Cyber Threat Intelligence and Lead
Listed on 2026-03-01
-
IT/Tech
Cybersecurity, IT Consultant, Information Security
How you'll help us Keep Climbing (overview & key responsibilities)
At Delta Air Lines,connection is at the heart of everything we do and guides our every action. Westrive to welcome and care for all of our customers during their travels withus and aim to deliver an elevated experience.
Delta is focused on sustaining a strong IT operation, growing our capabilities, and maximizing optimization across each of our tech hubs to elevate the travel experience forour customers and empower our 90,000 Delta people.
We’re committed to fostering innovation, and we’re excited to invite you to be part of our journeyas we shape the future of technology at the world’s best airline!
Delta Air Lines is looking for a talented experienced Cyber Threat Intelligence & Hunting Lead to be a part of Delta’s Information Security team committed to safeguarding information and information systems from unauthorized access, use, disclosure, disruption, modification or destruction.
As Cyber Threat Intelligence & Hunting Lead, you will use your technical experience to profile and build defenses against existing and emerging threats to Delta's IT landscape. You will also apply your technical knowledge to solving complex intelligence problems, produce short-term and long-term written assessments, and brief Delta's leadership. Cyber Threat Intelligence & Hunting Lead is a SOC fusion role that combines threat intelligence and threat hunting operations reporting to the Manager of Cyber Threat Intelligence (CTI) but also closely aligned with the Cybersecurity Monitoring & Incident Response (CMIR) team in both strategic and day-to-day operations.
YOURRESPONSIBILITIES IN THIS ROLE
Identify emerging and persistent threats to the organization's networks, systems, and applications.
Lead coordinated efforts across SOC teams to ensure the effective delivery and tracking of intelligence driven responses to threats.
Operate and mature process related to the threat hunting program across SOC teams and related security vendors/services.
Develop a threat assessment/modeling framework documenting threats to aid in driving resiliency initiatives that require broader non-SOC business partner buy-in.
Develop rules & policies across the technology and security stack that deliver protective and detective controls.
Mentor and develop Cyber Threat Intelligence and Incident Response analysts on hunt methodology, adversary TTP analysis, and detection tuning.
Security Engineering related to cyber threat intelligence services portals and Threat Intelligence Platform (TIP).
At least 10 years of experience in the IT space with at least 5 years of experience in Cybersecurity roles/duties focused on threat intelligence, monitoring, and incident response.
Experience developing and managing detection rules in SIEMs
Experience with EDR, NDR and CDR solutions with a focus on policy/rule management
Experience in threat research, vulnerability research, malware analysis and exploit investigation.
Understanding of MITRE ATT&CK, Cyber Kill Chain, Pyramid of Pain, Threat Hunting Frameworks
Solid understanding of networking (WAN, LAN, wLAN), network domains (Internet, intranet, DMZ), communication techniques/protocols (IP and others), and their combined effects on network and host systems security.
Understanding of Linux/Unix platforms.
Comfortable handling multiple deliverables and able to manage priorities in a time-sensitive environment.
Strong written and verbal technical and non-technical communication skills. Assures smooth flowing, timely transmission of critical information. Oral and written communication is well organized, clear, accurate, grammatically correct, and is adapted for the target audience, including C-Suite.
Collaborative, embraces diverse people, thinking and styles.
Consistently makes safety and security, or self and others, the priority.
High School Diploma, GED or High School Equivalency.
Security Engineering of Threat Intelligence Platform (TIP)
Preferred key industry certifications such as CEH, Security+, CISSP, CISA, CISM, GCIH, etc.
Bachelor's Degree in…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).