This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As a Senior Cyber Threat Intelligence Engineer, you will function as a deeply technical individual contributor responsible for advancing intelligence-driven threat detection and proactive threat hunting across GEICO’s environment. This role requires extensive hands-on experience, strong analytic judgment, and the ability to independently execute complex work that directly contributes to reducing cyber risk. You will be expected to operate with a high degree of autonomy, applying your technical expertise to identify adversary behavior, develop actionable insights, and drive meaningful outcomes without requiring close supervision.
Job Responsibility:
Analyze and assess advanced cyber threats, adversary behavior, tooling, and campaigns relevant to GEICO
Develop and execute intelligence-informed threat-hunting hypotheses using endpoint, network, and cloud telemetry
Build, maintain, and enhance custom tools, scripts, and automation to support intelligence analysis and hunting workflows
Use programming and scripting languages (e.g., Python, PowerShell, Bash, or similar) to analyze data, enrich intelligence, and automate manual processes
Translate threat intelligence into actionable detection logic, investigative guidance, and response context
Produce clear, well-structured written intelligence products, including assessments, briefings, and reports for both technical and non-technical audiences
Support active investigations by providing timely adversary context during incidents
Track emerging threats, vulnerabilities, and adversary trends, prioritizing relevance and impact
Continuously improve analytic tradecraft, tooling, and processes to increase effectiveness and efficiency
Requirements:
7+ years of experience in cyber threat intelligence, threat hunting, security operations, or a related cybersecurity discipline
Demonstrated hands-on experience conducting threat hunting in enterprise environments
Strong coding or scripting experience with the ability to design and maintain custom tools
Proven experience applying adversary frameworks such as MITRE ATT&CK to real-world detection and analysis
Experience producing written intelligence products that inform technical teams and leadership
Deep understanding of attacker techniques, intrusion workflows, malware, and phishing operations
Experience working with SIEM, EDR, and threat intelligence platforms
Ability to work independently, manage competing priorities, and deliver results under time constraints
Nice to have:
Experience supporting incident response or digital forensics activities
Familiarity with cloud platforms and cloud-based threat activity
Experience building internal CTI tooling, pipelines, or automation
Experience working in large enterprise or regulated environments
What we offer:
Comprehensive Total Rewards program
401K savings plan with 6% match
Performance and recognition-based incentives
Tuition assistance
Mental healthcare
Fertility and adoption assistance
Workplace flexibility
GEICO Flex program (work from anywhere in the US for up to four weeks per year)