Manager, Cyber Threat Intelligence – Response

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of DON PEO MLB

DON PEO MLB

501 - 1000 employees

Founded 2020

🎖️ Defense

📦 Logistics

💼 Consulting

Defense • Logistics • Consulting

DON PEO MLB is an official organization within the U. S. Department of Defense that focuses on delivering effective and affordable business IT solutions to enhance the readiness of the Navy and Marine Corps. The organization provides critical defense business systems that support staffing, training, organizing, and equipping forces worldwide. Through innovative technology services and continuous improvement, PEO MLB enables day-to-day operations and modernizes enterprise business systems tailored to the needs of military personnel.

📋 Description

• Lead MLB's threat intelligence and incident response programs across the League office, the 30 Clubs, and their affiliates • Own the vulnerability intelligence program and assess real-world risk from vulnerabilities, exploit code, proof-of-concepts, and threat actor weaponization • Set remediation priorities using severity, exploit intelligence, asset context, and active targeting • Direct research across OSINT, social media, deep and dark web sources, commercial intelligence platforms, and industry information-sharing groups • Track threat actors, campaigns, indicators of compromise, and tactics, techniques, and procedures • Build automation for vulnerability research, intelligence enrichment, alert correlation, investigation support, and reporting • Convert intelligence into detection content, alert logic, hunt hypotheses, and tuning recommendations using Sigma, YARA, SIEM queries, EDR logic, and detection-as-code practices • Develop and lead hypothesis-driven threat hunts across endpoint, identity, cloud, network, email, and application telemetry • Support the incident response lifecycle from triage through closure, including containment, eradication, recovery, and escalation • Serve as incident commander when on-call and lead incident bridges involving the vSOC, Clubs, Legal, Privacy, Communications, Technology, and other stakeholders • Lead post-incident reviews, update playbooks and controls, and track corrective actions • Lead analysts, contractors, vSOC partners, and external security providers • Own security awareness training, education, and phishing simulation programs • Plan and lead League-wide, Club, and internal tabletop exercises • Develop and maintain incident response plans, escalation paths, procedures, and playbooks

🎯 Requirements

• Bachelor's degree in Cybersecurity, Information Security, Computer Science, Criminal Justice, Criminology, Law, or a related field, or equivalent practical experience • Strong knowledge of threat actors, campaigns, indicators of compromise, tactics, techniques, and procedures, including practical use of the MITRE ATT&CK framework • Working knowledge of AWS or GCP • Scripting, detection, or query languages such as PowerShell, Python, SQL, KQL, SPL, Sigma, or YARA • Experience in cyber threat intelligence, incident response, security operations, digital forensics, or a related security role • Experience leading security incidents through triage, escalation, containment, eradication, recovery, and post-incident review • Experience developing and running threat hunts across endpoint, identity, cloud, network, email, or application data • Experience developing or tuning detection content using SIEM queries, EDR logic, Sigma, YARA, or detection-as-code practices • Hands-on experience with EDR/XDR, SIEM, and vulnerability assessment platforms • Experience using OSINT, social media sources, deep and dark web monitoring, and commercial threat intelligence platforms • Experience with security automation and orchestration (SOAR) platforms, including building workflows for threat intel research, enrichment, correlation, and reporting • Strong documentation and communication skills, including explaining attack methods, response decisions, and risk to technical and non-technical audiences • Ability to handle sensitive information and participate in a rotational after-hours on-call and incident escalation schedule • Preferred certifications: CompTIA CySA+, CompTIA CTIA, or SANS GIAC Cyber Threat Intelligence (GCTI)

🏖️ Benefits

• Competitive Benefits Package • Company 401K Contribution • Paid Time Off and Holidays • Paid Parental Leave • Access to Free Tickets to Baseball Games & MLB.TV • Discounts at MLB Store | MLBShop.com • Employee Assistance Programs (EAP) • Onsite/Online Training & Development Programs • Tuition Reimbursement • Disability Benefits (short term and long term) • Life and Accidental Death Insurance • Pet Insurance • Bonus

Apply Now

Similar Jobs

🔥 19 minutes ago

CVS Health

10,000+ employees

🏥 Healthcare

⚕️ Healthcare Insurance

🛒 Retail

CVS Health provider relations manager supporting Medicaid policies, provider systems, credentialing, and claims operations. Ensuring contractual service standards for Aetna Better Health of Oklahoma.

🔥 21 minutes ago

Radiology Partners

5001 - 10000

🏥 Healthcare

🤝 B2B

👥 B2C

Payor strategy manager optimizing contracting, KPIs, and revenue opportunities for Radiology Partners, a U.S. radiology practice. Partnering with Analytics, Finance, and Revenue Cycle Management on strategic initiatives.

🔥 51 minutes ago

BCD Travel

10,000+ employees

💼 Consulting

📦 Logistics

🏨 Hospitality

Meeting Manager leading high-profile meetings and events for BCD Meetings & Events, a global meetings and events agency. Managing strategy, logistics, budgets, vendors, clients, and on-site execution.

🔥 1 hour ago

Shiseido

10,000+ employees

🏭 Manufacturing

📣 Marketing

🍽️ Food & Beverage

Senior Manager driving Amazon marketplace growth for Shiseido’s prestige beauty brands. Owning strategy, P&L, promotions, media, and cross-functional execution.

🔥 1 hour ago

Ziff Davis

1001 - 5000

💼 Consulting

🏥 Healthcare

📣 Marketing

Customer Solutions Manager helping Ookla, a connectivity intelligence company, guide complex enterprise customers from pre-sales through renewal readiness. Translating network data into strategic recommendations and measurable value.