Padmi
Kroll logo
Kroll

valuation services · private equity advisory

Director, Threat Intelligence

United States$200k–$230k/yrPosted 8 days ago
SecurityStaff+H-1B track record
Apply at Kroll

Opens the source posting on hcxs.fa.us2.oraclecloud.com

Source description

About the role

View original

Skip to main content.

View More Jobs

Director, Threat Intelligence

United States

Job Description

Kroll CTI is seeking a highly motivated and client-focused Director, Embedded Threat Intelligence – Incident Resppnse & Ransomware Servies to support our Incident Response and Cyber Risk advisory practice. This role sits at the intersection of threat intelligence, ransomware analysis, and frontline incident response support, delivering actionable intelligence to clients facing sophisticated cyber threats.

As a trusted advisor, you will support global clients during high-impact ransomware incidents, providing deep intelligence on adversaries, guiding investigative efforts, and delivering strategic and tactical insights that enable informed decision-making under pressure.

Key Responsibilities

Client-Facing Incident Response Support

  • Embed with Incident Response teams to provide real-time intelligence support during active ransomware incidents

  • Translate technical findings into clear, actionable recommendations for client stakeholders, including executives, legal counsel, and IT/security teams

  • Assist with attribution analysis, threat actor profiling, and understanding adversary intent

  • Contribute to client briefings, situation updates, and post-incident reporting

Ransomware Threat Intelligence & Adversary Analysis

  • Track and analyze ransomware groups, affiliates, and broader cybercriminal ecosystems

  • Develop detailed intelligence on adversary TTPs, tooling, infrastructure, and operational playbooks

  • Map attacker behavior to frameworks such as MITRE ATT&CK to support detection and response

  • Identify and assess emerging ransomware trends, targeting patterns, and sector-specific risks

Malware Analysis & Technical Investigation

  • Conduct static and dynamic malware analysis on ransomware payloads, loaders, and supporting tools

  • Reverse engineer malware to understand encryption techniques, persistence mechanisms, and command-and-control activity

  • Extract and validate IOCs and behavioral indicators to enhance detection and response efforts

  • Collaborate with digital forensics and IR teams to link malware findings to broader intrusion activity

Covert Collection & Intelligence Development

  • Conduct covert intelligence collection across restricted-access environments, including dark web forums, leak sites, and negotiation portals

  • Monitor ransomware group communications, victim disclosures, and affiliate activity

  • Provide insight into attacker motivations, timelines, and negotiation dynamics

Tactical & Strategic Reporting

  • Produce high-quality, client-ready deliverables under tight timelines, including:

  • Incident-specific intelligence summaries

  • Ransomware group profiles and threat assessments

  • Tactical reports detailing TTPs, IOCs, and defensive recommendations

  • Tailor reporting for both technical and non-technical audiences, ensuring clarity and impact

  • Support development of thought leadership and threat landscape reporting

Required Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Intelligence Studies, or related field (or equivalent experience)

  • 3–7+ years of experience in cyber threat intelligence, incident response, or cyber consulting

  • Strong understanding of ransomware attack lifecycles, including initial access, lateral movement, exfiltration, and extortion

  • Hands-on experience with malware analysis and reverse engineering tools (e.g., Ghidra, IDA Pro, Wireshark, sandbox environments)

  • Experience producing actionable intelligence on TTPs and IOCs

  • Proven ability to operate in high-pressure, client-facing environments

Preferred Qualifications

  • Familiarity with enterprise incident response engagements and crisis management

  • Experience with threat actor negotiation dynamics or ransomware leak site monitoring

  • Proficiency in scripting (Python, PowerShell) to support analysis and automation

  • Relevant certifications (e.g., GCTI, GCFA, GREM, CISSP)

Core Competencies

  • Strong client communication and stakeholder management skills

  • Ability to distill complex threat intelligence into clear, decision-ready insights

  • Analytical rigor and attention to detail in fast-moving environments

  • Sound judgment in handling sensitive and high-stakes incidents

  • Team-oriented mindset with ability to collaborate across technical and non-technical teams

What Success Looks Like

  • Delivering high-confidence, actionable intelligence that directly informs client response decisions

  • Enhancing the effectiveness and speed of ransomware incident containment and remediation

  • Building trusted relationships with clients during critical, high-pressure engagements

  • Contributing to the firm’s reputation as a leader in cyber incident response and threat intelligence advisory services

Your recruiter will be happy to walk you through your U.S.-specific benefits, which include:

  • Healthcare Coverage: Comprehensive medical, dental, and vision plans.

  • Time Off and Leave Policies: Generous paid time off (PTO), paid company holidays, generous parental and family leave.

  • Protective Insurances: Life insurance, short- and long-term disability coverage, and accident protection.

  • Compensation and Rewards: Competitive salary structures, performance-based incentives, and merit-based compensation reviews.

  • Retirement Plans: 401(k) plans with company matching.

Please note that benefits may vary by region, department and role. We encourage you to speak with your recruiter to learn more about the specific benefits available for your position.

About Kroll

Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll.

In order to be considered for a position, you must formally apply via careers.kroll.com.

We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability.

The current salary range for this position is $200,000 to $230,000

#DNI

Apply Now

Job Info

  • Job Identification21014456
  • Job CategoryCyber Security
  • Posting Date07/13/2026, 03:45 PM
  • Job ScheduleFull time
  • LocationsUnited States

Similar Jobs

American English

  • العربية
  • Deutsch
  • American English
  • Español
  • Français
  • Français canadien
  • Italiano
  • 日本語
  • Nederlands
  • Português do Brasil
  • 简体中文
  • 繁體中文

I am an employee

Are You Still With Us?

It seems you've been gone for a while. For security reasons we will end your session automatically in 03:00 unless you would like to continue working.

End SessionContinue Working

Work Summary

This summary is generated by AI Assist. Click inside the summary text box to make changes as necessary.

DiscardAdd Summary

Page Director, Threat Intelligence - Kroll Careers loaded

More at Kroll

Related open roles

View all roles