Source Job

US

  • Lead MLB's threat intelligence and incident response programs across the league office, 30 Clubs, and affiliates.
  • Manage vulnerability intelligence, digital risk monitoring, incident coordination, and forensic investigations.
  • Own security awareness programming and use automation to shorten research, triage, and reporting cycles.

Threat Intelligence Incident Response Security Operations Detection Engineering

20 jobs similar to Manager, Cyber Threat Intelligence & Response

Jobs ranked by similarity.

$140,000–$180,000/yr
US

  • Apply deep expertise in cyber threat intelligence, analyzing advanced threat actors and attack methodologies.
  • Lead strategic threat intelligence initiatives, developing methodologies and providing thought leadership.
  • Convey complex intelligence findings through reports and briefings to diverse technical and executive audiences.

NBCUniversal is a leading media and entertainment company, creating and distributing content across film, television, streaming, and theme parks. As a subsidiary of Comcast Corporation, it employs a large global workforce and fosters an inclusive culture with a commitment to community engagement.

US

  • Lead enterprise-wide response to high-risk cybersecurity incidents as Cyber Incident Commander, directing cross-functional efforts and driving containment to resolution.
  • Provide executive incident leadership by delivering updates to senior leaders and supporting decision-making during incidents.
  • Strengthen the incident response program through post-incident reviews, root cause analysis, and continuous improvements to response plans and playbooks.

Experian is a global data and technology company that powers opportunities for people and businesses across financial services, healthcare, automotive, and more. The company has a team of 25,200 employees in 32 countries and is known for its award-winning, people-first culture.

$125,560–$173,010/yr
Canada Unlimited PTO

  • Lead and develop a team of security engineers to defend infrastructure, SaaS, and endpoints against real-world adversaries.
  • Own detection and response, including incident command, tuning CrowdStrike, and conducting cybersecurity risk assessments.
  • Drive AI security strategy and partner with cross-functional teams to build robust detection controls.

Forward Financing is a financial technology company that unlocks capital to fuel small businesses across America. Since 2012, they have provided over $4.8 billion in funding to more than 92,000 small businesses and are recognized as a Best Place to Work with a culture focused on empowerment and collaboration.

US

  • Build and maintain reusable use cases and reference architectures on the Cyware platform for threat intelligence, automation, and agentic SOC workflows.
  • Act as the primary voice of the market to Product, translating customer pain points into product requirements and roadmap input.
  • Enable Sales Engineering and Customer Success teams with reusable technical assets and best practices.

Cyware delivers an innovative approach to cybersecurity that unifies threat intelligence, automation, threat response, and vulnerability management. It is a cybersecurity startup that has closed its Series C funding round and fosters an exciting and challenging start-up culture.

US Australia

  • Analyze and respond to advanced threats ranging from commodity phishing to zero-day exploits.
  • Monitor and triage alerts from network security monitoring, EDR platforms, and other log sources.
  • Create detailed incident reports and collaborate with threat intelligence and incident response teams.

Volexity is a cybersecurity company specializing in threat intelligence and incident response. They have a growing, industry-leading security operations team and value diversity and equal opportunity.

$155,000–$185,000/yr
US

  • Serve as insider-risk technical lead and trusted advisor to USPTO stakeholders, running customer syncs and delivering status reporting.
  • Own technical direction of insider-risk toolset in Microsoft Purview, including policies, indicators, and dashboards.
  • Design custom dashboards and playbooks in Microsoft Sentinel, and investigate insider-risk alerts alongside analysts.

9th Way Insignia is a service-disabled, veteran-owned small business that brings transformative technology to government customers. They specialize in cybersecurity, cloud modernization, and data analytics, and are a small business focused on mission achievement.

Unlimited PTO

  • Lead and execute complex digital forensics and incident response investigations across a range of engagement types.
  • Deliver high-quality analysis, client communication, and tailored deliverables for both technical and managerial audiences.
  • Collaborate with peers to improve methodologies, tooling, and automation to respond to emerging threats.

GuidePoint Security provides trusted cybersecurity expertise, solutions and services to help organizations make better decisions and minimize risk. With over 1,300 employees and a focus on collaboration and mentorship, the company serves Fortune 500 companies and government agencies.

$153,000–$214,000/yr
US Canada

  • Lead end-to-end response to product security incidents, from discovery to disclosure.
  • Own and evolve 1Password's PSIRT function, including severity frameworks and playbooks.
  • Drive coordinated vulnerability disclosure and partner with external security researchers.

1Password is a cybersecurity company providing enterprise password management and Unified Access Management, trusted by over 180,000 businesses. With $400M ARR and a remote-first culture, it values collaboration, transparency, and innovation.

EMEA

  • You'll lead the VIPR & VMDR function, integrating vulnerability intelligence, detection, and response for customers across APJ/APAC.
  • You'll operate and tune vulnerability detection tools like Tenable, Qualys, and Rapid7, and automate pipelines using Python and REST APIs.
  • You'll build risk dashboards and executive briefings, and collaborate with Customer Success and Security Engineering to improve remediation metrics.

ServiceNow is the AI control tower for business reinvention, bringing together AI, data, and workflows to help 85% of the Fortune 500 work smarter. The company fosters an AI-native culture where technology and talent are unstoppable together.

US

  • Conduct comprehensive OSINT and Deep & Dark Web analysis to develop intelligence on national security threats.
  • Perform proactive covert engagement with threat actors using managed-attribution tradecraft.
  • Apply an offensive-security perspective to assess how adversaries could operationalize exposed data.

Flashpoint is a pioneering threat intelligence company providing data and insights to commercial and government clients. The company prioritizes a diverse and inclusive culture with employee wellness and growth opportunities.

$172,279–$249,640/yr
US Canada

  • Build and maintain SIEM for log collection and detection rules across corporate and production environments.
  • Design and deploy canary tokens and early warning mechanisms to detect threats before they reach critical assets.
  • Investigate security incidents end-to-end, including malware analysis, exfiltration assessment, and timeline reconstruction.

Quora operates two platforms: a global knowledge sharing platform with over 300M monthly unique visitors, and Poe, a platform for chatting and building with AI language models. The company is privately held, remote-first, and fosters a culture of transparency, collaboration, and experimentation.

US

  • Deploy and support Scout products in real customer environments, building and improving deployment automations.
  • Prototype integrations with customer systems and turn repeatable issues into actionable product requirements.
  • Communicate clearly with technical and non-technical customers while researching cybersecurity trends.

Volexity is a cybersecurity company that builds products used in real-world security environments, including incident response and threat intelligence. The company values diversity and is an equal opportunity employer, hiring based on qualifications and merit.

$152,000–$152,000/yr
US

  • You will hunt for and analyze adversary capabilities targeting ICS/OT networks.
  • You will develop tools and scripts for capability analysis and inform detection strategies.
  • Your work directly enhances Dragos' ability to defend against advanced threats.

Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The company is a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust.

$145,000–$170,000/yr
US Unlimited PTO

  • Plan and conduct offensive security engagements of varying size, scope, and focus.
  • Communicate findings and recommendations to technical and executive stakeholders through reports and presentations.
  • Build scripts, tools, or methodologies to enhance offensive services and mentor less experienced staff.

SpecterOps is an offensive security consultancy that delivers red team assessments, penetration tests, and adversary simulation services to large commercial enterprises. The company fosters a culture of passionate curiosity, consistent improvement, empathy, sustainability, humility, and empowerment through transparency.

$115,000–$125,000/yr
US

  • Lead identification and assessment of vulnerabilities through regular security assessments and penetration testing.
  • Manage security event monitoring, incident response, and collaborate with IT teams to remediate threats.
  • Develop and implement identity and access management (IAM) procedures and security controls across the organization.

Capital Bank N.A. is a publicly traded bank offering commercial and consumer banking services primarily in Maryland, DC, and Northern Virginia, along with nationwide lending brands. With over $3 billion in assets, it has been named one of the 'Best Banks to Work For' in the U.S. for 6 out of the last 7 years.

Ireland UK

  • Maintain the ability to identify, investigate, and manage threats of violence toward global offices, executives, and employees.
  • Utilize evidence-based risk assessment tools and conduct research using open-source intelligence and other resources.
  • Collaborate with internal teams and external partners to develop and manage case life cycles and provide actionable threat assessments.

Concentric is a risk consultancy specializing in delivering strategic security and intelligence services to private clients and corporations globally. The company is comprised of elite professionals from military, government, and intelligence backgrounds and operates with core values of integrity, collaboration, and excellence.

US 3w PTO

  • Lead the enterprise Vulnerability Management and CDM program, directing scanning and prioritization strategies.
  • Coordinate remediation activities across system owners, engineering teams, and ISSOs to reduce cyber risk.
  • Develop executive metrics, dashboards, and reports to communicate vulnerability posture and operational risk trends.

True Zero Technologies is a veteran-owned small business that focuses on purposeful enablement of people and technology. Recognized as a Best Places to Work in 2023 and 2025, and listed on the Inc. 5000 fastest-growing companies, the company emphasizes a people-first culture and dedication to excellence.

$190,900–$334,100/yr
North America Unlimited PTO

  • Own the architecture for AI-powered security automation across cyber defense, from threat intelligence to incident response.
  • Unify internal telemetry, asset data, and external intelligence into defender-ready systems that scale operations.
  • Build and grow a high-caliber engineering team, enabling security practitioners to extend automation themselves.

ServiceNow is an AI platform company that helps 85% of the Fortune 500 integrate AI, data, and workflows. Founded on the idea of freeing people from busywork, it fosters an AI-native culture where technology and talent are unstoppable together.

US Unlimited PTO

  • Develop differentiated product messaging and positioning for VulnCheck's exploit intelligence products.
  • Lead go-to-market launches and create sales enablement content like solution briefs and battlecards.
  • Conduct market intelligence and competitive analysis to inform strategy and support the sales team.

VulnCheck is The Exploit Intelligence Company, delivering structured exploit intelligence for cybersecurity infrastructure. Founded in 2021, the company has a transparent, collaborative culture and values growth, curiosity, and innovation.

$162,000–$210,000/yr
US

  • Define and drive AI-forward product strategy for SpyCloud's investigations capabilities, enabling security teams to uncover, understand, and act on cybercriminal activity using intelligent, automated workflows.
  • Partner closely with Engineering, Design, Data Science, and Go-to-Market teams to deliver innovative AI-driven features that help customers investigate threats faster and reduce manual effort.
  • Own the product vision, strategy, and roadmap for the AI-powered Investigations product portfolio, balancing long-term vision with customer needs and business priorities.

SpyCloud transforms recaptured darknet data to disrupt cybercrime, offering automated identity threat protection solutions that use advanced analytics and AI to accelerate investigations and protect identities. Headquartered in Austin, TX, SpyCloud employs over 250 cybersecurity experts focused on protecting businesses and consumers from stolen identity data.