Principal, Threat Operations Program Lead

National Student ClearinghouseHerndon, VA
Hybrid

About The Position

The Technical Specialist, Threat Operations serves as a senior operational leader and key partner within the Cyber Operations team, acting as the functional second-in-command across threat operations activities. This role is responsible for building, scaling, and sustaining a comprehensive threat operations program that translates threat and exposure signals into actionable insights and business risk decisions. This position combines hands-on operational oversight—including detection, triage, investigation, and response—with ownership of strategic program elements such as threat intelligence, lifecycle governance, and Continuous Threat Exposure Management (CTEM). The role also requires leadership through influence, driving consistent execution, talent development, and high-quality outcomes across analysts, partners, and stakeholders. The Technical Specialist, Threat Operations is expected to maximize AI-assisted and agentic AI workflows while maintaining human accountability, secure data handling, and audit-ready evidence. All outputs must remain defensible, traceable, and aligned with enterprise governance standards. Currently, this is a remote-first position, and this position may be required to periodically work on-site at our office and the frequency would depend on the department/division's requirements. Therefore, candidates must either reside within a reasonable distance to commute to our office or be willing to travel to our office in Herndon, when required.

Requirements

  • Bachelors degree in Cybersecurity, Computer Science, IT, or any related field. A combination of education and experience including military service will also be considered.
  • Current, active certification in one or more of the following is required: CISSP, CISM, GIAC, CySA+, Microsoft Security, or cloud security certifications.
  • 10 years of direct experience in cybersecurity operations, incident response, or threat analysis.
  • Experience investigating cloud security issues (AWS and/or OCI).
  • Hands-on experience with AI-assisted security workflows and governance-aligned practices.
  • Experience developing threat intelligence or CTEM-aligned programs.
  • Experience managing external security partners and service delivery (e.g., MDR/MSSP), including performance outcomes, SLAs, and continuous improvement.
  • Strong knowledge of threat operations, incident response, and investigation methodologies.
  • Advanced understanding of MITRE ATT&CK framework and detection coverage strategies.
  • Knowledge of cloud security threats (AWS, OCI), particularly identity and control plane risks.
  • Understanding of threat intelligence lifecycle and CTEM program implementation.
  • Knowledge of enterprise AI governance, including generative AI risks and controls.
  • Ability to build and scale threat operations processes and programs.
  • Ability to develop metrics and reporting frameworks that drive decision-making.
  • Experience designing AI-assisted investigation and triage workflows.
  • Ability to translate technical risk into business-aligned remediation strategies.
  • Strong decision-making skills under uncertainty, supported by defensible evidence.
  • Excellent communication skills with both technical and executive audiences.
  • High degree of judgment, integrity, and accountability.
  • Ability to collaborate cross-functionally and influence without direct authority.
  • Demonstrated leadership through influence across matrixed teams, partners, and stakeholders, including prioritization, coaching, performance feedback, and operational execution.
  • Exceptional ability to translate and communicate technical risk, threat assessments, and mitigation strategies to technical, executive, and board-level audiences.
  • Demonstrates the Clearinghouse’s core competencies: customer focus, optimizes work processes, communicates effectively, collaborates, and is open and authentic.
  • Must live within a commutable distance to Herndon, VA or in one of the Clearinghouse's approved States for hiring purposes.
  • Must be currently authorized to work in the United States on a full-time basis.
  • We do not intend to sponsor external applicants for work visas, and may consider sponsorship only if no qualified candidates can be found who are authorized to work without sponsorship.
  • Must be at least 18 years old.

Nice To Haves

  • Experience building or maturing CTEM programs.
  • Experience managing MDR/MSSP vendors using outcomes-based metrics.
  • Scripting or query language experience (e.g., Python, PowerShell, KQL).
  • Experience presenting to senior leadership or board-level audiences.
  • Experience with SOAR automation and AI-assisted investigation workflows.
  • Experience with enterprise Copilot tools and governed AI environments.
  • Knowledge of security tools such as Microsoft Defender, Wiz Defend, etc.
  • Experience implementing QA and validation processes for AI outputs.
  • Prior experience managing direct reports within a cybersecurity, threat intel, or technical environment

Responsibilities

  • Demonstrate the Clearinghouse's core competencies: Customer Focus, Optimizes Work Processes, Collaborates, Communicates Effectively, and Be Open and Authentic.
  • Oversee detection, triage, and validation of security alerts, ensuring timely and evidence-based disposition.
  • Translate technical findings into clear risk-based recommendations and actionable next steps.
  • Serve as escalation lead during high-severity incidents, ensuring proper scoping, documentation, and remediation to closure.
  • Develop and mature the threat operations program roadmap, including CTEM strategy and operating model.
  • Perform business-centric threat modeling to align adversary activity with enterprise risk and impact.
  • Define governance frameworks, including prioritization logic, escalation criteria, and executive reporting.
  • Design and continuously improve repeatable workflows, including AI-assisted triage, investigation, and reporting processes.
  • Establish and manage key performance indicators (e.g., MTTD, MTTR, detection quality, noise reduction).
  • Maintain playbooks, investigation templates, and escalation workflows to ensure consistency and audit readiness.
  • Drive continuous improvement of detection fidelity through tuning and feedback loops.
  • Implement AI-assisted workflows with clear human-in-the-loop validation and decision points.
  • Ensure secure handling of sensitive data and alignment with enterprise AI governance policies.
  • Validate AI outputs for accuracy and reliability and mitigate known risks such as hallucinations, bias, or incomplete context.
  • Harden AI processes against adversarial threats (e.g., prompt injection, data leakage).
  • Lead the threat intelligence lifecycle, including requirements, collection, analysis, dissemination, and feedback.
  • Translate intelligence into actionable outputs such as threat hunts, detection priorities, and control validation.
  • Deliver executive-ready threat assessments with clear sourcing and confidence levels.
  • Establish operating rhythms and performance expectations with external security partners.
  • Ensure alignment with MITRE ATT&CK coverage and measurable detection and response outcomes.
  • Integrate partner outputs into internal workflows, ensuring accountability and closure of findings.
  • Lead investigations involving cloud control plane threats (such as AWS and OCI), focusing on identity and configuration risks.
  • Correlate cloud, endpoint, identity, and network signals to prioritize remediation based on risk.
  • Partner with engineering teams to validate remediation and risk acceptance actions and decisions.
  • Coordinate with incident response, engineering, and business stakeholders to drive remediation.
  • Integrate third-party risk insights into threat analysis and recommendations.
  • Partner with architecture and assurance teams to improve long-term security controls.
  • Position may be required to perform other duties as required.
  • These essential functions are representative of those that must be met by an employee to successfully perform the job.
  • Reasonable accommodations will be made to enable individuals with disabilities to perform these essential functions.

Benefits

  • Comprehensive medical, dental, and vision insurance
  • Life and disability insurance benefits
  • Health care, dependent care, and limited purpose flexible spending accounts
  • Health savings account with annual employer contributions
  • Voluntary supplemental health plans for Accident and Hospital Indemnity coverage
  • Infertility coverage
  • Generous 401k matching contribution program with the opportunity to defer pre-tax and Roth contributions, as well as catch-up contributions
  • Competitive paid leave program consisting of vacation, sick, and personal time
  • Paid holidays
  • Up to 3 weeks of paid parental leave during a 12-month period
  • Up to 5 days of paid military leave per calendar year
  • Reimbursed for basic wholesale company and roadside assistance memberships
  • Option to request a buy back on portions of unused accrued vacation
  • Employee Education Assistance Program
  • LinkedIn Learning subscription
  • Mental health support with up to eight free therapy sessions for employees and their family members
  • Well-being reward benefits
  • Eligibility for service credit towards the Public Service Loan Forgiveness program (PSLF)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service