All vacancies
Counter-Threat Intelligence Engineer
Cambium Learning Group
Remote · worldwide, UTC+4 acceptedSalary not disclosedfull-timeHimalayas
Cambium Learning Group is seeking a Counter-Threat Intelligence Engineer to enhance the organization’s ability to identify, understand, and counter cyber threats that could impact our learners, educators, associates, platforms, data, and business operations. This role combines threat intelligence, ethical hacking, exposure validation, adversary emulation, and security engineering to turn emerging threat information into actionable defenses.
Responsibilities
- Collect, analyze, and operationalize strategic, tactical, and operational threat intelligence from trusted internal and external sources, including indicators of compromise, adversary tactics, techniques, and procedures, emerging vulnerabilities, and targeted threat activity.
- Perform adversary-focused research and ethical hacking activities, with authorization, to validate exposures, identify likely attack paths, and recommend defensive improvements across endpoints, cloud services, applications, identity platforms, networks, and third-party integrations.
- Partner with Security Operations to create, tune, and validate detections, playbooks, threat hunting hypotheses, and response workflows in data log pipelines, SIEM, XDR, EDR, vulnerability management, and related security tools.
- Support Continuous Threat Exposure Management efforts by helping scope assets, discover exposures, prioritize findings based on business risk, validate exploitability, and coordinate mobilization of remediation activities with IT, infrastructure, engineering, and business owners.
- Produce concise, actionable threat intelligence reports, briefings, and technical recommendations for audiences ranging from security analysts to senior leadership, emphasizing relevance, impact, urgency, and practical next steps.
- Contribute to incident response investigations by enriching alerts with threat context, malware or phishing analysis, infrastructure research, attack timeline reconstruction, and lessons learned.
- Maintain awareness of threat actor tradecraft, vulnerability exploitation trends, cloud and identity attacks, education-sector threats, data protection risks, and changes in attacker use of automation and artificial intelligence.
- Use independent judgment to make recommendations on defensive priorities, detection improvements, risk acceptance considerations, and escalation paths while staying aligned with Cambium policies, standards, and governance expectations.
Languages
- Work format
- Remote
- Seniority
- Senior
- Posted
- 31 Aug 2026
- Last verified
- In the last 3 days
- Apply by
- 30 Oct 2026
