Senior Threat Intelligence Analyst

ID.meMountain View, VA
Onsite

About The Position

ID.me is seeking a senior threat intelligence professional to lead technical tracking of adversaries targeting the identity verification ecosystem and translate that tracking into actionable business decisions. This role involves understanding the industrialized market of identity fraud, including credential and document vendors, tooling, synthetic identity brokers, and organized account takeover crews. The analyst will own intelligence coverage end-to-end for defined threats, from collection strategy and research to model and tooling development, and delivering finished intelligence to various stakeholders including detection engineers, executives, and government partners. This is a senior individual-contributor role offering high autonomy and influence over security and product direction. The position also involves technical mentorship for other analysts and setting standards for team analysis.

Requirements

  • 5+ years of experience in threat intelligence, cyber threat hunting, fraud intelligence, or a closely related discipline, including experience producing finished intelligence for decision-makers.
  • 3+ years of hands-on collection across the deep and dark web, including illicit marketplaces and encrypted communication platforms, with demonstrated tradecraft and operational security practices.
  • Deep, applied experience with common analysis models and frameworks (MITRE ATT&CK, the Diamond Model, kill chain, structured analytic techniques), with a track record of using them to reach and defend analytic judgments.
  • Demonstrated ability to take ambiguous, fragmentary, and conflicting information and produce a clear assessment with appropriately expressed confidence.
  • Exceptional written and verbal communication skills, including experience writing for both deeply technical and executive audiences.
  • Track record of working independently: scoping own problems, setting priorities, and driving work to a result without close direction.
  • Proven ability to influence stakeholders outside of security and translate intelligence into actionable changes for other teams.

Nice To Haves

  • Experience with identity fraud, account takeover, synthetic identity, document and biometric fraud, or the fraud-as-a-service ecosystem.
  • Strong SQL skills for independent data analysis at scale.
  • Scripting in Python or similar for collection, enrichment, and automation.
  • Experience turning intelligence into production detections or fraud controls alongside engineering and data science teams.
  • Experience mentoring analysts or leading intelligence projects across multiple contributors.
  • Relevant certifications such as GCTI, GREM, GCFA, GOSI, CISSP, or Security+.
  • Working proficiency in a foreign language relevant to threat actor communities.
  • Experience in a regulated or government-facing environment, or supporting external partners with intelligence products.

Responsibilities

  • Own an intelligence portfolio, taking end-to-end responsibility for tracking threat actors, fraud typologies, or ecosystems targeting ID.me and its partners, from collection through analysis to delivery and follow-up.
  • Set collection strategy by defining and prioritizing intelligence requirements in partnership with security, fraud, product, and company leadership, and identifying and closing gaps in current coverage.
  • Conduct technical collection at depth across deep and dark web forums, illicit marketplaces, encrypted messaging platforms, and closed communities, using sound tradecraft and operational security.
  • Proactively hunt for new actor activity, tooling, and TTPs across internal telemetry and external sources, identifying potential threats before they escalate into incidents.
  • Produce finished intelligence in the form of assessments with clear judgments, stated confidence levels, articulated assumptions, and specific recommendations for diverse audiences.
  • Make intelligence operational by converting research into detections, fraud signals, blocklists, enrichment, and platform data, and working with relevant teams to deploy and measure effectiveness.
  • Advance the team's analytic tradecraft by improving threat modeling standards, structured analytic methods, reporting templates, source evaluation, and the team's use of frameworks like MITRE ATT&CK and the Diamond Model.
  • Build or specify tooling, pipelines, and enrichment to automate manual work and expand coverage.
  • Mentor analysts on collection tradecraft, analytic writing, and structured analysis, and review their work to develop their judgment.
  • Represent the function by briefing senior leadership, partners, industry peer groups, law enforcement, and information-sharing communities.

Benefits

  • Full-time employment
  • In-office culture
  • Commitment to equal employment opportunity
  • Reasonable accommodation for qualified employees with disabilities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service