phishing kits, malicious URLs, and email-based malware delivery techniques to identify emerging tactics.
- Produce intelligence on social engineering trends, including impersonation, pretexting, and credential-harvesting techniques used in email attacks.
- Partner with detection engineering to translate email threat intelligence into improved phishing and social engineering detection.
- Track and map adversary tactics, techniques, and procedures against frameworks such as MITRE ATT&CK.
- Support the integration of threat intelligence into detection engineering, vulnerability prioritization, and other security tooling and workflows.
- Help define and refine intelligence requirements and collection priorities.
- Use threat intelligence platforms (TIPs) and automation to improve the speed, accuracy, and scale of intelligence production.
- Conduct quality reviews of intelligence products to ensure consistency, accuracy, and actionable outcomes.
- Act as an intelligence resource during security incidents, providing adversary context and threat assessments to support response.
- Track geopolitical events, cybercriminal activity, nation-state operations, and emerging technologies that may impact the organization or our customers.
- Maintain working relationships with commercial intelligence vendors, ISACs, and industry-sharing communities to source and validate intelligence.
What You'll Bring- Experience conducting cyber threat intelligence analysis at the tactical, operational, or strategic level.
- Working knowledge of the MITRE ATT&CK framework and threat-informed defense concepts.
- Experience with threat intelligence platforms.
- Familiarity with OSINT collection techniques and tools.
- Experience analyzing malware, phishing campaigns, and indicators of compromise (IOCs).
- Experience analyzing business email compromise (BEC) and other email-borne social engineering threats.
- Understanding of email authentication and anti-spoofing standards (SPF, DKIM, DMARC).
- Familiarity with phishing kit analysis, URL and domain reputation analysis, and email header forensics.
- Strong analytical writing skills, with the ability to produce clear, actionable intelligence reports and briefings.
- Familiarity with intelligence-sharing standards such as STIX/TAXII.
- Bachelor's degree in a related field or equivalent experience; industry certifications (e.g., GCTI, CTIA) are a plus.
Strongly Preferred- Experience producing and delivering recurring intelligence products, such as quarterly threat landscape reports and executive-level threat briefs.
- Experience developing and presenting webinars, briefings, or other public-facing threat intelligence content to customers, partners, or industry audiences.
- Experience integrating threat intelligence feeds with SIEM or SOAR platforms.
- Familiarity with dark web monitoring and closed-source intelligence sources.
- Experience with email security platforms or secure email gateways.
LocationThis role follows Mimecast's hybrid working model, with employees expected in the office at least two days per week. Working together in person fosters collaboration, communication, and learning, drives innovation between teams, and strengthens the interpersonal connections that keep a global team running smoothly.
Join our Threat Intelligence team to accelerate your career, working with cutting-edge technologies and contributing to analysis that has real, direct customer impact. You will be immersed in a dynamic environment that recognizes and celebrates your achievements.
Mimecast is on a path of steady, healthy growth, investing in people who bring the skills and expertise to raise our technical capability, operational maturity, and customer success to the next level. Every voice and every action matters here.
Mimecast offers formal and on-the-job learning opportunities, maintains a comprehensive benefits package that helps our employees and their family members sustain a healthy lifestyle, and offers the chance to work across cross-functional teams to build your knowledge.
The base salary range for this position is $148,000-$222,000 plus benefits. This range represents the minimum and maximum new hire compensation for this role. The position may also be eligible for incentive plans and additional benefits, in accordance with company policy and local regulations. Our salary ranges are determined by role, level, and location with individual compensation also dependent on factors such as qualifications, experience, and skills. Final offers will reflect these considerations and may vary accordingly.