Manager, Threat Intelligence (Remote)
Straight from PDI Technologies’s careers page. Apply on the company site — no recruiter, no middleman.
Manager, Threat Intelligence
Team: Customer Support
Location: Remote US
Commitment: Full-time
Workplace Type: remote
Every day, millions of people buy fuel, coffee, and lunch at the businesses PDI protects. Convenience stores, fuel stations, quick-service restaurants, and automotive businesses run on payment systems, point-of-sale networks, and connected site equipment, and financially motivated attackers know it.
Were looking for an experienced leader to own threat intelligence, threat hunting, and detection engineering for our SOC. Youll build the clearest picture anywhere of who targets these industries and how, then turn it into detections, hunts, and guidance that protects 12,000+ customers.
This isnt an internal intel team serving one company. Your teams work ships to every customer we protect, and youll have real room to build the program the way you think it should run.
Why this role stands out
- A threat landscape you can own. Payment card theft, POS malware, ransomware against franchise networks, and attacks on connected forecourt and in-store systems. Few teams anywhere specialize here.
- A straight line from intel to impact. Your team writes the intelligence and the detections. Youll see your work stop real attacks across many customer environments.
- Room to build. Shape the methodology, tooling, and AI-assisted workflows rather than inheriting someone elses playbook.
- Visibility. Brief customer executives, partner with SOC, product, and company leaders, and represent PDI in industry and intelligence-sharing communities.
What youll own
- Hire, coach, and develop a remote team of analysts, hunters, and detection engineers, with clear priorities and career paths.
- With a team of four, youll split your time between leading and doing: hunting, writing intelligence, and building detections alongside the team.
- Partner with SOC, Incident Response, and Security Engineering leaders to improve detection, response, and customer outcomes.
- Define intelligence requirements with SOC leadership and customers and run the full intelligence lifecycle from collection through feedback.
- Deliver strategic, operational, and tactical products: actor profiles, campaign analysis, industry threat briefs, and customer-specific reports.
- Track the actors that matter most to our customers, including financially motivated groups, payment fraud operations, and ransomware crews targeting retail and hospitality.
- Own detection content strategy across SIEM and EDR/XDR, including development, testing, tuning, and coverage measured against MITRE ATT&CK.
- Run hypothesis-driven threat hunts across customer environments and feed what you find back into new detections.
- Use automation and AI to scale enrichment, triage support, and reporting so the team can focus on analysis, not busywork.
- Provide intelligence context during major incidents and lead during complex escalations.
- Serve as a trusted advisor to customers through briefings, reports, and presentations for both technical and executive audiences.
- Run the team on clear metrics such as detection coverage, hunt findings, reporting timeliness, and customer satisfaction, and contribute to service planning and new offerings.
Lead and grow the team
Build the intelligence program
Turn intelligence into detection
Step in when it matters
Be the voice of the team
What success looks like
- First 90 days: Assess the team, tooling, and current detection coverage. Agree on intelligence requirements with SOC leadership and key customers.
- By 6 months: A regular cadence of industry threat reporting, plus an ATT&CK coverage baseline and roadmap.
- By 12 months: Measurable gains in detection coverage and hunt-driven findings, and a team customers see as the go-to source on threats to their industry.
What you bring
- 8+ years in cybersecurity across threat intelligence, threat hunting, incident response, detection engineering, or security operations.
- 3+ years managing technical security teams, including hiring and developing people.
- Deep knowledge of adversary tactics and the frameworks used to analyze them, such as MITRE ATT&CK, the intelligence lifecycle, and the Diamond Model.
- A track record of producing finished intelligence for both technical and executive audiences.
- Hands-on experience with SIEM (FortiSIEM, Microsoft Sentinel, Splunk, Google Chronicle, or ArcSight) and EDR/XDR platforms and their query languages (KQL, SPL, or similar). Our environment includes FortiSIEM; equivalent experience is welcome.
- Experience supporting complex investigations and incident response.
- Excellent written, verbal, and presentation communication skills.
- Clear writing and speaking skills, with the ability to translate technical findings into business risk.
- Experience at an MSSP or MDR provider serving many customers.
- Background in retail, hospitality, or payments environments, including POS systems or PCI DSS.
- Detection-as-code, Sigma, SOAR, or scripting (e.g., Python).
- Experience with threat intelligence platforms and feeds, such as MISP or Recorded Future.
- Cloud and SaaS investigations across Azure, AWS, or Microsoft 365.
- Active involvement in intelligence-sharing communities such as RH-ISAC.
- Certifications such as GCTI, GCFA, GCIH, GREM, or CISSP are welcome but not required.
Required
Nice to have
A bachelors degree in a related field or equivalent experience. If youre close on the requirements and excited about the work, wed still like to hear from you.
Similar remote jobs
More like this →

Immersive Labs
Cloud Security Engineer (Remote)


Discover More than 100,000 Hidden Remote Jobs Before Everyone Else
Unlock All Remote Jobs Today
Simple pricing. Big savings on Quarterly and Yearly.
Monthly Access
- Instant access to fresh remote jobs from 500+ companies
- New opportunities added hourly, often 3-7 days before anywhere else
- Advanced filtering by role type, stack, pay, and location
- Priority customer support
Yearly Access
- Everything in Monthly
- Save $169 (~74%) vs paying monthly
- Average job search takes ~6 months - get covered for the whole journey
- Less than the cost of one lunch per month for competitive advantage
- Equivalent to just ~$4.92/month