PDI Technologies Logo

PDI Technologies

Manager, Threat Intelligence

Posted 2 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in US
Senior level
Remote
Hiring Remotely in US
Senior level
Leads and develops a threat intelligence, threat hunting, and detection engineering team serving multiple customer environments. Owns the intelligence lifecycle, produces strategic and tactical intelligence, develops SIEM and EDR/XDR detections, conducts threat hunts, supports complex incidents, and briefs technical and executive audiences. Establishes ATT&CK coverage, automates workflows, partners with SOC and security engineering teams, and advises customers on threats affecting retail, hospitality, payments, and connected systems.
The summary above was generated by AI
At PDI Technologies, we empower some of the world's leading convenience retail and petroleum brands with cutting-edge technology solutions that drive growth and operational efficiency. By “Connecting Convenience” across the globe, we empower businesses to increase productivity, make more informed decisions, and engage faster with customers through loyalty programs, shopper insights, and unmatched real-time market intelligence via mobile applications, such as GasBuddy.  We’re a global team committed to excellence, collaboration, and driving real impact. Explore our opportunities and become part of a company that values diversity, integrity, and growth.

Role Overview

Every day, millions of people buy fuel, coffee, and lunch at the businesses PDI protects. Convenience stores, fuel stations, quick-service restaurants, and automotive businesses run on payment systems, point-of-sale networks, and connected site equipment, and financially motivated attackers know it.

We're looking for an experienced leader to own threat intelligence, threat hunting, and detection engineering for our SOC. You'll build the clearest picture anywhere of who targets these industries and how, then turn it into detections, hunts, and guidance that protects 12,000+ customers.

This isn't an internal intel team serving one company. Your team's work ships to every customer we protect, and you'll have real room to build the program the way you think it should run.

Why this role stands out
  • A threat landscape you can own. Payment card theft, POS malware, ransomware against franchise networks, and attacks on connected forecourt and in-store systems. Few teams anywhere specialize here.
  • A straight line from intel to impact. Your team writes the intelligence and the detections. You'll see your work stop real attacks across many customer environments.
  • Room to build. Shape the methodology, tooling, and AI-assisted workflows rather than inheriting someone else's playbook.
  • Visibility. Brief customer executives, partner with SOC, product, and company leaders, and represent PDI in industry and intelligence-sharing communities.

What you'll own

    Lead and grow the team
    • Hire, coach, and develop a remote team of analysts, hunters, and detection engineers, with clear priorities and career paths.
    • With a team of four, you'll split your time between leading and doing: hunting, writing intelligence, and building detections alongside the team.
    • Partner with SOC, Incident Response, and Security Engineering leaders to improve detection, response, and customer outcomes.
    • Build the intelligence program
      • Define intelligence requirements with SOC leadership and customers and run the full intelligence lifecycle from collection through feedback.
      • Deliver strategic, operational, and tactical products: actor profiles, campaign analysis, industry threat briefs, and customer-specific reports.
      • Track the actors that matter most to our customers, including financially motivated groups, payment fraud operations, and ransomware crews targeting retail and hospitality.
      • Turn intelligence into detection
        • Own detection content strategy across SIEM and EDR/XDR, including development, testing, tuning, and coverage measured against MITRE ATT&CK.
        • Run hypothesis-driven threat hunts across customer environments and feed what you find back into new detections.
        • Use automation and AI to scale enrichment, triage support, and reporting so the team can focus on analysis, not busywork.
        • Step in when it matters
          • Provide intelligence context during major incidents and lead during complex escalations.
          • Be the voice of the team
            • Serve as a trusted advisor to customers through briefings, reports, and presentations for both technical and executive audiences.
            • Run the team on clear metrics such as detection coverage, hunt findings, reporting timeliness, and customer satisfaction, and contribute to service planning and new offerings.

What success looks like

    • First 90 days: Assess the team, tooling, and current detection coverage. Agree on intelligence requirements with SOC leadership and key customers.
    • By 6 months: A regular cadence of industry threat reporting, plus an ATT&CK coverage baseline and roadmap.
    • By 12 months: Measurable gains in detection coverage and hunt-driven findings, and a team customers see as the go-to source on threats to their industry.

What you bring

    Required
    • 8+ years in cybersecurity across threat intelligence, threat hunting, incident response, detection engineering, or security operations.
    • 3+ years managing technical security teams, including hiring and developing people.
    • Deep knowledge of adversary tactics and the frameworks used to analyze them, such as MITRE ATT&CK, the intelligence lifecycle, and the Diamond Model.
    • A track record of producing finished intelligence for both technical and executive audiences.
    • Hands-on experience with SIEM (FortiSIEM, Microsoft Sentinel, Splunk, Google Chronicle, or ArcSight) and EDR/XDR platforms and their query languages (KQL, SPL, or similar). Our environment includes FortiSIEM; equivalent experience is welcome.
    • Experience supporting complex investigations and incident response.
    • Excellent written, verbal, and presentation communication skills.
    • Clear writing and speaking skills, with the ability to translate technical findings into business risk.
    • Nice to have
      • Experience at an MSSP or MDR provider serving many customers.
      • Background in retail, hospitality, or payments environments, including POS systems or PCI DSS.
      • Detection-as-code, Sigma, SOAR, or scripting (e.g., Python).
      • Experience with threat intelligence platforms and feeds, such as MISP or Recorded Future.
      • Cloud and SaaS investigations across Azure, AWS, or Microsoft 365.
      • Active involvement in intelligence-sharing communities such as RH-ISAC.
      • Certifications such as GCTI, GCFA, GCIH, GREM, or CISSP are welcome but not required.
      • A bachelor's degree in a related field or equivalent experience. If you're close on the requirements and excited about the work, we'd still like to hear from you.

PDI is committed to offering a well-rounded benefits program, designed to support and care for you, and your family throughout your life and career.  This includes a competitive salary, market-competitive benefits, and a quarterly perks program. We encourage a good work-life balance with ample time off [time away] and, where appropriate, hybrid working arrangements.  Employees have access to continuous learning, professional certifications, and leadership development opportunities. Our global culture fosters diversity, inclusion, and values authenticity, trust, curiosity, and diversity of thought, ensuring a supportive environment for all.

Similar Jobs

18 Days Ago
Remote
United States
Senior level
Senior level
Big Data • Security • Software • Analytics • Cybersecurity
Lead global cyber operations and investigations, conduct threat intelligence and malware research, produce all-source assessments, automate OSINT collection, and communicate cyber risks to clients and stakeholders. Develop scalable intelligence processes, maintain threat knowledge bases, support detection engineering, analyze cyber trends, and mature threat intelligence methodologies while serving as a subject matter expert.
Top Skills: EdrMalware AnalysisExcelMicrosoft PowerpointMicrosoft WordMitre Att&CkOsintSandboxingSIEMStatic Code Analysis
15 Minutes Ago
Remote
USA
120K-180K Annually
Senior level
120K-180K Annually
Senior level
Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software • Defense Technology
Develop and maintain internal full-stack applications using C#/Blazor or Python. Build CI/CD pipelines and infrastructure automation with GitLab, Azure DevOps, GitHub, Artifactory, and SonarQube. Partner with cross-functional teams to improve software delivery, code quality, security, compliance, and operational visibility. Implement scalable enterprise solutions, infrastructure as code, secure development practices, and DevSecOps workflows.
Top Skills: ArtifactoryAzure DevopsBicepBlazorC#Ci/CdDevsecopsGitGitlabInfrastructure As CodePythonRbacSonarqubeSsoTerraform
32 Minutes Ago
Remote or Hybrid
45K-85K Annually
Junior
45K-85K Annually
Junior
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Handle inbound calls and warm leads, advise customers on insurance coverage, match products to their needs, and convert prospects into policyholders. The role includes paid training and Property & Casualty licensing, customer communication, sales closing, and remote work using company-provided equipment. Employees must work four weekdays and one weekend day and maintain a compliant home office with high-speed wired internet.
Top Skills: Pc ProficiencyProperty & Casualty Insurance LicenseWired High-Speed Internet

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account