Lead Threat Intelligence Engineer
Core
Establishing Clio's dedicated threat intelligence capability to characterize adversaries targeting legal tech, produce actionable intelligence for detection and red teaming, and analyze fraud/abuse patterns.
Role type
Senior individual-contributor threat intelligence engineer
Builds
Threat intelligence platform, original research on adversary campaigns, fraud pattern briefs, and intelligence-driven detection requirements
Domain
Cybersecurity, Threat Intelligence, Legal Tech, Fraud Prevention
Required skills
Threat intelligence lifecycle management, adversary tracking and attribution, fraud and abuse pattern analysis, MITRE ATT&CK and Diamond Model fluency, structured analytic techniques, AI agent direction and validation, scripting (Python/Ruby), stakeholder briefing, team mentoring
Preferred skills
Financial services cybercrime experience, legal-tech threat landscape knowledge, industry intel-sharing community relationships (via careerplan.io/jobs/REQ-5442-lead-threat-intelligence-engineer-at-clio)
Technologies
Splunk, ELK/OpenSearch, OSINT tools, dark-web monitoring feeds, AI agents
Responsibilities
Define and maintain Priority Intelligence Requirements; stand up the threat intelligence platform; produce tactical, operational, and strategic intelligence; track external threat actors and fraud rings; mentor junior analysts; manage vendor relationships; brief security leadership and technical teams
Seniority
Senior, hands-on IC with strategic program ownership
