Threat Intelligence Lead

Obsidian Security
Palo Alto
Workplace: OnsiteFull timeUSD 240,000 - 280,000 annuallyFunction: Administration & Executive AssistanceSkills: ["Ownership","Analytical depth","Judgment","Team-oriented","Mission-driven"]

Build and scale Obsidian’s threat intelligence and threat hunting capabilities by collecting and synthesizing signals from feeds, open source, ISACs, vendor advisories, and more. Translate intelligence into decision-grade products and MITRE ATT&CK–mapped TTPs, then run hypothesis-driven hunts across SaaS/cloud and corporate environments. Operationalize detections, support investigations, and pressure-test the product internally as “customer zero.”

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Obsidian Security
Obsidian Security
2 days ago

Threat Intelligence Lead

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 14 hours agoStatus: Live

Job Summary

Build and scale Obsidian’s threat intelligence and threat hunting capabilities by collecting and synthesizing signals from feeds, open source, ISACs, vendor advisories, and more. Translate intelligence into decision-grade products and MITRE ATT&CK–mapped TTPs, then run hypothesis-driven hunts across SaaS/cloud and corporate environments. Operationalize detections, support investigations, and pressure-test the product internally as “customer zero.”
Location: Palo Alto
Workplace: Onsite
Employment Type: Full time
Job Function: Administration & Executive Assistance
Seniority: Mid level

Key Responsibilities

  • •Collect, correlate, and synthesize threat intelligence from commercial feeds, open source, ISACs, vendor advisories, researcher communities, and dark web sources.
  • •Assess and prioritize emerging threats, campaigns, and vulnerabilities for applicability to Obsidian’s product and corporate infrastructure.
  • •Produce decision-grade intelligence products (threat advisories, actor/campaign profiles, and periodic briefings) for technical teams and leadership.
  • •Run structured, hypothesis-driven threat hunts across corporate and product environments; operationalize IOCs into detections and manage IOC lifecycle.
  • •Serve as “customer zero” by using the product to secure corporate assets, run hunts, and improve in-development workflows via feedback.

Pay and Benefits

Salary: USD 240,000 - 280,000 annually
Perks:Health InsuranceDentalVision401kEquityParental Leave

Key Requirements

  • •At least 6 years of experience in threat intelligence, threat hunting, detection engineering, incident response, or security operations.
  • •Demonstrated ability to analyze threat data and produce clear, prioritized, actionable assessments for varied audiences.
  • •Hands-on threat hunting experience across cloud, SaaS, and endpoint telemetry, with fluency in MITRE ATT&CK and the intelligence lifecycle.
  • •Working knowledge of security capabilities and attack surface of modern IT and SaaS systems such as Okta, Google Workspace, Salesforce, Slack, Notion, and Jira.
  • •Experience with SIEM query languages and scripting for automation/enrichment in Python; familiarity with intelligence sharing standards and tooling (STIX/TAXII, MISP, OpenCTI, or similar).
Experience:CybersecurityThreat intelligenceThreat huntingSecurity operationsSaaSCloudIncident response
Skills:OwnershipAnalytical depthJudgmentTeam-orientedMission-driven
Languages:English
Tech Stack:MITRE ATT&CKPythonSIEMSTIX/TAXIIMISPOpenCTIIOCTTPOAuthGoogle WorkspaceOktaSalesforceSlackNotionJira

Company Brief

Obsidian Security
Provides cloud-native security solutions that detect and respond to identity- and configuration-based threats across SaaS, IaaS, and cloud identity platforms. Focuses on discovering risky exposures, prioritizing alerts, and enabling remediation for enterprise cloud environments.
Industry: Cybersecurity
Headquarters: San Mateo, United States
WebsiteLinkedIn