Manager, Cyber Threat Intelligence & Response
Major League BaseballAbout the role
Major League Baseball is looking for a Manager, Cyber Threat Intelligence & Response to lead MLB's threat intelligence and incident response programs across the League office, the 30 Clubs, and their affiliates. The role manages vulnerability and exploit intelligence, digital risk monitoring, incident coordination, forensic investigation, threat hunting, and the use of intelligence in vSOC detection and response. The manager also owns security awareness programming and uses automation to shorten research, triage, and reporting cycles.
Responsibilities
Threat and Vulnerability Intelligence
- Own MLB's vulnerability intelligence program. Monitor newly disclosed vulnerabilities, exploit code, proof-of-concept availability, and threat actor weaponization to assess real-world risk across MLB environments
- Combine severity, exploit intelligence, asset context, and active targeting to set remediation priorities for the vSOC, Clubs, and internal Technology teams
- Direct research across OSINT, social media, deep and dark web sources, commercial intelligence platforms, and industry information-sharing groups
- Track threat actors, campaigns, indicators of compromise, and tactics, techniques, and procedures. Maintain documentation that the vSOC can use during investigations, threat modeling, and response
- Track and report threat intelligence, vulnerability, and response measures, including time to detect, time to contain, time to recover, incident recurrence, playbook use, and corrective action closure
- Support investigations involving credential exposure, phishing infrastructure, impersonation, fraudulent domains, executive targeting, brand abuse, and other external threats. Coordinate takedown or disruption work when needed
Detection Engineering and Threat Hunting
- Build and improve automation for vulnerability research, intelligence enrichment, alert correlation, investigation support, and reporting
- Convert threat and vulnerability intelligence into detection content, alert logic, hunt hypotheses, and tuning recommendations using Sigma, YARA, SIEM queries, EDR logic, and detection-as-code practices where appropriate
- Develop and lead hypothesis-driven threat hunts across endpoint, identity, cloud, network, email, and application telemetry
- Use threat and vulnerability intelligence to validate vSOC alerts, support containment decisions, reduce false positives, and identify gaps in detection coverage
Incident Response
- Support the incident response lifecycle, including triage, severity assessment, escalation, containment, eradication, recovery, and closure
- Set intelligence priorities and collection requirements for cyber threat intelligence, digital risk protection, social media monitoring, and vulnerability research
- Serve as incident commander when on-call for security events and lead incident bridges involving the vSOC, Clubs, Legal, Privacy, Communications, Technology, and other stakeholders
- Exercise delegated authority to direct containment, recovery, forensic response, and cross-functional incident coordination
- Lead post-incident reviews, document findings, update playbooks and controls, and track corrective actions through completion
Security Awareness and Incident Readiness
- Lead analysts, contractors, vSOC partners, and external security providers supporting intelligence and response operations
- Own MLB's security awareness strategy, including training, education, and phishing simulations based on current attacker methods and observed risk
- Plan and lead League-wide, Club, and internal tabletop exercises to test incident response plans, escalation procedures, communications, and playbooks
- Develop and maintain incident response plans, escalation paths, procedures, and playbooks for endpoint, identity, cloud, email, third-party, ransomware, and business email compromise scenarios
Qualifications & Skills
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Criminal Justice, Criminology, Law, or a related field, or equivalent practical experience
- Strong knowledge of threat actors, campaigns, indicators of compromise, tactics, techniques, and procedures, including practical use of the MITRE ATT&CK framework
- Working knowledge of AWS or GCP and scripting, detection, or query languages such as PowerShell, Python, SQL, KQL, SPL, Sigma, or YARA
- Experience in cyber threat intelligence, incident response, security operations, digital forensics, or a related security role
- Experience leading security incidents through triage, escalation, containment, eradication, recovery, and post-incident review
- Experience developing and
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s