Bachelor's degree in cyber security, Computer Science, or related field.
4+ years of experience in cyber incident response, threat intelligence, or analytical work.
Experience leading negotiations and communications in ransomware cases.
Strong writing and presentation skills for high-pressure situations.
Familiarity with threat actor behaviors, tactics, techniques, and malware families.
Responsibilities
Lead communications and negotiations for ransomware and cyber extortion cases.
Develop communication strategies and maintain records for negotiation progress.
Analyze threat actors and campaigns to provide insights for incident responses.
Mentor junior analysts and set standards for documentation and reporting.
Collaborate with cross-functional teams to ensure timely communication and intelligence sharing.
Benefits
Work remotely from anywhere in the USA.
Mentorship opportunities within a specialized team.
Involvement in cutting-edge cyber threat intelligence work.
Dynamic role within a rapidly evolving field.
Access to professional development and further certification opportunities.
Full Job Description
Job Title: Senior Cyber Threat Analyst Location: Remote, USA Reports to: Managing Director Employment Type: Full time Job Req ID: 2026 Req Begin Date: 8/10/2026 Job Summary Join us in shaping the future of TMHCC-CPLG as a key contributor in our cyber extortion and threat intelligence function, Vector3. You will lead threat actor communications and negotiation support for ransomware and cyber extortion engagements, helping shape case strategy through direct communication, disciplined documentation, and sound judgment. You will also leverage advanced analytical skills to understand threat actors, campaigns, tactics, techniques, and procedures, while providing intelligence support that strengthens incident response and case outcomes. You will work closely with your team and engagement leads to turn direct communications and threat activity into actionable support that helps the organization anticipate, understand, and respond to adversaries. Key Responsibilities Relying on extensive security knowledge and advanced technical expertise, this role is accountable for the following responsibilities Relying on advanced knowledge and strong leadership skills, this role is accountable for the following responsibilities: Threat Actor Communications and Negotiation Leadership:
Lead written communications and negotiation support for ransomware and cyber extortion engagements under the direction of counsel.
Develop communication strategy, draft response language, and maintain disciplined negotiation records that support case objectives.
Track demands, deadlines, concessions, proof-of-possession requests, and actor behavior to help the engagement team assess leverage and next steps.
Review and refine communications prepared by junior analysts to ensure they are clear, professional, accurate, and aligned with case strategy.
Threat Intelligence and Adversary Analysis:
Research, analyze, and track threat actors, extortion groups, malware families, campaigns, and emerging adversary infrastructure.
Correlate communications, indicators, and intelligence to identify patterns in actor behavior, tactics, techniques, and procedures.
Provide intelligence support to active investigations and time-sensitive events so response teams can make informed decisions.
Maintain actor profiles, negotiation notes, intelligence artifacts, and reference material in approved repositories.
Team Leadership and Process Improvement:
Mentor junior analysts and help establish consistent standards for negotiation support, documentation, and intelligence reporting.
Improve communication workflows, intelligence collection, validation, and dissemination processes for scale and repeatability.
Collaborate with DFIR, legal, insurance, and client-facing teams to ensure communications are timely, relevant, and actionable.
Competencies Planning
Contribute to the development of both short-term and long-term plans for designated area of the organization.
Technical Excellence
Experience leading threat actor communications and producing intelligence products that inform decisions during active cyber incidents.
Write, or is a major contributor to, technical reports and documentation.
Analyze complex threat data and present findings in a clear and useful manner for multiple audiences.
Cost Management
Develop innovative ways to improve financials.
Business Controls and Policies
Comply with all corporate policies and procedures.
Education Minimum 4 Year's bachelor's degree in cyber security, Computer Science, Information Technology related degree. Certifications, Licenses, and Designations Preferred advanced degrees or certifications (CISSP, CISM, GCFE, GCFA, GREM, GBFA, GCIH, CFCE, CCE) are a plus Experience 4+ years of professional experience in cyber incident response, threat intelligence, negotiations, investigations, or related analytical work. Other
Experience leading threat actor communications in ransomware or cyber extortion cases.
Strong writing and presentation skills with the ability to communicate clearly under pressure.
Ability to manage multiple complex matters simultaneously and respond to urgent requests.
Familiarity with threat actor behavior, TTPs, malware families, and campaign activity using open-source and commercial intelligence sources.
Additional Job Description Pay Transparency The pay range for this position is $109,500-$164,300 which includes geographic adjustments, where applicable. The pay range is the range THMCC, in good faith, believes is the range of compensation for this role at the time of this posting. The hired applicant will be offered pay within the entire range based on the candidate's geographic location, qualifications, work experience, education, and/or skill level.