Skip to content

Open nowPosted 7 days ago

Manager, Threat Intelligence

PDI Technologies24 open roles

Where
Remote US
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowManager, Threat IntelligencePDI Technologies · Remote US
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on PDI Technologies's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. PDI Technologies postings stay open a median of 19 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.5%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 33.9%30 days
This job: posted 7 days ago

PDI Technologies median: 19 days open

The posting

At PDI Technologies, we empower some of the world's leading convenience retail and petroleum brands with cutting-edge technology solutions that drive growth and operational efficiency. By “Connecting Convenience” across the globe, we empower businesses to increase productivity, make more informed decisions, and engage faster with customers through loyalty programs, shopper insights, and unmatched real-time market intelligence via mobile applications, such as GasBuddy. We’re a global team committed to excellence, collaboration, and driving real impact. Explore our opportunities and become part of a company that values diversity, integrity, and growth.

Role Overview

Every day, millions of people buy fuel, coffee, and lunch at the businesses PDI protects. Convenience stores, fuel stations, quick-service restaurants, and automotive businesses run on payment systems, point-of-sale networks, and connected site equipment, and financially motivated attackers know it.

We're looking for an experienced leader to own threat intelligence, threat hunting, and detection engineering for our SOC. You'll build the clearest picture anywhere of who targets these industries and how, then turn it into detections, hunts, and guidance that protects 12,000+ customers.

This isn't an internal intel team serving one company. Your team's work ships to every customer we protect, and you'll have real room to build the program the way you think it should run.

Why this role stands out

  • A threat landscape you can own. Payment card theft, POS malware, ransomware against franchise networks, and attacks on connected forecourt and in-store systems. Few teams anywhere specialize here.
  • A straight line from intel to impact. Your team writes the intelligence and the detections. You'll see your work stop real attacks across many customer environments.
  • Room to build. Shape the methodology, tooling, and AI-assisted workflows rather than inheriting someone else's playbook.
  • Visibility. Brief customer executives, partner with SOC, product, and company leaders, and represent PDI in industry and intelligence-sharing communities.

What you'll own

  • Hire, coach, and develop a remote team of analysts, hunters, and detection engineers, with clear priorities and career paths.
  • With a team of four, you'll split your time between leading and doing: hunting, writing intelligence, and building detections alongside the team.
  • Partner with SOC, Incident Response, and Security Engineering leaders to improve detection, response, and customer outcomes.
  • Define intelligence requirements with SOC leadership and customers and run the full intelligence lifecycle from collection through feedback.
  • Deliver strategic, operational, and tactical products: actor profiles, campaign analysis, industry threat briefs, and customer-specific reports.
  • Track the actors that matter most to our customers, including financially motivated groups, payment fraud operations, and ransomware crews targeting retail and hospitality.
  • Own detection content strategy across SIEM and EDR/XDR, including development, testing, tuning, and coverage measured against MITRE ATT&CK.
  • Run hypothesis-driven threat hunts across customer environments and feed what you find back into new detections.
  • Use automation and AI to scale enrichment, triage support, and reporting so the team can focus on analysis, not busywork.
  • Provide intelligence context during major incidents and lead during complex escalations.
  • Serve as a trusted advisor to customers through briefings, reports, and presentations for both technical and executive audiences.
  • Run the team on clear metrics such as detection coverage, hunt findings, reporting timeliness, and customer satisfaction, and contribute to service planning and new offerings.

What success looks like

  • First 90 days: Assess the team, tooling, and current detection coverage. Agree on intelligence requirements with SOC leadership and key customers.
  • By 6 months: A regular cadence of industry threat reporting, plus an ATT&CK coverage baseline and roadmap.
  • By 12 months: Measurable gains in detection coverage and hunt-driven findings, and a team customers see as the go-to source on threats to their industry.

What you bring

  • 8+ years in cybersecurity across threat intelligence, threat hunting, incident response, detection engineering, or security operations.
  • 3+ years managing technical security teams, including hiring and developing people.
  • Deep knowledge of adversary tactics and the frameworks used to analyze them, such as MITRE ATT&CK, the intelligence lifecycle, and the Diamond Model.
  • A track record of producing finished intelligence for both technical and executive audiences.
  • Hands-on experience with SIEM (FortiSIEM, Microsoft Sentinel, Splunk, Google Chronicle, or ArcSight) and EDR/XDR platforms and their query languages (KQL, SPL, or similar). Our environment includes FortiSIEM; equivalent experience is welcome.
  • Experience supporting complex investigations and incident response.
  • Excellent written, verbal, and presentation communication skills.
  • Clear writing and speaking skills, with the ability to translate technical findings into business risk.
  • Experience at an MSSP or MDR provider serving many customers.
  • Background in retail, hospitality, or payments environments, including POS systems or PCI DSS.
  • Detection-as-code, Sigma, SOAR, or scripting (e.g., Python).
  • Experience with threat intelligence platforms and feeds, such as MISP or Recorded Future.
  • Cloud and SaaS investigations across Azure, AWS, or Microsoft 365.
  • Active involvement in intelligence-sharing communities such as RH-ISAC.
  • Certifications such as GCTI, GCFA, GCIH, GREM, or CISSP are welcome but not required.

PDI is committed to offering a well-rounded benefits program, designed to support and care for you, and your family throughout your life and career. This includes a competitive salary, market-competitive benefits, and a quarterly perks program. We encourage a good work-life balance with ample time off [time away] and, where appropriate, hybrid working arrangements. Employees have access to continuous learning, professional certifications, and leadership development opportunities. Our global culture fosters diversity, inclusion, and values authenticity, trust, curiosity, and diversity of thought, ensuring a supportive environment for all.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against PDI Technologies's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on PDI Technologies's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    PDI Technologies's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.