Role OverviewThe Principal, Threat Operations Program Lead serves as a senior operational leader and key partner within the Cyber Operations team, acting as the functional second-in-command across threat operations activities. This role is responsible for building, scaling, and sustaining a comprehensive threat operations program that translates threat and exposure signals into actionable insights and business risk decisions.
What You Will Do
The Technical Specialist, Threat Operations is expected to maximize AI-assisted and agentic AI workflows while maintaining human accountability, secure data handling, and audit-ready evidence. All outputs must remain defensible, traceable, and aligned with enterprise governance standards.
Why It Might Be a Fit
The role requires leadership through influence, driving consistent execution, talent development, and high-quality outcomes across analysts, partners, and stakeholders. The ideal candidate will have 10 years of direct experience in cybersecurity operations, incident response, or threat analysis, and experience investigating cloud security issues (AWS and/or OCI).
Requirements
- Bachelors degree in Cybersecurity, Computer Science, IT, or any related field.
- Current, active certification in one or more of the following: CISSP, CISM, GIAC, CySA+, Microsoft Security, or cloud security certifications.
- 10 years of direct experience in cybersecurity operations, incident response, or threat analysis.
- Experience investigating cloud security issues (AWS and/or OCI).
- Hands-on experience with AI-assisted security workflows and governance-aligned practices.
- Experience developing threat intelligence or CTEM-aligned programs.
- Experience managing external security partners and service delivery (e.g., MDR/MSSP), including performance outcomes, SLAs, and continuous improvement.
- Strong knowledge of threat operations, incident response, and investigation methodologies.
- Advanced understanding of MITRE ATT&CK framework and detection coverage strategies.
- Knowledge of cloud security threats (AWS, OCI), particularly identity and control plane risks.
- Understanding of threat intelligence lifecycle and CTEM program implementation.
- Knowledge of enterprise AI governance, including generative AI risks and controls.
- Ability to build and scale threat operations processes and programs.
- Ability to develop metrics and reporting frameworks that drive decision-making.
- Experience designing AI-assisted investigation and triage workflows.
- Ability to translate technical risk into business-aligned remediation strategies.
- Strong decision-making skills under uncertainty, supported by defensible evidence.
- Excellent communication skills with both technical and executive audiences.
- High degree of judgment, integrity, and accountability.
- Ability to collaborate cross-functionally and influence without direct authority.
- Demonstrated leadership through influence across matrixed teams, partners, and stakeholders, including prioritization, coaching, performance feedback, and operational execution.
- Exceptional ability to translate and communicate technical risk, threat assessments, and mitigation strategies to technical, executive, and board-level audiences.
Benefits
- Comprehensive medical, dental, and vision insurance
- Life and disability insurance benefits
- Health care, dependent care, and limited purpose flexible spending accounts
- Health savings account with annual employer contributions
- Voluntary supplemental health plans for Accident and Hospital Indemnity coverage
- Infertility coverage
- 401k matching contribution program
- Paid leave program consisting of vacation, sick, and personal time
- Paid holidays
- Up to 3 weeks of paid parental leave during a 12-month period
- Up to 5 days of paid military leave per calendar year
- Employee Education Assistance Program
- LinkedIn Learning subscription
- Mental health with up to eight free therapy sessions
- Well-being reward benefits
- Service credit towards the Public Service Loan Forgiveness program (PSLF)
]]>