Senior Threat Intelligence Analyst

ID.me

McLean, Mountain View (VA, CA)

On-site

USD 150,000 - 190,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

ID.me, a leading digital identity platform, is seeking a senior threat intelligence professional to lead end-to-end tracking of adversaries targeting our identity ecosystem. You will own collection, research, model building, and delivery of finished intelligence to engineers, executives, and partners.

This senior IC role demands independent work, strong communication, and ability to influence product and security directions.

Qualifications

  • 5+ years of experience in threat intelligence, cyber threat hunting, fraud intelligence, or a closely related discipline.
  • 3+ years of hands-on collection across the deep and dark web, including illicit marketplaces and encrypted communication platforms.
  • Deep, applied experience with common analysis models and frameworks (MITRE ATT&CK, the Diamond Model, kill chain, structured analytic techniques).
  • Demonstrated ability to translate intelligence into actionable decisions for engineers, executives, and external partners.
  • Exceptional written and verbal communication, with ability to influence stakeholders outside security.

Responsibilities

  • Own an intelligence portfolio covering threat actors, fraud typologies, and ecosystems targeting ID.me and partners from collection to delivery.
  • Define and prioritize intelligence requirements in partnership with security, fraud, product, and leadership.
  • Conduct collection across deep/dark web, illicit marketplaces, encrypted platforms with strong operational security.
  • Proactively hunt for new actor activity, tooling, and TTPs across internal and external sources.
  • Write finished intelligence with clear judgments, confidence levels, and concrete recommendations for diverse audiences.
  • Convert research into detections, fraud signals, and platform enrichment; collaborate with detection engineering and product teams.
  • Improve analytic tradecraft: threat modeling, reporting templates, and source evaluation.
  • Identify where automation is needed and build or specify tooling and pipelines.
  • Mentor analysts, review work, and raise analytic judgment and standards.
  • Represent the function by briefing senior leadership, partners, and industry groups.

Skills

Threat intelligence
Cyber threat hunting
Fraud intelligence
Structured analytic techniques
MITRE ATT&CK
Diamond Model
Communication skills
Independent worker
Influence stakeholders

Tools

SQL
Python
Data analysis tools

Job description

Company Overview

ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly login across websites without having to create a new login and verify their identity again. Over 152 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600+ consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships. ID.me’s technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to “No Identity Left Behind” to enable all people to have a secure digital identity. To learn more, visit https://network.id.me/ .

ID.me is a full-time, in-office culture. Unless a specific job description explicitly states otherwise, all roles are on-site five days per week at one of our offices in McLean, VA; Mountain View, CA; New York City, NY; or Tampa, FL. Certain roles — such as field-based sales or other remote-by-design positions — may have different work arrangements as noted in their individual postings.

At ID.me, we embrace the thoughtful use of AI tools in our daily work and there are even occasions where we leverage AI in our hiring process. However, during the interview process, we want to understand your individual skills and experiences. Therefore, we have guidelines on how AI can be appropriately used during your application and interviews which can be found here .

ID.me is looking for a senior threat intelligence professional to lead technical tracking of the adversaries targeting the identity verification ecosystem, and to turn that tracking into decisions the business acts on. Identity fraud is an industrialized market of credential and document vendors, injection and deepfake tooling, synthetic identity brokers, and organized account takeover crews. This role sits directly across from it.

You will own intelligence coverage for a defined set of threats end to end: setting the collection strategy, running the research, building the models and tooling, and delivering the finished product to the people who need it, from detection engineers to executives and government partners. This is a senior individual-contributor role with high autonomy and real influence over security and product direction. You will also be a technical mentor to the analysts around you and a standard-setter for how the team does analysis.

Responsibilities

  • Own an intelligence portfolio. Take end-to-end responsibility for tracking a set of threat actors, fraud typologies, or ecosystems targeting ID.me and our partners, from collection through analysis to delivery and follow-up.
  • Set collection strategy. Define and prioritize intelligence requirements in partnership with security, fraud, product, and company leadership. Identify gaps in current coverage and close them.
  • Run technical collection at depth. Conduct sustained collection and source development across deep and dark web forums, illicit marketplaces, encrypted messaging platforms, and closed communities, using sound tradecraft and operational security.
  • Hunt emerging activity. Proactively hunt for new actor activity, tooling, and TTPs across internal telemetry and external sources, and pull threads before they become incidents.
  • Produce finished intelligence. Write assessments that hold up to scrutiny, with clear judgments, stated confidence levels, articulated assumptions, and specific recommendations, for audiences ranging from engineers to the executive team to external partners.
  • Make intelligence operational. Convert research into detections, fraud signals, blocklists, enrichment, and platform data. Work with detection engineering, data science, and product to get it deployed and measure whether it worked.
  • Advance the team's analytic tradecraft. Improve threat modeling standards, structured analytic methods, reporting templates, source evaluation, and the team's use of frameworks such as MITRE ATT&CK and the Diamond Model.
  • Build tooling and automation. Identify where manual work is limiting coverage and build or specify the tooling, pipelines, and enrichment to remove it.
  • Mentor and raise the bar. Coach analysts on collection tradecraft, analytic writing, and structured analysis. Review their work and help develop their judgment.
  • Represent the function. Brief senior leadership, partners, and where appropriate, industry peer groups, law enforcement, and information-sharing communities.

Qualifications

  • 5+ years of experience in threat intelligence, cyber threat hunting, fraud intelligence, or a closely related discipline, including experience producing finished intelligence for decision-makers.
  • 3+ years of hands-on collection across the deep and dark web, including illicit marketplaces and encrypted communication platforms, with demonstrated tradecraft and operational security practices.
  • Deep, applied experience with common analysis models and frameworks (MITRE ATT&CK, the Diamond Model, kill chain, structured analytic techniques). Not just familiarity, but a track record of using them to reach and defend analytic judgments.
  • Demonstrated ability to take ambiguous, fragmentary, and conflicting information and produce a clear assessment with appropriately expressed confidence.
  • Exceptional written and verbal communication, including experience writing for both deeply technical and executive audiences.
  • Track record of working independently: scoping your own problems, setting priorities, and driving work to a result without close direction.
  • Proven ability to influence stakeholders outside of security, and to translate intelligence into changes other teams actually make.

Preferred Qualifications

  • Experience with identity fraud, account takeover, synthetic identity, document and biometric fraud, or the fraud-as-a-service ecosystem.
  • Strong SQL skills for independent data analysis at scale, and scripting in Python or similar for collection, enrichment, and automation.
  • Experience turning intelligence into production detections or fraud controls alongside engineering and data science teams.
  • Experience mentoring analysts or leading intelligence projects across multiple contributors.
  • Relevant certifications such as GCTI, GREM, GCFA, GOSI, CISSP, or Security+.
  • Working proficiency in a foreign language relevant to threat actor communities.
  • Experience in a regulated or government-facing environment, or supporting external partners with intelligence products.

ID.me maintains a work environment free from discrimination, where employees are treated with dignity and respect. All ID.me employees share in the responsibility for fulfilling our commitment to equal employment opportunity. ID.me does not discriminate against any employee or applicant on the basis of age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. ID.me adheres to these principles in all aspects of employment, including recruitment, hiring, training, compensation, promotion, benefits, social and recreational programs, and discipline. In addition, ID.me's policy is to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations and ordinances where a particular employee works. Upon request we will provide you with more information about such accommodations.

Please review our Privacy Policy, including our CCPA policy, at id.me/privacy . If you provide ID.me with any personally identifiable information you confirm that you have read and agree to be bound by the terms and conditions set out in our Privacy Policy.

ID.me participates in E-Verify.

This role requires working onsite 5 days per week at one of our hub offices (Mountain View, CA or McLean, VA).

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Threat Intelligence Analyst
Senior Threat Intelligence Analyst

Idme • McLean (VA)

On-site
USD 150,000 - 230,000
Senior Threat Intelligence Analyst
Senior Threat Intelligence Analyst

ID.me • Washington, Baltimore (MD)

On-site
USD 140,000 - 200,000
Director of Product Security
Director of Product Security

ID.me • Mountain View (CA)

On-site
USD 244,000 - 272,000
Medical benefits
401(k) with company match
Paid time off
Director of Product Security
Director of Product Security

ID.me • San Francisco (CA)

On-site
USD 244,000 - 272,000
Medical benefits
Dental benefits
Vision benefits
+2
Senior Software Development Engineer - Fullstack
Senior Software Development Engineer - Fullstack

Socket.dev • McLean (VA)

On-site
USD 191,000 - 231,000
Account Executive, Workforce Identity East
Account Executive, Workforce Identity East

ID.me • Washington

On-site
USD 140,000 - 160,000
Director of Product Security
Director of Product Security

Idme • Mountain View (CA)

On-site
USD 244,000 - 272,000
Vice President Communications
Vice President Communications

ID.me • Mountain View (CA), McLean (VA)

On-site
USD 275,000 - 350,000
Staff Software Engineer - Applications, Full Stack
Staff Software Engineer - Applications, Full Stack

Idme • McLean (VA)

On-site
USD 183,000 - 215,000
Medical, dental, vision benefits
401(k) with company match
Unlimited PTO
Senior Software Development Engineer - Fullstack
Senior Software Development Engineer - Fullstack

ID.me • Maryland

On-site
USD 191,000 - 231,000
Medical insurance
Dental insurance
Vision insurance
+4