Counter-Threat Intelligence Engineer

Cambium Learning Group

United States

Remote

USD 120,000 - 170,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Remote-first environment
Flexible work arrangements

Job summary

Cambium Learning Group seeks a Counter-Threat Intelligence Engineer to enhance the organization's ability to identify, understand, and counter cyber threats impacting learners, educators, associates, platforms, data, and business operations.

This role blends threat intelligence, adversary emulation, exposure validation, and security engineering to reduce attack surface, improve detection logic, support incident response, and translate findings into practical remediation with measurable risk

Qualifications

  • 5+ years of cybersecurity experience with focus in threat intelligence, ethical hacking, or related roles.
  • CEH or equivalent offensive security certifications preferred; OSCP/GPEN/CTIA etc. may be considered.
  • Strong understanding of cyber kill chain, MITRE ATT&CK, and detection/response tooling.

Responsibilities

  • Collect and analyze threat intelligence from trusted sources and indicators of compromise.
  • Perform adversary emulation and authorized testing to identify exposures and recommend defenses.
  • Collaborate with Security Operations to tune detections, playbooks, and response workflows.
  • Support threat exposure management by scoping assets and prioritizing remediation activities.
  • Produce actionable threat intelligence summaries and executive-ready briefings.

Skills

Threat intelligence
Ethical hacking
Threat hunting
Incident response
Security operations
Vulnerability assessment
Communication

Education

Bachelor's degree in Cybersecurity, Computer Science, IT, Engineering, or related field

Tools

SIEM
XDR/EDR
Threat intelligence platforms
Vulnerability scanners
Cloud security tools
Identity logs
Endpoint telemetry
Network telemetry
Ticketing/workflow platforms

Job description

Job Overview

Cambium Learning Group is seeking a Counter-Threat Intelligence Engineer to enhance the organization’s ability to identify, understand, and counter cyber threats that could impact our learners, educators, associates, platforms, data, and business operations. This role combines threat intelligence, ethical hacking, exposure validation, adversary emulation, and security engineering to turn emerging threat information into actionable defenses. The engineer will work closely with Security Operations, IT Operations, Risk, Legal Compliance, Product, Engineering, and business stakeholders to help reduce attack surface, improve detection logic, support incident response, and translate technical findings into clear recommendations. The ideal candidate brings hands-on offensive security experience, exceptional analytical judgment, and the ability to communicate threat context in a way that drives practical remediation and measurable risk reduction.


Job Responsibilities

Collect, analyze, and operationalize strategic, tactical, and operational threat intelligence from trusted internal and external sources, including indicators of compromise, adversary tactics, techniques, and procedures, emerging vulnerabilities, and targeted threat activity. Perform adversary-focused research and ethical hacking activities, with authorization, to validate exposures, identify likely attack paths, and recommend defensive improvements across endpoints, cloud services, applications, identity platforms, networks, and third-party integrations. Partner with Security Operations to create, tune, and validate detections, playbooks, threat hunting hypotheses, and response workflows in data log pipelines, SIEM, XDR, EDR, vulnerability management, and related security tools. Support Continuous Threat Exposure Management efforts by helping scope assets, discover exposures, prioritize findings based on business risk, validate exploitability, and coordinate mobilization of remediation activities with IT, infrastructure, engineering, and business owners. Produce concise, actionable threat intelligence reports, briefings, and technical recommendations for audiences ranging from security analysts to senior leadership, emphasizing relevance, impact, urgency, and practical next steps. Contribute to incident response investigations by enriching alerts with threat context, malware or phishing analysis, infrastructure research, attack timeline reconstruction, and lessons learned. Maintain awareness of threat actor tradecraft, vulnerability exploitation trends, cloud and identity attacks, education-sector threats, data protection risks, and changes in attacker use of automation and artificial intelligence. Use independent judgment to make recommendations on defensive priorities, detection improvements, risk acceptance considerations, and escalation paths while staying aligned with Cambium policies, standards, and governance expectations.


Job Requirements

5+ years of progressive cybersecurity experience, with at least 2 years in threat intelligence, ethical hacking, penetration testing, detection engineering, security operations, incident response, vulnerability management, or a closely related role. Certified Ethical Hacker (CEH) certification is highly preferred; similar hands-on offensive security or threat intelligence certifications may be considered, such as OSCP, GPEN, CompTIA PenTest+, CPENT, eJPT, GCTI, CTIA, or equivalent practical experience. Proven working knowledge of the cyber kill chain, MITRE ATT&CK, common attack techniques, malware and phishing behaviors, cloud and identity threats, vulnerability exploitation, attacker infrastructure, and defensive countermeasures. Hands-on experience with security tools and data sources such as SIEM, XDR/EDR, vulnerability scanners, threat intelligence platforms, cloud security tools, identity logs, endpoint telemetry, network telemetry, and ticketing/workflow platforms. Ability to write clear threat intelligence summaries, detection recommendations, executive briefings, remediation guidance, and technical documentation that can be acted on by cross-functional teams. Experience conducting authorized security testing, adversary emulation, attack surface analysis, detection validation, or threat hunts in a disciplined, evidence-based, and policy-aligned manner. Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field preferred; equivalent professional experience and certifications may be considered. High judgment, strong ethics, discretion with sensitive information, collaborative communication style, and commitment to protecting confidential, proprietary, student, customer, associate, and business data.


Preferred Qualifications

Experience in education technology, SaaS, cloud-first, remote-first, or regulated environments. Experience building threat hunting content, Sigma/YARA rules, KQL/SPL queries, detection-as-code, or automation for enrichment and triage. Familiarity with scripting or automation using Python, PowerShell, Bash, APIs, or SOAR-style workflows. Working knowledge of data privacy, secure software development, third-party risk, and compliance frameworks such as ISO 27001, SOC 2, NIST CSF, or NIST SP 800-series guidance.


To learn more about our organization and the exciting work we do, visit www.cambiumlearning.com


Remote First Work Environment

Our Remote First approach gives employees the flexibility and trust they need to effectively balance work with life. It creates a culture in which all employees are valued and where success is measured in results. It allows us to work collaboratively, inclusively and for greater positive impact, regardless of our individual locations. If you will be working remotely, either occasionally or on a permanent basis, you must have a reliable internet connection through a cable or fiber-optic broadband service with minimum speeds of 10 Mbps download and 5 Mbps upload. The successful candidate will be expected to actively participate in video-based interviews during the recruiting process and ongoing virtual meetings with their camera on, as part of their role. To maintain confidentiality and ensure a fair evaluation process, the use of note-taking tools, reference materials, or AI-powered tools (including generative AI, language models, or similar technologies) during interviews or other selection activities is prohibited unless prior written approval has been obtained from the People Experience team. If you require an exception for medical, accessibility, or other reasons, please contact your Talent Acquisition team member to discuss accommodations in advance. As part of our Remote-First benefits, Cambium offers reimbursement to help cover the cost of setting up your home or remote office.


An Equal Opportunity Employer

We are dedicated to fostering a culture that celebrates unique backgrounds, ideas, and experiences. All qualified applicants will receive consideration for employment without discrimination on the basis of race, color, age, religion, sex (including pregnancy, gender, gender identity/expression, or sexual orientation), national origin, protected veteran status, disability, or genetic information (including family medical history). We will provide reasonable accommodations for qualified individuals with disabilities. You may request an accommodation during the recruiting process with your Talent Acquisition team member.


Cambium Learning® Group is the education essentials company. With an intentionally curated portfolio of respected global brands, Cambium serves as a leader in the education space, helping millions of educators and students feel more universally valued each and every day. In everything we do and across all our brands, we focus on the elements that are most essential to the success of education. Our family of companies includes: Cambium Assessment, Lexia Learning, Learning A-Z, Voyager, Sopris Learning, ExploreLearning, Time4Learning, Kurzweil Education. To learn more about the Cambium organization and our other career opportunities, visit www.cambiumlearning.com/about-us/careers.


As a group, we value: Simplicity – Across all our teams and all areas of our business, we create simplicity, making things easier and more clear for those we work with. Certainty – We continually strive to eliminate doubt, delivering solutions, services and communications that our customers know they can count on. Now – We understand the need to make a difference not only for the future, but for today, and our people are committed to making the most of each moment we spend serving our customers.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Category Manager - IT
Category Manager - IT

Cambium Learning Group • United States

On-site
USD 90,000 - 140,000
Remote-First Threat Intelligence Engineer
Remote-First Threat Intelligence Engineer

Cambium Learning Group • United States

Remote
USD 120,000 - 170,000
Remote-first environment
Flexible work arrangements
Director, VSL Customer Success
Director, VSL Customer Success

Cambium Learning Group • United States

Remote
USD 150,000 - 210,000
Remote-first environment
Home office reimbursement
ELA Senior Content Advisor—Product Development
ELA Senior Content Advisor—Product Development

Cambium Learning Group • Northern (KY)

Hybrid
USD 120,000 - 160,000
Math Senior Content Advisor—Product Development
Math Senior Content Advisor—Product Development

Cambium Learning Group • Northern (KY)

Hybrid
USD 120,000 - 160,000
Revenue Enablement Director
Revenue Enablement Director

Cambium Learning Group • United States

On-site
USD 180,000 - 230,000
VP, Innovation & Engineering
VP, Innovation & Engineering

Time4Learning • United States

Remote
USD 150,000 - 200,000
Flexible remote work
Home office setup reimbursement
Team-building activities
Financial Analyst
Financial Analyst

Cambium Learning Group • Northern (KY)

Hybrid
USD 65,000 - 90,000
Senior Software Engineer (AI Applications)
Senior Software Engineer (AI Applications)

SupportFinity™ • Boston (MA)

Hybrid
USD 120,000 - 150,000
Flexible working hours
Home office reimbursement
Collaborative work culture
Information Security Risk Analyst
Information Security Risk Analyst

Lam Research • Tualatin (OR)

Hybrid
USD 80,000 - 110,000