Job Closed

This listing is no longer active.

RTX logo
RTX

RTX Corporation is an Aerospace and Defense company that provides advanced systems and services for commercial, military and government customers worldwide. It comprises three industry-leading businesses – Collins Aerospace Systems, Pratt & Whitney, and Raytheon.

Threat Intelligence Lead (Remote)

Threat Intelligence SpecialistSecurity AnalystFull TimeRemoteLeadTeam 10,001+Since 2020H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

56 days ago

Salary

$107K - $204K / year

Seniority

Lead

Job Description

Threat Intelligence Lead (Remote)

RTX

Date Posted: 2026-04-10Country: United States of AmericaLocation: US-CA-REMOTEPosition Role Type: RemoteU.S. Citizen, U.S. Person, or Immigration Status Requirements: The ability to obtain and maintain a U.S. government issued security clearance is required.​ U.S. citizenship is required, as only U.S. citizens are eligible for a security clearanceSecurity Clearance Type: DoD Clearance: Top SecretSecurity Clearance Status: Active and existing security clearance required after day 1 At RTX, the world largest aerospace and defense company, 185,000 great minds are united by purpose and inspired to make a difference solving the world’s most complex problems. With our three market leading businesses, world-class operations and investments in research and development, we offer capabilities and opportunity no one else can. Together, we push the boundaries of known science and find new ways to connect and protect our world. Pratt & Whitney is a world leader in the design, manufacture and service of aircraft engines and auxiliary power systems and has been revolutionizing modern flight for over 100 years. Join us and help shape the future of aerospace and defense. The Pratt & Whitney Global Security Services (GSS) Threat Intelligence Lead is a cyber investigative and analytics role responsible for leading data exfiltration investigations and advancing insider threat detection capabilities within the Threat Management and Intelligence program. Operating at the intersection of cybersecurity, digital forensics, and intelligence analysis, this role focuses on identifying, investigating, and mitigating risks related to the unauthorized movement of sensitive data—including intellectual property and controlled technical information—across endpoints, cloud platforms, email systems, and removable media. The ideal candidate combines investigative experience with strong technical expertise, leveraging enterprise security tools such as Splunk and DLP platforms to detect anomalous behavior and support complex investigations. This role also incorporates open-source intelligence (OSINT) to enrich investigations and strengthen risk identification. In addition to supporting investigations, the Intelligence Lead applies behavioral analytics and trend analysis to proactively identify insider threat indicators and deliver clear, actionable intelligence. What You Will Do: - Lead complex investigations involving data exfiltration, insider threat activity, and misuse of enterprise systems. - Validate and triage alerts from DLP, SIEM, and UEBA; reconstruct user activity and data movement to establish intent, scope, and impact . - Collect, preserve, and analyze digital evidence in support of investigations, ensuring chain-of-custody and legal defensibility. - Conduct forensic analysis of file transfers, user activity, and system artifacts. - Partner with Legal and HR to ensure investigations meet regulatory and evidentiary standards. - Leverage OSINT tools and techniques (e.g., link analysis, persona development, attribution) to identify external risk indicators and potential insider collusion. - Conduct proactive threat hunting to identify previously undetected insider risk activity. - Partner with Cybersecurity (SOC), HR, Legal, Compliance, and IT to coordinate investigative actions and response strategies. - Provide subject matter expertise on data exfiltration risks, investigative findings, and mitigation actions; support escalation and response for high-risk or sensitive incidents. - Produce clear, concise investigative reports and intelligence briefings for technical and non-technical audiences. - Translate complex technical findings into actionable recommendations, including risk mitigation, corrective actions, and control enhancements. - Support the evolution of the insider threat program through process improvements, tool optimization, and policy enhancements. Qualifications You Must Have: - Bachelor’s degree in Cybersecurity, Computer Science, Criminal Justice, Intelligence Studies, or related field (or equivalent experience) and minimum 8 years experience in cyber investigations, digital forensics, insider threat, intelligence analysis, or related fields; or An Advanced Degree in a related field and minimum 5 years experience. - Proven experience conducting data exfiltration or cyber-enabled investigations. - Proven ability to interview subjects, witnesses, and complainants and compiling investigative summaries, findings, and recommendations. - Experience handling digital evidence and maintaining chain-of-custody. - Strong analytical and critical thinking skills with the ability to connect disparate data points into a clear narrative. - Excellent written and verbal communication skills, including investigative reporting and executive briefings. - U.S. Citizenship and ability to obtain and maintain a Secret or Top-Secret security clearance. Qualifications We Prefer: - Experience with data loss prevention tools and forensic platforms. - Knowledge of classified environment operations, including associated security measures and protection of sensitive information. - Experience in insider threat or threat management programs. - Background in corporate investigations, counterintelligence, or cyber threat intelligence. - Hands-on experience with OSINT tools and methodologies, including link analysis and dark web research. - Proven ability to work in cross-functional environments with HR, Legal, Compliance, and Cyber teams. - Knowledge of data classification, IP protection, and export-controlled data environments. What Sets This Role Apart: - Direct mission impact protecting sensitive aerospace technologies and national security programs. - Access to advanced investigative tools, datasets, and enterprise-scale systems. - Unique blend of cyber investigations, insider threat, and intelligence analysis. - High visibility role that engages others to recognize and mitigate risk. Please ensure the role type defined below is appropriate for your needs before applying to this role. This position is classified as: Remote: Employees who are working in Remote roles will work primarily offsite (from home). If you live within a reasonable commute of an RTX site with other colleagues you interact with, your manager will discuss whether there is a degree of onsite presence associated with this role. As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote. The salary range for this role is 107,500 USD - 204,500 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate’s work experience, location, education/training, and key skills. Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement. Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company’s performance. This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply. RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window. RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans’ Readjustment Assistance Act. Privacy Policy and Terms: Click on this link to read the Policy and Terms

Related Job Pages

More Threat Intelligence Specialist Jobs

Full TimeRemoteTeam 1,001-5,000

Job summary: This position performs duties remotely in a central monitoring unit and is responsible for the continuous monitoring, interpretation, communication, and documentation of video EEG tracings, cardiac rhythms and rhythm components. Population served is based on the scope of services in the department. Essential Responsibilities 1. Assists with initiating and discontinuing EKG and EEG monitoring. 2. Monitors, reviews and logs patient information including, cardiac rhythm or rhythm component changes, cardiac rhythm variances and EEG video tracings to determine baseline & variances. 3. Notifies nursing staff when leads are off or of incorrect lead placement. Assists staff with patient skin preparation and correct lead placement as necessary. 4. Notifies Registered Nurse of cardiac rhythm or rhythm component changes, and cardiac rhythm variances that indicate myocardial ischemia or acute myocardial infarction. If primary RN is not available, escalates using appropriate chain of command. 5. Notifies Registered Nurse of video EEG tracing changes. If primary RN is not available, escalates using appropriate chain of command. 6. Identifies and troubleshoots routine technical problems with the central monitoring system & initiates biomedical repairs as necessary. 7. Maintains all telemetry and EMU equipment and supplies inventory. 8. Documents patient periods off EEG or telemetry for showers, tests, and procedures. 9. Analyzes cardiac rhythm and records measurements, calculations, & interpretation of patient record in accordance with established protocols. 10. Interprets the appropriate information needed to identify each patient’s requirements relative to his or her age-specific needs. 11. Reports to RN/ MD irregularities noted on video EEG. 12. Utilizes available equipment knowledgeably and effectively; reports malfunctions and other potentially hazardous situations to charge nurse/nurse manager. 13. Prepares EEG reports as directed 14. Interprets the appropriate information needed to identify each patient’s requirements relative to his or her age-specific needs. 15. Maintain and Model Nuvance Health Values. 16. Demonstrates regular, reliable and predictable attendance. 17. Performs other duties as required. Education and Experience Requirements: · High School Diploma or equivalent · Successful completion of dysrhythmia recognition course upon hire or obtained within the employment probationary period. · Successful completion of cardiac monitoring examination and EEG competency examination. · PREFER: Cardiac monitoring experience. · PREFER: One (1) year of acute patient care experience. Minimum Knowledge, Skills and Abilities Requirements: · Maintains current knowledge of the technical operation of the central monitoring station. · Annually completes online arrythmia recognition course with 90% minimum. License, Registration, or Certification Requirements: · Current Basic Life Support (BLS) certification. Education: HS GRAD/EQUIVALENT Working Conditions: Manual: significant manual skills/motor coord & finger dexterity Occupational: Some occupational risk Physical Effort: Medium to Heavy effort. May exert up to 35 lbs. force Physical Environment: Some exposure to dirt, odors, noise, human waste, etc. Company: Vassar Brothers Medical Center Org Unit: 1608 Department: Nursing Monitor Techs Exempt: No Salary Range: $25.57 Hourly

United States
$26 / hour
Job Board logo

Senior Threat Researcher

Job Board

Corelight is the cybersecurity company that transforms network and cloud activity into evidence—evidence that elite defenders use to proactively hunt for threats, accelerate response to cyber incidents, gain complete network visibility, and create powerful analytics using machine-learning and behavioral analysis tools. We are the fastest-growing Network Detection and Response (NDR) platform in the industry. We are proud of our culture and values—driving diversity of background and thought, low-ego results, applied curiosity, and tireless service to our customers and community. Corelight is committed to a geographically dispersed yet connected employee base with employees working remotely and from office locations worldwide.

Full TimeRemoteTeam 201-500

Senior Threat Researcher Do you want to help make the world safe from cyber attack? At Corelight, we believe that the best approach to cybersecurity risk starts with the network. Attackers can evade endpoint detection, firewalls and many other technologies - but they can’t avoid leaving digital footprints on the networks they traverse. Built on open-source innovations from Zeek, Suricata and YARA and refined through years of real-world use, Corelight transforms network footprints from physical, virtual and cloud networks into actionable insights. Our customers use these insights to speed incident response and proactively hunt for threats. At Corelight, we don't just find threats; we decode the language of the network to stay steps ahead of the adversary. As a Senior Threat Researcher, you sit at the strategic intersection of our Detection Engineering and Machine Learning (ML) teams. You are the "expert bridge"—translating complex attacker behaviors into the high-fidelity data signals that power our advanced AI models. By leveraging your deep understanding of network traffic and threat actor psychology, you will guide our data scientists to solve concrete security challenges, ensuring our detections are not just innovative, but devastatingly effective against real-world attacks. Specific Responsibilities: - Architect AI-Driven Detections: Lead the independent delivery of high-quality research and code for complex network detections, authoring clear design documents that articulate technical trade-offs to stakeholders. - Bridge Detection & Data Science: Act as the network security subject matter expert for ML/AI teams, pinpointing critical signals within telemetry (Zeek, NetFlow, PCAPs) to drive feature engineering and model training. - Simulate Adversary Behavior: Utilize offensive frameworks like Caldera and Cobalt Strike to generate the synthetic lab data necessary to train and validate robust, real-world ML models. - Roadmap Alignment: Align individual research and prototyping tasks with quarterly milestones and the overarching 12-month roadmap to ensure maximum product impact. - Optimize Research Workflows: Identify gaps in current processes and actively propose improvements to team-level tools, testing frameworks, and documentation to increase overall velocity. - Mentor and Uplevel: Guide newer team members and interns through technical workflows and conduct constructive research reviews to maintain a high standard of collective output. Knowledge/Skills/Abilities needed to be successful: - Network Protocol Mastery: Deep competence in the OSI model and TCP/IP, with the ability to map emerging adversary tactics to quantitative detection strategies across protocols like HTTP/S, DNS, SMB, and TLS. - Data Science Translation: A strong understanding of the practical application of ML for behavioral data, including the ability to navigate challenges like model drift, false positives, and latency. - Network Telemetry Expertise: Proficiency in extracting and transforming network logs (Zeek, Suricata) using Python and SQL to identify subtle indicators of C2 beaconing or lateral movement. - Offensive Security Insight: Familiarity with Red Team operations and the ability to reverse-engineer attacker behaviors into programmatic detection logic. - Product-Centered Thinking: The ability to navigate ambiguity and ensure technical research projects directly support long-term product objectives and milestones. - Effective Technical Liaison: A proactive communicator who can simplify complex AI concepts for security stakeholders while providing deep domain context to data science peers. - Collaborative Mentorship: A low-ego approach to peer review and a commitment to elevating team capability through shared knowledge and constructive feedback. Qualifications/Requirements: - Professional Experience: 5+ years of experience in Threat Research, Detection Engineering, or Network Threat Hunting. - Technical Proficiency: Extensive experience analyzing network traffic with Zeek/Bro, Suricata, and Wireshark. - Scripting & Data: Strong working knowledge of Python and SQL for manipulating and analyzing massive datasets. - Security Domain Knowledge: Proficiency in mapping detections to the MITRE ATT&CK framework and simulating threats with offensive security tools. - Autonomy: Demonstrated ability to act independently on moderate-to-complex projects, exercising strong judgment in selecting technical methods. - Education: Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Data Science, or equivalent practical experience. Fueled by investments from top-tier venture capital organizations such as Crowdstrike, Accel and Insight, Corelight is the fastest growing network detection and response platform in the industry. Our customers trust us to protect mission-critical assets in leading enterprises, government, and research institutions worldwide. We are leading the way with AI-assisted workflows, machine learning models, cloud security and SaaS-based solutions to arm defenders with the tools and knowledge they need to disrupt cyber attacks. Our team of passionate innovators are dedicated to solving some of the toughest challenges in cybersecurity, while fostering a collaborative, inclusive, and growth-oriented culture. Corelight is committed to a geographically distributed yet connected employee base with employees working from home and office locations around the world. At Corelight, we take pride in the diversity of our backgrounds and perspectives, and we are committed to fostering an inclusive environment that strengthens our company. By embracing a wide range of experiences, backgrounds, neurodiversity, talents, and approaches to problem-solving, we aim to create a workplace where everyone can thrive and contribute their best. We are looking forward to meeting you. Check us out at www.corelight.com Notice of Pay Transparency: The compensation for this position may vary depending on factors such as your location, skills and experience. Depending on the nature and seniority of the role, a percentage of compensation may come in the form of a commission-based or discretionary bonus. Equity and additional benefits will also be awarded. Compensation Range $145,000—$188,000 USD

United Kingdom
$145K - $188K / year
Remote World logo

Senior Insider Threat Investigator

Remote World

Model N is the leader in revenue optimization and compliance for pharmaceutical, medtech, and high-tech innovators. For more than 25 years, we have helped customers maximize revenue, streamline operations, and maintain compliance through cloud-based software, value-added services, and data-driven insights. With a focus on innovation and customer success, Model N empowers life sciences and high-tech manufacturers to bring life-changing products to the world more efficiently and profitably. Model N is trusted by over 150 of the world’s leading companies across more than 120 countries. For more information, visit www.modeln.com.

Role Description The Senior Insider Threat Investigator develops and executes portions of the enterprise insider threat investigation and analytics program for assigned areas. The role supports complex investigations, analytics-driven risk assessments, and mitigation activities related to insider risks, including data loss, fraud, misuse of systems, and policy violations. This position requires senior-level subject matter expertise, applying advanced analytical, technical, and risk judgment skills to evaluate highly complex user behavior, support investigative decision-making, and communicate outcomes to investigative, legal, compliance, cybersecurity, and business leadership. Key Responsibilities - Develops and expands insider threat investigation knowledge and capability; communicates complex investigative methodologies, findings, and mitigation strategies to investigators, partners, and less-experienced team members. - Performs portions of high-complexity insider threat investigations by analyzing user activity, access patterns, logs, behavioral data, and investigative artifacts to develop timelines, risk assessments, root-cause analyses, and evidentiary documentation. - Coordinates required investigative actions and communications in alignment with insider threat response plans and guidance from leadership to mitigate risk, protect sensitive information, and ensure timely, defensible outcomes. - Supports research and analysis of potential and known insider threat risks, trends, and control gaps across assigned areas; evaluates effectiveness of investigative and monitoring controls and documents results. - Develops and enhances portions of investigative playbooks, workflows, and response procedures; monitors indicators of insider risk and supports detection, escalation, and containment activities. - Partners with Cybersecurity, IT, Legal, Compliance, HR, Privacy, and Analytics teams to ensure investigative activities are compliant with regulatory, legal, privacy, and internal control requirements. - Translates investigative findings and operational needs into recommendations for process, service, and technical improvements to strengthen the insider threat program and overall risk posture. Qualifications - 3+ years of experience in insider threat programs, cybersecurity investigations, digital forensics, or risk analytics. - Advanced knowledge of insider threat investigation methodologies, behavioral monitoring, and forensic analysis techniques. - Experience with DFIR, SIEM, and investigative analytics platforms. - Strong understanding of regulatory and control frameworks (e.g., NIST, ISO 27001, GDPR). - Strong written and verbal communication skills, including executive-level reporting. Requirements - Cyber Investigations - Data-Driven Decision Making - Digital Forensics - Executive Level Reporting - General Data Protection Regulation (GDPR) - Insider Threat Mitigation - IT Security Operations - NIST Cybersecurity Framework (CSF) - Penetration Testing - Risk Analytics - Root-Cause Analysis - Security Information and Event Management (SIEM) - Security Tools - Threat Assessment Benefits - Compensation offered for this role is $80,000 - 140,000 annually and is based on experience and qualifications. - The candidate(s) offered this position will be required to submit to a background investigation.

Austria
$80K - $140K / year
Job Closed
Full TimeRemoteTeam 1,001-5,000Since 1985H1B Sponsor

About Us Sophos is a global leader and innovator of advanced security solutions for defeating cyberattacks. The company acquired Secureworks in February 2025, bringing together two pioneers that have redefined the cybersecurity industry with their innovative, native AI-optimized services, technologies and products. Sophos is now the largest pure-play Managed Detection and Response (MDR) provider, supporting more than 28,000 organizations. In addition to MDR and other services, Sophos’ complete portfolio includes industry-leading endpoint, network, email, and cloud security that interoperate and adapt to defend through the Sophos Central platform. Secureworks provides the innovative, market-leading Taegis XDR/MDR, identity threat detection and response (ITDR), next-gen SIEM capabilities, managed risk, and a comprehensive set of advisory services. Sophos sells all these solutions through reseller partners, Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) worldwide, defending more than 600,000 organizations worldwide from phishing, ransomware, data theft, other every day and state-sponsored cybercrimes. The solutions are powered by historical and real-time threat intelligence from Sophos X-Ops and the newly added Counter Threat Unit (CTU). Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com. Role Summary Malware Researcher? Red/Blue/Purple team member? We have a fantastic opportunity here at Sophos Labs for a Threat Researcher role to join our global team of Behavioral Protection engineers, to hunt, to research, and to add real-time protection for suspicious activity across our customer environments. Our team of skilled security experts combine their passion to detect & disrupt cyber-attacks with their capability to develop protection rules that can cut through the noise in modern computing environments to tease out attacker’s nefarious activities. You are intrinsically motivated to understand the core logic behind malware and hacking attacks, to find & predict new ways attackers will modify their techniques and take great satisfaction in developing robust protection logic that is immune to evasive actions. You will be responsible for writing behavioral protection rules that are able to block malicious activities across all types of TTP (even if a Mitre Technique doesn’t exist yet). This is the foundation of Sophos next-gen approach. Above all - you enjoy thinking creatively; combining your deep technical knowledge, your tenacity for innovation, and your can-do attitude to solve complex and challenging problems on daily basis. Additionally, you will also be supporting our remediation effort to remove artifacts left behind, by writing cleanup rules, and supporting our Sandbox development, such as (but not limited to) creating signatures, identifying evasion techniques that prevent the sandbox from running the threat smoothly. What You Will Do - Conduct in-depth behavioral analysis of Windows threats. - Develop Behavioral rules for various threat behaviors including hands-on keyboard attack, malware payloads, initial attack vectors and Advanced Persistent Threats (APTs). - Produce quality threat analysis reports for both internal and external audience. - Assist in sandbox improvements by analyzing malware that hinders the sandbox environment in running the threat, which deploys various anti-analysis techniques. - Develop Cleanup rules to remove artifacts that are left behind by the behavioral protection rules. - Collaborate with other cross-functional teams to improve behavioral protection capability based on the threat analysis. - Guide and train junior team members in assisting malware analysis, peer code review. - Assist in the development of tools wherever necessary to improve day-to-day task. What You Will Bring - Strong knowledge of Windows Internals including Memory management, Processes, Threads. - Proficiency in both static and dynamic analysis of threats, using tools such as IDAPro, WinDbg. - Demonstrated programming experience. Preferred: Python, Lua. - Excellent communication skills with the ability to demonstrate complex technical problem to peer researchers as well as to product engineering team. - Excellent analytical and problem-solving skills with the ability to think strategically and creatively. - Bachelor’s degree in computer software (Computer Security preferable) or equivalent experience. Ready to Join Us? At Sophos, we believe in the power of diverse perspectives to fuel innovation. Research shows that candidates sometimes hesitate to apply if they don't check every box in a job description. We challenge that notion. Your unique experiences and skills might be exactly what we need to enhance our team. Don't let a checklist hold you back – we encourage you to apply. What's Great About Sophos? · Sophos operates a remote-first working model, making remote work the primary option for most employees. However, some roles may necessitate a hybrid approach. While we are a remote first organization, applicants must have legal authorization to work in the jurisdiction where the position is posted, without requiring employer sponsorship. · Our people – we innovate and create, all of which are accompanied by a great sense of fun and team spirit · Employee-led diversity and inclusion networks that build community and provide education and advocacy · Annual charity and fundraising initiatives and volunteer days for employees to support local communities · Global employee sustainability initiatives to reduce our environmental footprint · Global fitness and trivia competitions to keep our bodies and minds sharp · Global wellbeing days for employees to relax and recharge · Monthly wellbeing webinars and training to support employee health and wellbeing Our Commitment To You We’re proud of the diverse and inclusive environment we have at Sophos, and we’re committed to ensuring equality of opportunity. We believe that diversity, combined with excellence, builds a better Sophos, so we encourage applicants who can contribute to the diversity of our team. All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation. We want to give you every opportunity to show us your best self, so if there are any adjustments we could make to the recruitment and selection process to support you, please let us know. Data Protection If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos. If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights. For more information on Sophos’ data protection practices, please consult our Privacy Policy Cybersecurity as a Service Delivered | Sophos

Oman + 1 moreAll locations: Oman | Romania