FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Manager, Cyber Threat Intelligence – Response
DON PEO MLBMLB cybersecurity manager leading threat intelligence and incident response across the League, 30 Clubs, and affiliates. Building detections, threat hunts, automation, and security awareness programs.
Posted 8/18/2026full-timeRemote • 🇺🇸 United StatesMid-LevelSenior💰 $105,000 - $135,000 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in threat intelligence and incident response, with a strong focus on vulnerability assessment, threat hunting, and security automation. Proficient in developing detection content and leading cross-functional teams in high-stakes environments.
Highest-signal resume keywords
Threat IntelligenceIncident ResponseVulnerability AssessmentDetection Content DevelopmentThreat Hunting
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Threat Actor AnalysisMITRE ATT&CK FrameworkScripting LanguagesSIEM QueriesEDR LogicDetection-as-Code PracticesCyber Threat IntelligenceDigital ForensicsSecurity OperationsIncident Command
Soft Skills
Strong Communication SkillsDocumentation Skills
Tools & Technologies
AWSGCPOSINT ToolsSOAR PlatformsVulnerability Assessment Platforms
Certifications & Qualifications
CompTIA CySA+CompTIA CTIASANS GIAC Cyber Threat Intelligence (GCTI)
Industry Keywords
Incident Response LifecycleThreat HuntingPhishing SimulationTabletop ExercisesPost-Incident Review
Tech Stack
Tools & technologiesAWSCloudCyber SecurityGoogle Cloud PlatformPythonSQL
About the role
Key responsibilities & impact- Lead MLB's threat intelligence and incident response programs across the League office, the 30 Clubs, and their affiliates
- Own the vulnerability intelligence program and assess real-world risk from vulnerabilities, exploit code, proof-of-concepts, and threat actor weaponization
- Set remediation priorities using severity, exploit intelligence, asset context, and active targeting
- Direct research across OSINT, social media, deep and dark web sources, commercial intelligence platforms, and industry information-sharing groups
- Track threat actors, campaigns, indicators of compromise, and tactics, techniques, and procedures
- Build automation for vulnerability research, intelligence enrichment, alert correlation, investigation support, and reporting
- Convert intelligence into detection content, alert logic, hunt hypotheses, and tuning recommendations using Sigma, YARA, SIEM queries, EDR logic, and detection-as-code practices
- Develop and lead hypothesis-driven threat hunts across endpoint, identity, cloud, network, email, and application telemetry
- Support the incident response lifecycle from triage through closure, including containment, eradication, recovery, and escalation
- Serve as incident commander when on-call and lead incident bridges involving the vSOC, Clubs, Legal, Privacy, Communications, Technology, and other stakeholders
- Lead post-incident reviews, update playbooks and controls, and track corrective actions
- Lead analysts, contractors, vSOC partners, and external security providers
- Own security awareness training, education, and phishing simulation programs
- Plan and lead League-wide, Club, and internal tabletop exercises
- Develop and maintain incident response plans, escalation paths, procedures, and playbooks
Requirements
What you’ll need- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Criminal Justice, Criminology, Law, or a related field, or equivalent practical experience
- Strong knowledge of threat actors, campaigns, indicators of compromise, tactics, techniques, and procedures, including practical use of the MITRE ATT&CK framework
- Working knowledge of AWS or GCP
- Scripting, detection, or query languages such as PowerShell, Python, SQL, KQL, SPL, Sigma, or YARA
- Experience in cyber threat intelligence, incident response, security operations, digital forensics, or a related security role
- Experience leading security incidents through triage, escalation, containment, eradication, recovery, and post-incident review
- Experience developing and running threat hunts across endpoint, identity, cloud, network, email, or application data
- Experience developing or tuning detection content using SIEM queries, EDR logic, Sigma, YARA, or detection-as-code practices
- Hands-on experience with EDR/XDR, SIEM, and vulnerability assessment platforms
- Experience using OSINT, social media sources, deep and dark web monitoring, and commercial threat intelligence platforms
- Experience with security automation and orchestration (SOAR) platforms, including building workflows for threat intel research, enrichment, correlation, and reporting
- Strong documentation and communication skills, including explaining attack methods, response decisions, and risk to technical and non-technical audiences
- Ability to handle sensitive information and participate in a rotational after-hours on-call and incident escalation schedule
- Preferred certifications: CompTIA CySA+, CompTIA CTIA, or SANS GIAC Cyber Threat Intelligence (GCTI)
Benefits
Comp & perks- Competitive Benefits Package
- Company 401K Contribution
- Paid Time Off and Holidays
- Paid Parental Leave
- Access to Free Tickets to Baseball Games & MLB.TV
- Discounts at MLB Store | MLBShop.com
- Employee Assistance Programs (EAP)
- Onsite/Online Training & Development Programs
- Tuition Reimbursement
- Disability Benefits (short term and long term)
- Life and Accidental Death Insurance
- Pet Insurance
- Bonus