CareerPlanSign in

Lead Threat Intelligence Engineer

💼 Full-time🗓 2026-10-02 → 2026-10-07

Core

Establishing Clio's dedicated threat intelligence capability to characterize adversaries targeting legal tech, produce actionable intelligence for detection and red teaming, and analyze fraud/abuse patterns.

Role type

Senior individual-contributor threat intelligence engineer

Builds

Threat intelligence platform, original research on adversary campaigns, fraud pattern briefs, and intelligence-driven detection requirements

Domain

Cybersecurity, Threat Intelligence, Legal Tech, Fraud Prevention

Required skills

Threat intelligence lifecycle management, adversary tracking and attribution, fraud and abuse pattern analysis, MITRE ATT&CK and Diamond Model fluency, structured analytic techniques, AI agent direction and validation, scripting (Python/Ruby), stakeholder briefing, team mentoring

Preferred skills

Financial services cybercrime experience, legal-tech threat landscape knowledge, industry intel-sharing community relationships (via careerplan.io/jobs/REQ-5442-lead-threat-intelligence-engineer-at-clio)

Technologies

Splunk, ELK/OpenSearch, OSINT tools, dark-web monitoring feeds, AI agents

Responsibilities

Define and maintain Priority Intelligence Requirements; stand up the threat intelligence platform; produce tactical, operational, and strategic intelligence; track external threat actors and fraud rings; mentor junior analysts; manage vendor relationships; brief security leadership and technical teams

Seniority

Senior, hands-on IC with strategic program ownership