Senior Cyber Threat Intelligence Engineer (hyrbid)

GEICO GEICO · Insurance · Bethesda, MD +3

Senior Cyber Threat Intelligence Engineer responsible for advancing intelligence-driven threat detection and proactive threat hunting across GEICO’s environment. Requires hands-on experience, strong analytic judgment, and ability to independently execute complex work. Develops actionable insights, drives outcomes, and influences detection strategies. Also involves technical leadership, mentoring junior analysts, and producing written intelligence products.

What you'd actually do

  1. Analyze and assess advanced cyber threats, adversary behavior, tooling, and campaigns relevant to GEICO
  2. Develop and execute intelligence-informed threat-hunting hypotheses using endpoint, network, and cloud telemetry
  3. Build, maintain, and enhance custom tools, scripts, and automation to support intelligence analysis and hunting workflows
  4. Use programming and scripting languages (e.g., Python, PowerShell, Bash, or similar) to analyze data, enrich intelligence, and automate manual processes
  5. Translate threat intelligence into actionable detection logic, investigative guidance, and response context

Skills

Required

  • 7+ years of experience in cyber threat intelligence, threat hunting, security operations, or a related cybersecurity discipline
  • Demonstrated hands-on experience conducting threat hunting in enterprise environments
  • Strong coding or scripting experience with the ability to design and maintain custom tools
  • Proven experience applying adversary frameworks such as MITRE ATT&CK to real-world detection and analysis
  • Experience producing written intelligence products that inform technical teams and leadership
  • Deep understanding of attacker techniques, intrusion workflows, malware, and phishing operations
  • Experience working with SIEM, EDR, and threat intelligence platforms
  • Ability to work independently, manage competing priorities, and deliver results under time constraints

Nice to have

  • Experience supporting incident response or digital forensics activities
  • Familiarity with cloud platforms and cloud-based threat activity
  • Experience building internal CTI tooling, pipelines, or automation
  • Experience working in large enterprise or regulated environments

What the JD emphasized

  • deeply technical individual contributor
  • independently execute complex work
  • high degree of autonomy
  • independently own work from initial problem identification through execution and delivery
  • define intelligence and hunting objectives
  • expert-level technical judgment
  • set a high bar for analytic quality