Senior Threat Intelligence Analyst

Idme

McLean (VA)

On-site

USD 150,000 - 230,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

ID.me is seeking a senior threat intelligence professional to lead end-to-end tracking of threat actors and fraud ecosystems impacting the identity verification space. You will own intelligence coverage, set collection strategy, and deliver actionable assessments to engineers, product, executives, and partners.

You will also mentor analysts, develop analytic tradecraft, and drive operational intelligence, detections, and platform enrichment aligned with business needs.

Qualifications

  • 5+ years of experience in threat intelligence, cyber threat hunting, fraud intelligence, or a closely related discipline.

Responsibilities

  • Own an intelligence portfolio.
  • Set collection strategy.
  • Run technical collection at depth.
  • Hunt emerging activity.
  • Produce finished intelligence.
  • Make intelligence operational.
  • Advance the team's analytic tradecraft.
  • Build tooling and automation.
  • Mentor and raise the bar.
  • Represent the function.

Skills

Threat intelligence
Threat hunting
Deep/dark web collection
MITRE ATT&CK
Analytic writing
SQL
Python

Tools

SQL
Python

Job description

Company Overview

ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly login across websites without having to create a new login and verify their identity again. Over 152 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600+ consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships. ID.me’s technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to 'No Identity Left Behind' to enable all people to have a secure digital identity. To learn more, visit https://network.id.me/.

ID.me is a full-time, in-office culture. Unless a specific job description explicitly states otherwise, all roles are on-site five days per week at one of our offices in McLean, VA; Mountain View, CA; New York City, NY; or Tampa, FL. Certain roles — such as field-based sales or other remote-by-design positions — may have different work arrangements as noted in their individual postings.

At ID.me, we embrace the thoughtful use of AI tools in our daily work and there are even occasions where we leverage AI in our hiring process. However, during the interview process, we want to understand your individual skills and experiences. Therefore, we have guidelines on how AI can be appropriately used during your application and interviews which can be found here.

ID.me is looking for a senior threat intelligence professional to lead technical tracking of the adversaries targeting the identity verification ecosystem, and to turn that tracking into decisions the business acts on. Identity fraud is an industrialized market of credential and document vendors, injection and deepfake tooling, synthetic identity brokers, and organized account takeover crews. This role sits directly across from it.

You will own intelligence coverage for a defined set of threats end to end: setting the collection strategy, running the research, building the models and tooling, and delivering the finished product to the people who need it, from detection engineers to executives and government partners. This is a senior individual-contributor role with high autonomy and real influence over security and product direction. You will also be a technical mentor to the analysts around you and a standard-setter for how the team does analysis.

Responsibilities
  • Own an intelligence portfolio. Take end-to-end responsibility for tracking a set of threat actors, fraud typologies, or ecosystems targeting ID.me and our partners, from collection through analysis to delivery and follow-up.
  • Set collection strategy. Define and prioritize intelligence requirements in partnership with security, fraud, product, and company leadership. Identify gaps in current coverage and close them.
  • Run technical collection at depth. Conduct sustained collection and source development across deep and dark web forums, illicit marketplaces, encrypted messaging platforms, and closed communities, using sound tradecraft and operational security.
  • Hunt emerging activity. Proactively hunt for new actor activity, tooling, and TTPs across internal telemetry and external sources, and pull threads before they become incidents.
  • Produce finished intelligence. Write assessments that hold up to scrutiny, with clear judgments, stated confidence levels, articulated assumptions, and specific recommendations, for audiences ranging from engineers to the executive team to external partners.
  • Make intelligence operational. Convert research into detections, fraud signals, blocklists, enrichment, and platform data. Work with detection engineering, data science, and product to get it deployed and measure whether it worked.
  • Advance the team's analytic tradecraft. Improve threat modeling standards, structured analytic methods, reporting templates, source evaluation, and the team's use of frameworks such as MITRE ATT&CK and the Diamond Model.
  • Build tooling and automation. Identify where manual work is limiting coverage and build or specify the tooling, pipelines, and enrichment to remove it.
  • Mentor and raise the bar. Coach analysts on collection tradecraft, analytic writing, and structured analysis. Review their work and help develop their judgment.
  • Represent the function. Brief senior leadership, partners, and where appropriate, industry peer groups, law enforcement, and information-sharing communities.
Qualifications
  • 5+ years of experience in threat intelligence, cyber threat hunting, fraud intelligence, or a closely related discipline, including experience producing finished intelligence for decision-makers.
  • 3+ years of hands-on collection across the deep and dark web, including illicit marketplaces and encrypted communication platforms, with demonstrated tradecraft and operational security practices.
  • Deep, applied experience with common analysis models and frameworks (MITRE ATT&CK, the Diamond Model, kill chain, structured analytic techniques). Not just familiarity, but a track record of using them to reach and defend analytic judgments.
  • Demonstrated ability to take ambiguous, fragmentary, and conflicting information and produce a clear assessment with appropriately expressed confidence.
  • Exceptional written and verbal communication, including experience writing for both deeply technical and executive audiences.
  • Track record of working independently: scoping your own problems, setting priorities, and driving work to a result without close direction.
  • Proven ability to influence stakeholders outside of security, and to translate intelligence into changes other teams actually make.
Preferred Qualifications
  • Experience with identity fraud, account takeover, synthetic identity, document and biometric fraud, or the fraud-as-a-service ecosystem.
  • Strong SQL skills for independent data analysis at scale, and scripting in Python or similar for collection, enrichment, and automation.
  • Experience turning intelligence into production detections or fraud controls alongside engineering and data science teams.
  • Experience mentoring analysts or leading intelligence projects across multiple contributors.
  • Relevant certifications such as GCTI, GREM, GCFA, GOSI, CISSP, or Security+.
  • Working proficiency in a foreign language relevant to threat actor communities.
  • Experience in a regulated or government-facing environment, or supporting external partners with intelligence products.

ID.me maintains a work environment free from discrimination, where employees are treated with dignity and respect. All ID.me employees share in the responsibility for fulfilling our commitment to equal employment opportunity. ID.me does not discriminate against any employee or applicant on the basis of age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. ID.me adheres to these principles in all aspects of employment, including recruitment, hiring, training, compensation, promotion, benefits, social and recreational programs, and discipline. In addition, ID.me's policy is to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations and ordinances where a particular employee works. Upon request we will provide you with more information about such accommodations.

Please review our Privacy Policy, including our CCPA policy, at id.me/privacy. If you provide ID.me with any personally identifiable information you confirm that you have read and agree to be bound by the terms and conditions set out in our Privacy Policy.

ID.me participates in E-Verify.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Threat Intelligence Analyst
Senior Threat Intelligence Analyst

ID.me • McLean (VA), Mountain View (CA)

On-site
USD 150,000 - 190,000
Senior Threat Intelligence Analyst
Senior Threat Intelligence Analyst

ID.me • Washington, Baltimore (MD)

On-site
USD 140,000 - 200,000
Director of Product Security
Director of Product Security

ID.me • Mountain View (CA)

On-site
USD 244,000 - 272,000
Medical benefits
401(k) with company match
Paid time off
Director of Product Security
Director of Product Security

ID.me • San Francisco (CA)

On-site
USD 244,000 - 272,000
Medical benefits
Dental benefits
Vision benefits
+2
Senior Software Development Engineer - Fullstack
Senior Software Development Engineer - Fullstack

Socket.dev • McLean (VA)

On-site
USD 191,000 - 231,000
Director of Product Security
Director of Product Security

Idme • Mountain View (CA)

On-site
USD 244,000 - 272,000
Vice President Communications
Vice President Communications

ID.me • Washington

On-site
USD 275,000 - 350,000
Comprehensive medical, dental, vision
401(k) with company match
Unlimited paid time off
Senior Software Engineer - Wallet - Authentication
Senior Software Engineer - Wallet - Authentication

ID.me • Mountain View (CA)

On-site
USD 133,000 - 222,000
Vice President Communications
Vice President Communications

ID.me • Mountain View (CA), McLean (VA)

On-site
USD 275,000 - 350,000
Senior Software Engineer – Quality Engineering
Senior Software Engineer – Quality Engineering

ID.me • San Francisco (CA)

On-site
USD 191,000 - 231,000