Senior Threat Intelligence Analyst

ID.meMcLean, VA
Onsite

About The Position

ID.me is seeking a senior threat intelligence professional to lead the technical tracking of adversaries targeting the identity verification ecosystem and translate this tracking into actionable business decisions. This role involves understanding the industrialized market of identity fraud, including credential and document vendors, injection and deepfake tooling, synthetic identity brokers, and organized account takeover crews. The position offers high autonomy and significant influence over security and product direction, with responsibilities including setting collection strategy, conducting research, building models and tooling, and delivering intelligence products to various stakeholders. The role also involves technical mentorship and setting analytical standards for the team.

Requirements

  • 5+ years of experience in threat intelligence, cyber threat hunting, fraud intelligence, or a closely related discipline, including experience producing finished intelligence for decision-makers.
  • 3+ years of hands-on collection across the deep and dark web, including illicit marketplaces and encrypted communication platforms, with demonstrated tradecraft and operational security practices.
  • Deep, applied experience with common analysis models and frameworks (MITRE ATT&CK, the Diamond Model, kill chain, structured analytic techniques), with a track record of using them to reach and defend analytic judgments.
  • Demonstrated ability to take ambiguous, fragmentary, and conflicting information and produce a clear assessment with appropriately expressed confidence.
  • Exceptional written and verbal communication skills, including experience writing for both deeply technical and executive audiences.
  • Track record of working independently: scoping own problems, setting priorities, and driving work to a result without close direction.
  • Proven ability to influence stakeholders outside of security and translate intelligence into changes other teams implement.

Nice To Haves

  • Experience with identity fraud, account takeover, synthetic identity, document and biometric fraud, or the fraud-as-a-service ecosystem.
  • Strong SQL skills for independent data analysis at scale, and scripting in Python or similar for collection, enrichment, and automation.
  • Experience turning intelligence into production detections or fraud controls alongside engineering and data science teams.
  • Experience mentoring analysts or leading intelligence projects across multiple contributors.
  • Relevant certifications such as GCTI, GREM, GCFA, GOSI, CISSP, or Security+.
  • Working proficiency in a foreign language relevant to threat actor communities.
  • Experience in a regulated or government-facing environment, or supporting external partners with intelligence products.

Responsibilities

  • Own an intelligence portfolio, taking end-to-end responsibility for tracking threat actors, fraud typologies, or ecosystems targeting ID.me and its partners, from collection through analysis to delivery and follow-up.
  • Set collection strategy by defining and prioritizing intelligence requirements in partnership with security, fraud, product, and company leadership, and identifying and closing gaps in current coverage.
  • Conduct sustained technical collection and source development across deep and dark web forums, illicit marketplaces, encrypted messaging platforms, and closed communities, employing sound tradecraft and operational security.
  • Proactively hunt for new actor activity, tooling, and TTPs across internal telemetry and external sources.
  • Produce finished intelligence assessments with clear judgments, stated confidence levels, articulated assumptions, and specific recommendations for diverse audiences.
  • Convert research into operational intelligence, such as detections, fraud signals, blocklists, enrichment, and platform data, and collaborate with engineering and data science teams for deployment and measurement.
  • Advance the team's analytic tradecraft by improving threat modeling standards, structured analytic methods, reporting templates, source evaluation, and the use of frameworks like MITRE ATT&CK and the Diamond Model.
  • Build or specify tooling, pipelines, and enrichment to automate manual work and expand coverage.
  • Mentor analysts on collection tradecraft, analytic writing, and structured analysis, and review their work to develop their judgment.
  • Represent the threat intelligence function by briefing senior leadership, partners, industry peer groups, law enforcement, and information-sharing communities.

Benefits

  • Full-time employment
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service