Senior Threat Intelligence and Vulnerability Engineer
Job Description
[Up to c. $225k Base Salary + Discretionary Bonus | *Remote Working - Tri-State Area Preferred]
Role Overview
We’re representing a global electronic-trading business whose technology supports high-volume, business-critical financial markets across multiple asset classes. The firm is continuing to invest in its cyber security capabilities as its trading platforms, infrastructure estate and international client base expand. This senior role will lead the connection between cyber threat intelligence, vulnerability management and practical security engineering. You will identify emerging threats, assess their relevance to the organisation, prioritise technical exposure and work directly with Security Operations, infrastructure, application and business-technology teams to drive measurable remediation...
Key Responsibilities
- Lead the end-to-end cyber threat intelligence lifecycle, including intelligence collection, validation, enrichment, correlation, analysis and targeted dissemination across security and technology teams
- Monitor global threat activity, adversary behaviour, emerging attack techniques and industry-specific campaigns, translating external intelligence into clear implications for the organisation
- Own the operational response to vendor advisories, critical CVEs, zero-day disclosures and emerging vulnerabilities, assessing relevance, exploitability and potential business impact
- Develop and mature the enterprise vulnerability-management programme, including standards, procedures, remediation SLAs, exception processes, escalation paths and governance
- Partner with infrastructure, application, cloud and system owners to prioritise vulnerabilities according to exploitability, asset criticality, exposure and wider business context
- Administer and optimise threat-intelligence platforms, commercial and open-source feeds, SIEM integrations, SOAR workflows and associated enrichment and distribution capabilities
- Build automation using Python, PowerShell, APIs, orchestration and appropriate AI capabilities to improve intelligence ingestion, vulnerability tracking, reporting and remediation coordination
- Produce clear operational and executive reporting covering threat trends, vulnerability exposure, remediation performance, recurring control weaknesses and material security risks
What You’ll Bring...
- Approximately 9-15 years of experience across cyber security engineering, security operations or threat management, including substantial hands-on ownership of threat intelligence and vulnerability-management programmes
- Strong practical knowledge of the threat-intelligence lifecycle, with evidence of converting threat actors, TTPs, IOCs and emerging attack vectors into relevant operational action
- Hands-on experience managing threat-intelligence platforms, external intelligence feeds, OSINT sources and integrations with SIEM, SOAR and security-monitoring technologies
- Proven delivery of enterprise vulnerability-management programmes covering scanning, vendor advisories, CVE analysis, zero-day response, risk-based prioritisation and remediation governance
- Strong understanding of MITRE ATT&CK, common infrastructure and application vulnerabilities, OWASP risks and the ways individual weaknesses can combine into wider attack paths
- Practical scripting and integration capability using Python, PowerShell or comparable technologies to automate security workflows and reduce manual operational effort
- Credibility communicating complex security exposure to both technical teams and senior stakeholders, including experience building meaningful risk metrics and executive reporting
- (Preferred) Financial-services, capital-markets, trading-technology or another highly regulated and availability-sensitive environment, alongside CISSP, CISM, GIAC or equivalent professional certification
...
Apply for this role
All fields marked with * are required.