Senior Threat Intelligence Analyst

ID.me

$120K — $145K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in threat intelligence, cyber threat hunting, or fraud intelligence.
  • 3+ years of hands-on collection across deep and dark web platforms.
  • Deep experience with analysis frameworks like MITRE ATT&CK and the Diamond Model.
  • Ability to synthesize ambiguous information into clear assessments.
  • Exceptional written and verbal communication skills for varied audiences.
  • Proven track record of working independently and managing priorities.

Responsibilities

  • Own an intelligence portfolio, tracking threats from collection to analysis.
  • Define and prioritize collection strategy in partnership with leadership.
  • Conduct deep technical collection using sound tradecraft.
  • Proactively hunt for new threat actor activity and tooling.
  • Produce intelligence assessments with clear judgments and recommendations.
  • Convert research into actionable fraud signals and detections.
  • Mentor analysts on tradecraft, analytic writing, and structured analysis.

Benefits

  • High autonomy in a senior individual-contributor role.
  • Real influence over security and product direction.
  • Opportunity to mentor and develop junior analysts.
  • Engagement with cross-functional teams and external partners.
  • Exposure to senior leadership and industry peer groups.
Full Job Description
ID.me is looking for a senior threat intelligence professional to lead technical tracking of the adversaries targeting the identity verification ecosystem, and to turn that tracking into decisions the business acts on. Identity fraud is an industrialized market of credential and document vendors, injection and deepfake tooling, synthetic identity brokers, and organized account takeover crews. This role sits directly across from it. You will own intelligence coverage for a defined set of threats end to end: setting the collection strategy, running the research, building the models and tooling, and delivering the finished product to the people who need it, from detection engineers to executives and government partners. This is a senior individual-contributor role with high autonomy and real influence over security and product direction. You will also be a technical mentor to the analysts around you and a standard-setter for how the team does analysis. Responsibilities • Own an intelligence portfolio. Take end-to-end responsibility for tracking a set of threat actors, fraud typologies, or ecosystems targeting ID.me and our partners, from collection through analysis to delivery and follow-up. • Set collection strategy. Define and prioritize intelligence requirements in partnership with security, fraud, product, and company leadership. Identify gaps in current coverage and close them. • Run technical collection at depth. Conduct sustained collection and source development across deep and dark web forums, illicit marketplaces, encrypted messaging platforms, and closed communities, using sound tradecraft and operational security. • Hunt emerging activity. Proactively hunt for new actor activity, tooling, and TTPs across internal telemetry and external sources, and pull threads before they become incidents. • Produce finished intelligence. Write assessments that hold up to scrutiny, with clear judgments, stated confidence levels, articulated assumptions, and specific recommendations, for audiences ranging from engineers to the executive team to external partners. • Make intelligence operational. Convert research into detections, fraud signals, blocklists, enrichment, and platform data. Work with detection engineering, data science, and product to get it deployed and measure whether it worked. • Advance the team's analytic tradecraft. Improve threat modeling standards, structured analytic methods, reporting templates, source evaluation, and the team's use of frameworks such as MITRE ATT&CK and the Diamond Model. • Build tooling and automation. Identify where manual work is limiting coverage and build or specify the tooling, pipelines, and enrichment to remove it. • Mentor and raise the bar. Coach analysts on collection tradecraft, analytic writing, and structured analysis. Review their work and help develop their judgment. • Represent the function. Brief senior leadership, partners, and where appropriate, industry peer groups, law enforcement, and information-sharing communities. Qualifications • 5+ years of experience in threat intelligence, cyber threat hunting, fraud intelligence, or a closely related discipline, including experience producing finished intelligence for decision-makers. • 3+ years of hands-on collection across the deep and dark web, including illicit marketplaces and encrypted communication platforms, with demonstrated tradecraft and operational security practices. • Deep, applied experience with common analysis models and frameworks (MITRE ATT&CK, the Diamond Model, kill chain, structured analytic techniques). Not just familiarity, but a track record of using them to reach and defend analytic judgments. • Demonstrated ability to take ambiguous, fragmentary, and conflicting information and produce a clear assessment with appropriately expressed confidence. • Exceptional written and verbal communication, including experience writing for both deeply technical and executive audiences. • Track record of working independently: scoping your own problems, setting priorities, and driving work to a result without close direction. • Proven ability to influence stakeholders outside of security, and to translate intelligence into changes other teams actually make. Preferred Qualifications • Experience with identity fraud, account takeover, synthetic identity, document and biometric fraud, or the fraud-as-a-service ecosystem. • Strong SQL skills for independent data analysis at scale, and scripting in Python or similar for collection, enrichment, and automation. • Experience turning intelligence into production detections or fraud controls alongside engineering and data science teams. • Experience mentoring analysts or leading intelligence projects across multiple contributors. • Relevant certifications such as GCTI, GREM, GCFA, GOSI, CISSP, or Security+. • Working proficiency in a foreign language relevant to threat actor communities. • Experience in a regulated or government-facing environment, or supporting external partners with intelligence products.

Similar Jobs

More Jobs at ID.me

More Information Technology Jobs

Find similar Senior Threat Intelligence Analyst jobs: