Director of Cyber Threat Intelligence

SoFi SoFi · Fintech · San Francisco, CA · Information Security

Director of Cyber Threat Intelligence at SoFi, leading the development and execution of a financial institution's cyber threat intelligence program. This role involves managing teams, deploying and maintaining a threat intelligence platform, ingesting and aggregating threat data, monitoring the threat landscape, and integrating AI/ML capabilities into cybersecurity workflows.

What you'd actually do

  1. Develop the CTI Program
  2. Team Management
  3. Strategic Direction
  4. Threat Intelligence Platform: Deploy and maintain a threat intelligence platform responsible for the intake, structuring, and distribution of threat intelligence to relevant teams.
  5. Data Ingestion & Aggregation: Manage the engineering processes for ingesting threat intelligence data from commercial, open-source, and internal resources.

Skills

Required

  • 7+ years of experience in cybersecurity, threat intelligence, operations, or risk management.
  • Bachelor’s or advanced degree in Cybersecurity, Computer Science, or a related field.
  • Demonstrated ability to lead teams effectively within a dynamic operational setting.
  • Proven experience in deploying and maintaining Threat Intelligence Platforms (TIP) and open-source intelligence (OSINT) tools.
  • In-depth knowledge of cyber threats, attack methodologies (such as the MITRE ATT&CK framework or the cyber kill chain), and vulnerabilities relevant to financial networks.
  • Familiarity with Security Information and Event Management (SIEM), SOAR tools, dissemination of intelligence through automation to security controls.
  • Exceptional written and verbal communication and presentation skills, capable of negotiating and influencing stakeholders at a senior level.
  • Strong critical reasoning, problem-solving, and project management abilities.
  • Ability to remain calm under pressure, handle multiple conflicting tasks, and maintain strict confidentiality regarding sensitive intelligence.

Nice to have

  • Experience integrating artificial intelligence or machine learning capabilities into cybersecurity or threat intelligence workflows, such as automation of threat analysis, detection enrichment, or large-scale data analysis.

What the JD emphasized

  • Candidates must demonstrate a proven track record in engineering robust and scalable cybersecurity or threat intelligence solutions.
  • Experience integrating artificial intelligence or machine learning capabilities into cybersecurity or threat intelligence workflows

Other signals

  • Develop the CTI Program
  • Deploy and maintain a threat intelligence platform
  • Data Ingestion & Aggregation
  • Experience integrating artificial intelligence or machine learning capabilities into cybersecurity or threat intelligence workflows