Threat Intelligence Lead

Obsidian SecurityPalo Alto, CA
$240,000 - $280,000

About The Position

Obsidian Security is seeking a Threat Intelligence Lead to build and lead the threat intelligence function. This role is responsible for identifying critical threats, understanding their relevance to Obsidian's product and corporate environment, and developing actionable intelligence. The ideal candidate will be a highly technical, team-oriented professional with an ownership mentality, capable of operating in a dynamic, high-growth startup environment. This is a high-impact role reporting to the Head of Security within the Trust Team, with significant collaboration across various departments including IT, Engineering, Product, and GRC. The position offers the autonomy to mature and scale Obsidian's threat intelligence and threat hunting capabilities, requiring strong analytical skills and the ability to navigate a modern tech stack within a cloud-native organization.

Requirements

  • At least 6 years of experience in threat intelligence, threat hunting, detection engineering, incident response, or security operations.
  • Demonstrated ability to analyze threat data and produce clear, prioritized, actionable assessments for varied audiences.
  • Hands-on threat hunting experience across cloud, SaaS, and endpoint telemetry.
  • Fluency in MITRE ATT&CK and the intelligence lifecycle.
  • Working knowledge of the security capabilities and attack surface of modern IT and SaaS systems (e.g., Okta, Google Workspace, Salesforce, Slack, Notion, Jira).
  • Experience with SIEM query languages.
  • Experience with scripting for automation and enrichment in a language such as Python.
  • Familiarity with intelligence sharing standards and tooling (STIX/TAXII, MISP, OpenCTI, or similar).
  • Obsessive about security while supporting the overall mission.
  • Mission and values-driven, with an ownership mentality.
  • Ability to operate and thrive in a dynamic, high-growth startup environment.
  • Highly technical team player with real analytical depth and judgment.
  • Ability to operate across a cloud-native organization with a cybersecurity mission and modern tech stack.

Nice To Haves

  • Excited about working at an industry-leading cybersecurity startup operating at the cutting edge of the field, defending against state-of-the-art threats.

Responsibilities

  • Collect, correlate, and synthesize threat intelligence from various sources (commercial feeds, open source, ISACs, vendor advisories, researcher communities, dark web) into a coherent picture.
  • Assess the applicability of emerging threats, campaigns, and vulnerabilities to the Obsidian product and corporate infrastructure, determining their relevance and impact.
  • Produce timely, decision-grade intelligence products, including threat advisories, actor and campaign profiles, and periodic briefings for technical teams and leadership.
  • Track threat actors targeting SaaS, cloud, and identity infrastructure, maintaining a view of relevant TTPs mapped to MITRE ATT&CK.
  • Own the intelligence requirements process, defining intelligence needs and driving collection efforts.
  • Run structured, hypothesis-driven threat hunts across corporate and product environments using IOCs, TTPs, and intelligence leads.
  • Operationalize indicators into detections, and manage the lifecycle of IOCs to ensure their continued usefulness.
  • Write and tune detection logic, convert hunt findings into durable detection logic, playbooks, and response actions, and partner with incident response.
  • Support incident investigations with attribution context, actor tradecraft, and pivoting off known infrastructure.
  • Contribute to purple team exercises and validate control effectiveness against intelligence-derived threats.
  • Act as 'customer zero' for the Obsidian product, using it to secure corporate assets, conduct hunts, and pressure-test features.
  • Identify use cases, provide feedback on in-development features, and influence product workflows.

Benefits

  • Competitive compensation with equity
  • 401k
  • Comprehensive healthcare with dental and vision coverage
  • Flexible paid time off
  • Paid holiday time off
  • 12 weeks of new parent or family leave
  • Personal and professional development resources
  • Opportunities for professional development
  • Opportunities to make high-impact contributions to security
  • Opportunities to influence the Obsidian product
  • Annual conference attendance budget
  • Opportunity to publish research, share non-proprietary code, and present at conferences
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service