Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
DON PEO MLB

Manager, Cyber Threat Intelligence – Response

DON PEO MLB

MLB cybersecurity manager leading threat intelligence and incident response across the League, 30 Clubs, and affiliates. Building detections, threat hunts, automation, and security awareness programs.

Posted 8/18/2026full-timeRemote • 🇺🇸 United StatesMid-LevelSenior💰 $105,000 - $135,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in threat intelligence and incident response, with a strong focus on vulnerability assessment, threat hunting, and security automation. Proficient in developing detection content and leading cross-functional teams in high-stakes environments.

Highest-signal resume keywords
Threat IntelligenceIncident ResponseVulnerability AssessmentDetection Content DevelopmentThreat Hunting

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Threat Actor AnalysisMITRE ATT&CK FrameworkScripting LanguagesSIEM QueriesEDR LogicDetection-as-Code PracticesCyber Threat IntelligenceDigital ForensicsSecurity OperationsIncident Command
Soft Skills
Strong Communication SkillsDocumentation Skills
Tools & Technologies
AWSGCPOSINT ToolsSOAR PlatformsVulnerability Assessment Platforms
Certifications & Qualifications
CompTIA CySA+CompTIA CTIASANS GIAC Cyber Threat Intelligence (GCTI)
Industry Keywords
Incident Response LifecycleThreat HuntingPhishing SimulationTabletop ExercisesPost-Incident Review

Tech Stack

Tools & technologies
AWSCloudCyber SecurityGoogle Cloud PlatformPythonSQL

About the role

Key responsibilities & impact
  • Lead MLB's threat intelligence and incident response programs across the League office, the 30 Clubs, and their affiliates
  • Own the vulnerability intelligence program and assess real-world risk from vulnerabilities, exploit code, proof-of-concepts, and threat actor weaponization
  • Set remediation priorities using severity, exploit intelligence, asset context, and active targeting
  • Direct research across OSINT, social media, deep and dark web sources, commercial intelligence platforms, and industry information-sharing groups
  • Track threat actors, campaigns, indicators of compromise, and tactics, techniques, and procedures
  • Build automation for vulnerability research, intelligence enrichment, alert correlation, investigation support, and reporting
  • Convert intelligence into detection content, alert logic, hunt hypotheses, and tuning recommendations using Sigma, YARA, SIEM queries, EDR logic, and detection-as-code practices
  • Develop and lead hypothesis-driven threat hunts across endpoint, identity, cloud, network, email, and application telemetry
  • Support the incident response lifecycle from triage through closure, including containment, eradication, recovery, and escalation
  • Serve as incident commander when on-call and lead incident bridges involving the vSOC, Clubs, Legal, Privacy, Communications, Technology, and other stakeholders
  • Lead post-incident reviews, update playbooks and controls, and track corrective actions
  • Lead analysts, contractors, vSOC partners, and external security providers
  • Own security awareness training, education, and phishing simulation programs
  • Plan and lead League-wide, Club, and internal tabletop exercises
  • Develop and maintain incident response plans, escalation paths, procedures, and playbooks

Requirements

What you’ll need
  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Criminal Justice, Criminology, Law, or a related field, or equivalent practical experience
  • Strong knowledge of threat actors, campaigns, indicators of compromise, tactics, techniques, and procedures, including practical use of the MITRE ATT&CK framework
  • Working knowledge of AWS or GCP
  • Scripting, detection, or query languages such as PowerShell, Python, SQL, KQL, SPL, Sigma, or YARA
  • Experience in cyber threat intelligence, incident response, security operations, digital forensics, or a related security role
  • Experience leading security incidents through triage, escalation, containment, eradication, recovery, and post-incident review
  • Experience developing and running threat hunts across endpoint, identity, cloud, network, email, or application data
  • Experience developing or tuning detection content using SIEM queries, EDR logic, Sigma, YARA, or detection-as-code practices
  • Hands-on experience with EDR/XDR, SIEM, and vulnerability assessment platforms
  • Experience using OSINT, social media sources, deep and dark web monitoring, and commercial threat intelligence platforms
  • Experience with security automation and orchestration (SOAR) platforms, including building workflows for threat intel research, enrichment, correlation, and reporting
  • Strong documentation and communication skills, including explaining attack methods, response decisions, and risk to technical and non-technical audiences
  • Ability to handle sensitive information and participate in a rotational after-hours on-call and incident escalation schedule
  • Preferred certifications: CompTIA CySA+, CompTIA CTIA, or SANS GIAC Cyber Threat Intelligence (GCTI)

Benefits

Comp & perks
  • Competitive Benefits Package
  • Company 401K Contribution
  • Paid Time Off and Holidays
  • Paid Parental Leave
  • Access to Free Tickets to Baseball Games & MLB.TV
  • Discounts at MLB Store | MLBShop.com
  • Employee Assistance Programs (EAP)
  • Onsite/Online Training & Development Programs
  • Tuition Reimbursement
  • Disability Benefits (short term and long term)
  • Life and Accidental Death Insurance
  • Pet Insurance
  • Bonus