Jobs and Careers
RT

Threat Intelligence Lead (Remote)

RTX
US-CA-REMOTE, United States, United StatesRemotefull_timeVerifiedPosted 10 Apr 2026
💰 $204,500/yr($107,500/yr$204,500/yr)

About the role

Date Posted:

2026-04-10

Country:

United States of America

Location:

US-CA-REMOTE

Position Role Type:

Remote

U.S. Citizen, U.S. Person, or Immigration Status Requirements:

The ability to obtain and maintain a U.S. government issued security clearance is required.​ U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance

Security Clearance Type:

DoD Clearance: Top Secret

Security Clearance Status:

Active and existing security clearance required after day 1

At RTX, the world largest aerospace and defense company, 185,000 great minds are united by purpose and inspired to make a difference solving the world’s most complex problems. With our three market leading businesses, world-class operations and investments in research and development, we offer capabilities and opportunity no one else can. Together, we push the boundaries of known science and find new ways to connect and protect our world. 

Pratt & Whitney is a world leader in the design, manufacture and service of aircraft engines and auxiliary power systems and has been revolutionizing modern flight for over 100 years. Join us and help shape the future of aerospace and defense.

The Pratt & Whitney Global Security Services (GSS) Threat Intelligence Lead is a cyber investigative and analytics role responsible for leading data exfiltration investigations and advancing insider threat detection capabilities within the Threat Management and Intelligence program. Operating at the intersection of cybersecurity, digital forensics, and intelligence analysis, this role focuses on identifying, investigating, and mitigating risks related to the unauthorized movement of sensitive data—including intellectual property and controlled technical information—across endpoints, cloud platforms, email systems, and removable media. The ideal candidate combines investigative experience with strong technical expertise, leveraging enterprise security tools such as Splunk and DLP platforms to detect anomalous behavior and support complex investigations. This role also incorporates open-source intelligence (OSINT) to enrich investigations and strengthen risk identification. In addition to supporting investigations, the Intelligence Lead applies behavioral analytics and trend analysis to proactively identify insider threat indicators and deliver clear, actionable intelligence. 

What You Will Do:

  • Lead complex investigations involving data exfiltration, insider threat activity, and misuse of enterprise systems.  
  • Validate and triage alerts from DLP, SIEM, and UEBA; reconstruct user activity and data movement to establish intent, scope, and impact . 
  • Collect, preserve, and analyze digital evidence in support of investigations, ensuring chain-of-custody and legal defensibility.  
  • Conduct forensic analysis of file transfers, user activity, and system artifacts.  
  • Partner with Legal and HR to ensure investigations meet regulatory and evidentiary standards.  
  • Leverage OSINT tools and techniques (e.g., link analysis, persona development, attribution) to identify external risk indicators and potential insider collusion.  
  • Conduct proactive threat hunting to identify previously undetected insider risk activity. 
  • Partner with Cybersecurity (SOC), HR, Legal, Compliance, and IT to coordinate investigative actions and response strategies. 
  • Provide subject matter expertise on data exfiltration risks, investigative findings, and mitigation actions; support escalation and response for high-risk or sensitive incidents. 
  • Produce clear, concise investigative reports and intelligence briefings for technical and non-technical audiences.  
  • Translate complex technical findings into actionable recommendations, including risk mitigation, corrective actions, and control enhancements.  
  • Support the evolution of the insider threat program through process improvements, tool optimization, and policy enhancements. 

Qualifications You Must Have:

  • Bachelor’s degree in Cybersecurity, Computer Science, Criminal Justice, Intelligence Studies, or related field (or equivalent experience) and minimum 8 years experience in cyber investigations, digital forensics, insider threat, intelligence analysis, or related fields; or An Advanced Degree in a related field and minimum 5 years experience.
  • Proven experience conducting data exfiltration or cyber-enabled investigations.  
  • Proven ability to interview subjects, witnesses, and complainants and compiling investigative summaries, findings, and recommendations. 
  • Experience handling digital evidence and maintaining

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

RTX

View company profile →