Associate Director, Threat Intelligence
AreteAbout the role
SUMMARY
The Associate Director, Threat Intelligence (CTI) is a self-driven cybersecurity leader responsible for managing a team of analysts and delivering high-quality, actionable intelligence to reduce risk and strengthen the security posture of clients. As a Subject Matter Expert (SME), this role collaborates with stakeholders to identify intelligence needs, analyze complex cyber threats, and guide the development of intelligence-driven strategies for threat detection, prevention, and response. The position demands strong analytical capabilities, deep technical expertise in CTI, DFIR, and the Dark Web, and the ability to clearly communicate insights to diverse audiences, including senior executives.
In addition to overseeing day-to-day team operations, the Associate Director mentors team members, ensures the consistent quality of intelligence products, and fosters a collaborative, high-performance environment. During client engagements, they work closely with internal experts and client stakeholders to deliver strategic guidance, reporting, and consultation. This role also involves building trusted relationships with clients and their legal counsel, maintaining situational awareness through data analysis, and providing leadership support during high-priority or after-hours incidents.
ROLES & RESPONSIBILITIES
- Manages Arete’s global team of cyber intelligence analysts, ensuring they meet or exceed SLA targets, adhere to KPIs, and deliver high-quality intelligence products
- Oversees quality of attribution and is responsible for pivoting training program
- Oversees production of annual and quarterly Crimeware reports, ad hoc blogs, and client-specific deliverables demonstrating Arete’s intelligence capabilities and expertise
- Contributes to the enhancement of existing CTI products, services, and processes, and/or creation of new ones to generate additional revenue
- Oversees a multi-team process gathering extensive information on cybercrime actors and actively correlating that information to drive response actions
- Works with stakeholders to determine cyber threat intelligence needs and requirements and identify the most effective methods for fulfilling them
- Conducts extensive research into current threat activity; analyzing the origins, pathways, and methodologies of malicious cyber activities to attribute, model and predict future intrusions and threats
- Evaluates current and emerging tools and best practices for tracking cyber-crime and advanced persistent threats to improve automation, data analysis, intelligence sharing and service offerings
- Produces materials, written products, and graphics related to tactical, operational, and strategic intelligence about threat groups, the methodologies they use, and the motivations behind their activity and briefs them to technical and non-technical audiences
- Supports the countermeasures development team highlighting indicators of threat activity for the creation of detection mechanisms and identifying gaps in the threat detection technology
- Engages with external entities, such as industry sharing groups, government agencies, and intelligence communities, to exchange information and collaborate on threat intelligence initiatives
- Acts as main point of contact for CTI-related matters, capturing client expectations, ensuring alignment throughout engagements, and delivering final reports that meet objectives of client and counsel
- Provides coaching and guidance to junior analysts and other team members; sets clear expectations, appraises performance, and supports career development and growth
- Fosters a collaborative and inclusive culture where top talent thrives; promotes accountability, professional growth, and shared success across teams
- Oversees recruitment, hiring, onboarding and retention of high-caliber employees
- Monitors team performance, offers guidance and feedback as needed to ensure long-term success of the CTI team
- Performs other duties as assigned by management
SKILLS AND KNOWLEDGE
- Holds comprehensive knowledge in CTI, Dark Web, and is familiar with malware reverse engineering or countermeasure development
- Strong background and practical hands-on experience with Cyber Threat Intelligence concepts, including expert-level knowledge of attribution and pivoting for investigations
- Ability to work effectively and independently in a fast-paced, dynamic environment and prioritize tasks to meet deadlines
- Knowledge of intrusion analysis models and frameworks like the Cyber Kill Chain, Diamond Model, and MITRE ATT&CK, and structured analytic techniques like Analysis of Competing Hypotheses (ACH)
- Knowledge of different cybercrime and state-sponsored threat actor groups,
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s