Threat Intelligence Lead

Anaplan · London, United Kingdom · Other

Posted 2026-08-24

Apply for this role →

Role Summary

As Anaplan's Threat Intelligence Lead, you will own and shape the company's Threat Intelligence function from the ground up. This is a senior, hands-on role at the heart of Anaplan's security organisation — you will set the TI strategy and lifecycle, build and mature the threat hunting programme, and act as the primary intelligence partner to the SOC, Product Security, and Incident Response teams. You'll be both a practitioner and a programme owner: conducting deep research, running hunts, building integrations, and presenting findings to CISO-level stakeholders.

Your Impact

Own and lead Anaplan's Threat Intelligence function — defining the TI strategy, lifecycle (planning, collection, processing, analysis, dissemination, and feedback), and operational cadence across the security organisation

Manage and administer TI platforms and tooling, and drive their integration with the SOC, Product Security, and other security teams' existing solutions

Own and mature Anaplan's threat hunting programme — designing and developing hunt methodologies, playbooks, and hypotheses for use across Security Operations and the broader security organisation, and executing hunts end-to-end

Serve as the primary TI partner during active incidents — providing timely, actionable intelligence to the incident response team by researching adversary TTPs, campaigns, IOCs, and attribution to support triage and containment decisions

Conduct structured threat intelligence research into threat actors, campaigns, and emerging risks relevant to Anaplan's threat landscape, producing intelligence products pitched appropriately for both technical teams and executive audiences

Build and maintain integrations between TI platforms and existing security tooling (SIEM, SOAR, EDR/XDR), leveraging scripting and engineering skills to automate intelligence collection, enrichment, and dissemination workflows

Author, contribute to, and validate detection content — including SIEM queries, hunt logic, and custom detection rules — informed by current threat intelligence and aligned to the MITRE ATT&CK framework

Communicate threat intelligence findings, programme maturity updates, and emerging risk briefings clearly and confidently to senior and executive stakeholders, up to and including CISO level

Your Qualifications

Deep understanding of what an effective Threat Intelligence function requires — including the intelligence lifecycle, operational cadence, and how TI integrates and delivers value across a security organisation

Hands-on experience with commercial and open-source TI platforms and tooling, spanning threat intelligence aggregation, enrichment, and sharing

Strong threat hunting experience — designing and executing structured, hypothesis-driven hunts using frameworks such as MITRE ATT&CK, and translating hunt findings into actionable detections

Practical experience supporting incident response with threat intelligence — comfortable researching adversary tradecraft, attribution, and IOCs under time pressure alongside an IR team

Engineering and scripting proficiency to build integrations, automate TI workflows, and develop or enhance hunt tooling

Experience authoring detection content — including SIEM query languages and custom detection rule formats

Solid working knowledge of SIEM, SOAR, and EDR/XDR platforms and how threat intelligence enriches their capabilities

Ability to communicate complex intelligence clearly and confidently to senior and executive audiences, including CISO-level stakeholders, adapting technical detail to the audience's context

Strong understanding of adversary tradecraft, threat actor groups, and the evolving threat landscape relevant to SaaS and enterprise environments

Apply for this role →

← Back to all jobs