Kroll Logo

Kroll

Senior Director, Cyber Threat Intellignece

Posted 3 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
200K-300K Annually
Senior level
Remote
Hiring Remotely in United States
200K-300K Annually
Senior level
Design, administer, and optimize a cyber threat intelligence platform. Build Python automation, ETL pipelines, APIs, and integrations that collect, enrich, normalize, correlate, and distribute intelligence from commercial, open-source, government, dark web, and internal sources. Apply STIX/TAXII and MITRE ATT&CK to track indicators, actors, malware, vulnerabilities, and campaigns. Develop dashboards and AI-assisted capabilities while ensuring data quality, governance, and security across intelligence repositories.
The summary above was generated by AI

As the leading independent provider of risk and financial advisory solutions, Kroll leverages our unique insights, data, and technology to help clients stay ahead of complex cyber threats. Our Cyber Risk team partners with organizations around the world to deliver intelligence-driven security solutions that enable informed decision-making and proactive risk management.

 

We are seeking an experienced Threat Intelligence Platform Engineer to join our Cyber Threat Intelligence team. This role is ideal for a security professional who is passionate about engineering scalable threat intelligence capabilities through automation, data integration, and platform management.

 

The Intelligence Platform Engineer is responsible for designing, building, and maintaining the technology, automation, and data infrastructure that powers cyber threat intelligence operations. This role serves as the bridge between intelligence analysis, threat research, data engineering, and security operations by developing scalable solutions that automate the collection, enrichment, normalization, correlation, and dissemination of cyber threat intelligence.

 

The successful candidate will identify and integrate intelligence data sources from commercial providers, open-source intelligence (OSINT), internal security telemetry, dark web collections, government feeds, and industry-sharing communities. They will leverage automation, APIs, machine learning, and data engineering techniques to transform raw intelligence into actionable insights that support threat detection, incident response, vulnerability management, executive reporting, and strategic decision-making. This aligns with internal descriptions emphasizing ownership of a threat intelligence platform, automation, and multi-source intelligence integration.

 

Working closely with Threat Intelligence Analysts, Incident Responders, Detection Engineers, and Security Operations teams, the successful candidate will improve the organization's ability to identify emerging threats through intelligent automation and data engineering.

 

Key Responsibilities:

  • Administer, maintain, and optimize Kroll’s Threat Intelligence Platform. 

  • Design and develop automated workflows for collecting, enriching, correlating, and distributing cyber threat intelligence. 

  • Build scalable automation to support dark web monitoring, credential exposure tracking, threat actor activity, and emerging threat detection. 

  • Develop and maintain integrations with commercial threat intelligence providers, OSINT sources, government intelligence feeds, ISACs, and internal security platforms. 

  • Design ETL pipelines to ingest, normalize, and organize structured and unstructured threat intelligence datasets. 

  • Correlate indicators of compromise (IOCs), threat actors, malware families, vulnerabilities, and campaigns using industry standards such as STIX/TAXII and the MITRE ATT&CK Framework. 

  • Develop dashboards, reporting, and visualizations that improve analyst efficiency and provide actionable intelligence to stakeholders. 

  • Evaluate emerging technologies, intelligence sources, and AI-driven capabilities to continuously improve Kroll's threat intelligence operations. 

  • Ensure data quality, governance, and security across all intelligence repositories. 

 

Required Qualifications:

Education

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related discipline, or equivalent professional experience. 

Experience

  • Minimum of five (5) years of experience in cybersecurity, cyber threat intelligence, or security engineering. 

  • Experience administering a Threat Intelligence Platform (EclecticIQ strongly preferred). 

  • Proven experience designing automation solutions using Python. 

  • Experience integrating APIs and external data sources. 

  • Hands-on experience with cyber threat intelligence workflows and intelligence lifecycle management. 

Technical Qualifications

Threat Intelligence

  • Experience working Threat Intelligence Platforms 

  • STIX 2.x and TAXII 

  • MITRE ATT&CK Framework 

  • MISP (preferred) 

  • IOC lifecycle management 

  • Threat actor tracking 

  • Campaign analysis 

  • Malware intelligence 

  • TTP analysis 

Programming & Automation

Required:

  • Advanced Python development 

Experience with:

  • REST APIs 

  • Webhooks 

  • Async programming 

  • Requests 

  • Pandas 

  • BeautifulSoup 

  • Selenium or Playwright 

  • SQLAlchemy 

Preferred:

  • JavaScript 

  • PowerShell 

  • Go 

Data Engineering

Experience with:

  • SQL 

  • PostgreSQL 

  • Elasticsearch/OpenSearch 

  • MongoDB (preferred) 

Ability to:

  • Build ETL pipelines 

  • Normalize structured and unstructured datasets 

  • Correlate multiple intelligence sources 

  • Design scalable data ingestion workflows 

Dark Web Intelligence

Experience collecting and automating intelligence from:

  • Underground forums 

  • Telegram channels 

  • Credential leak repositories 

  • Marketplace monitoring 

  • Paste sites 

  • Open-source intelligence sources 

Cloud & Infrastructure

Experience with AWS services including:

  • Lambda 

  • ECS 

  • S3 

  • IAM 

  • EventBridge 

  • Step Functions 

  • Secrets Manager 

Security Platforms

Experience integrating with technologies such as:

  • Splunk 

  • CrowdStrike Falcon 

  • VirusTotal 

  • GreyNoise 

  • Shodan 

  • Censys 

Preferred Qualifications

  • Experience developing AI-assisted threat intelligence workflows. 

  • Familiarity with Large Language Models (LLMs) for intelligence summarization and analysis. 

  • Experience with graph databases such as Neo4j. 

  • Knowledge of Retrieval-Augmented Generation (RAG) architectures. 

  • Experience building knowledge graphs. 

  • Familiarity with DevOps practices, Docker, Kubernetes, and CI/CD pipelines. 

Preferred Certifications

  • GIAC Cyber Threat Intelligence (GCTI) 

  • SANS FOR578 Cyber Threat Intelligence 

  • CISSP 

  • AWS Certified Security – Specialty 

  • AWS Certified Developer – Associate 

  • Security+ 

  • GSEC 

What Success Looks Like

The successful candidate will:

  • Build scalable automation that significantly reduces manual intelligence collection and analysis. 

  • Improve analyst productivity through efficient data integration and workflow automation. 

  • Expand Kroll's ability to monitor the dark web and emerging threat landscape. 

  • Deliver actionable, high-quality intelligence through a modern, integrated Threat Intelligence Platform. 

  • Help position Kroll as an industry leader in intelligence-driven cybersecurity services through continuous innovation and operational excellence. 

 

Why Join Kroll?

 

At Kroll, you'll work alongside some of the industry's most respected cyber professionals, solving complex challenges for organizations around the world. We foster a collaborative, innovation-driven environment where your expertise directly contributes to protecting clients from evolving cyber threats. You'll have the opportunity to work with cutting-edge technologies, influence the evolution of our threat intelligence capabilities, and make a meaningful impact across our global Cyber Risk practice.

 

Your recruiter will be happy to walk you through your U.S.-specific benefits, which include:

 

  • Healthcare Coverage: Comprehensive medical, dental, and vision plans.

  • Time Off and Leave Policies: Generous paid time off (PTO), paid company holidays, generous parental and family leave.

  • Protective Insurances: Life insurance, short- and long-term disability coverage, and accident protection.

  • Compensation and Rewards: Competitive salary structures, performance-based incentives, and merit-based compensation reviews.

  • Retirement Plans: 401(k) plans with company matching.

 

Please note that benefits may vary by region, department and role. We encourage you to speak with your recruiter to learn more about the specific benefits available for your position.

 

About Kroll 

 

Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll. 

 

In order to be considered for a position, you must formally apply via careers.kroll.com.

 

We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability.

 

The current salary range for this position is $200,000 to $300,000

 

 

#LI-CN1

#LI-Remote

Kroll Addison, Illinois, USA Office

Addison, United States

Kroll Chicago, Illinois, USA Office

Chicago, United States

Similar Jobs

61K-126K Annually
Senior level
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Manages, investigates, evaluates, and resolves attorney-represented and litigated auto and homeowners bodily injury claims. Responsibilities include assessing coverage, liability, damages, reserves, suspicious activity, and subrogation opportunities; negotiating settlements; coordinating with counsel; preparing for trials and hearings; communicating with claimants and policyholders; maintaining claim files; and managing legal billing and practices.
5 Minutes Ago
Remote or Hybrid
45K-100K Annually
Junior
45K-100K Annually
Junior
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Handles inbound calls and warm leads, consults customers on insurance needs, recommends appropriate Property and Casualty products and coverages, and converts prospects into policyholders. The role includes paid training and licensing, customer communication, sales closing, schedule flexibility, and remote work using company-provided equipment. Employees must work four weekdays and one weekend day and maintain a dedicated workspace with qualifying wired high-speed internet.
Top Skills: Cable/Fiber/Dsl InternetPcWired High-Speed Internet
19 Minutes Ago
In-Office or Remote
IN, USA
180K-220K Annually
Senior level
180K-220K Annually
Senior level
Big Data • Fitness • Healthtech • Information Technology • Software • Analytics
Build and close enterprise relationships with pharmaceutical and biotechnology companies. Prospect within an assigned territory, develop qualified pipelines, engage scientific and commercial stakeholders, scope data and analytics solutions, create business cases, negotiate enterprise licensing agreements, and manage contracts through close. Maintain forecast discipline, collaborate with product, data, legal, finance, and delivery teams, ensure smooth handoffs, and provide market feedback that shapes Arcadia’s Life Sciences offerings, pricing, packaging, and roadmap.
Top Skills: BantClinical AnalyticsCRMEhr DataHealthcare Claims DataHeorMeddicMeddpiccReal-World Data (Rwd)Real-World Evidence (Rwe)

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account