Threat Intelligence Lead

Anaplan

Threat Intelligence Lead Overview

Company Name Anaplan
Job Role Threat Intelligence Lead
Qualifications Not Specified
Category General Jobs
Job Type Full Time
Location London

Join a leading organization dedicated to transforming business decision-making through innovative AI-powered scenario planning and analysis tools. Our platform is trusted by over 2,400 global companies, including Fortune 50 giants like Coca-Cola, LinkedIn, Adobe, LVMH, and Bayer. At Anaplan, we foster a culture of diversity, inclusion, and continuous improvement, encouraging our team members to bring their authentic selves to work and to contribute to our collective success.

Role Overview

We are seeking a highly experienced Threat Intelligence Lead to oversee and enhance our incident response and digital forensics capabilities. This senior, hands-on position requires a deep understanding of digital forensic techniques, incident management, and threat intelligence analysis. You will lead complex investigations, perform forensic examinations across various environments, and leverage intelligence to understand adversaries, including state-sponsored actors, criminal groups, and AI-enabled attackers.

Key Responsibilities

  • Lead investigations into high-severity security incidents, managing the process from initial triage through containment, eradication, and recovery, including post-incident reviews.
  • Perform forensic analysis on endpoints, servers, cloud platforms, SaaS applications, and identity systems, ensuring evidence integrity and reconstructing attacker activities.
  • Apply threat intelligence to guide investigations, understanding attacker tradecraft, objectives, and related activities to inform response strategies.
  • Collaborate with legal, privacy, and communications teams during major incidents, and coordinate with external response partners as needed.
  • Conduct proactive threat hunting based on hypotheses derived from investigation findings and intelligence insights, developing precise detection mechanisms.
  • Create threat reports that translate technical findings into clear assessments for security teams and executive leadership.
  • Develop and shape the organizationâ??s threat intelligence capabilities, including defining requirements, sourcing, and tooling support.
  • Expand and improve incident response playbooks, forensic procedures, and evidence handling standards, mentoring SOC analysts during investigations.
  • Integrate AI tools into workflows to automate evidence collection, enrichment, and analysis, building AI-assisted investigation workflows and automation solutions.

Required Skills and Experience

  • Hands-on experience in digital forensics and incident response, especially managing complex investigations in hybrid, cloud, and SaaS environments.
  • Proficiency in forensic techniques across endpoints, memory, network, logs, and cloud evidence, with a strong focus on evidence handling and chain of custody.
  • An investigative mindset that seeks to understand who is behind malicious activity, their motives, and their methods, turning findings into actionable intelligence.
  • Knowledge of intelligence analysis fundamentals, including structured analysis, confidence assessments, and models like the Diamond Model and F3EAD.
  • Understanding of the cybercrime underground ecosystem, including criminal forums, marketplaces, initial access brokers, and ransomware groups, with experience managing research personas as a plus.
  • Experience leading hypothesis-driven threat hunting and translating findings into detection rules.
  • Practical experience with AI applications in security, such as building workflows that leverage large language models for investigation or automation, supported by scripting skills like Python.
  • Strong familiarity with SIEM, SOAR, and EDR/XDR platforms, and how they support investigation, hunting, and response activities.
  • Deep understanding of attacker behaviors and the MITRE ATT&CK framework, especially in enterprise, cloud, and SaaS environments.
  • Excellent communication skills, capable of explaining complex technical findings clearly to senior stakeholders, including CISOs.
  • Calm, structured approach during high-pressure incidents, with a focus on knowledge sharing and team development.

Our Commitment

We are dedicated to fostering a diverse, equitable, inclusive, and belonging-focused workplace. We believe that embracing diversity enhances innovation, trust, and business success. We are committed to respecting and valuing all individuals, regardless of gender, ethnicity, age, neurodiversity, disability, or background. Reasonable accommodations are provided for candidates with disabilities upon request.

Important Notices

Beware of fraudulent job offers circulating online. Anaplan does not make job offers without an extensive interview process involving our recruitment team and hiring managers, and all official communications come from an @anaplan.com email address. If in doubt, contact us at [email protected].

Candidate data collected during recruitment is handled in accordance with our privacy policies, which may include AI and automated tools to assist in evaluation.

Application Process

Interested candidates can submit their applications by providing personal details, attaching a CV, and answering questions about work authorization and sponsorship needs. We encourage you to create job alerts for future opportunities at Anaplan.

Note: The role is based in London, UK, and the application form asks about right to work and visa sponsorship requirements.


Degree Requirement: Not Specified

Visa Sponsorship May be

To apply for this job please visit job-boards.greenhouse.io.