ID.me
Senior Threat Intelligence Analyst
McLean, Virginia · Mountain View, California, United States
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.6M live jobs from 190,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Senior
- Country
- US
- Work mode
- Remote-friendly
- First seen by hirly
- 21 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Company Overview
ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly login across websites without having to create a new login and verify their identity again. Over 152 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600+ consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships. ID.me’s technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to “No Identity Left Behind” to enable all people to have a secure digital identity. To learn more, visit https://network.id.me/ .
ID.me is a full-time, in-office culture. Unless a specific job description explicitly states otherwise, all roles are on-site five days per week at one of our offices in McLean, VA; Mountain View, CA; New York City, NY; or Tampa, FL. Certain roles — such as field-based sales or other remote-by-design positions — may have different work arrangements as noted in their individual postings.
At ID.me, we embrace the thoughtful use of AI tools in our daily work and there are even occasions where we leverage AI in our hiring process. However, during the interview process, we want to understand your individual skills and experiences. Therefore, we have guidelines on how AI can be appropriately used during your application and interviews which can be found here .
ID.me is looking for a senior threat intelligence professional to lead technical tracking of the adversaries targeting the identity verification ecosystem, and to turn that tracking into decisions the business acts on. Identity fraud is an industrialized market of credential and document vendors, injection and deepfake tooling, synthetic identity brokers, and organized account takeover crews. This role sits directly across from it.
You will own intelligence coverage for a defined set of threats end to end: setting the collection strategy, running the research, building the models and tooling, and delivering the finished product to the people who need it, from detection engineers to executives and government partners. This is a senior individual-contributor role with high autonomy and real influence over security and product direction. You will also be a technical mentor to the analysts around you and a standard-setter for how the team does analysis.
Responsibilities
Own an intelligence portfolio. Take end-to-end responsibility for tracking a set of threat actors, fraud typologies, or ecosystems targeting ID.me and our partners, from collection through analysis to delivery and follow-up.
Set collection strategy. Define and prioritize intelligence requirements in partnership with security, fraud, product, and company leadership. Identify gaps in current coverage and close them.
Run technical collection at depth. Conduct sustained collection and source development across deep and dark web forums, illicit marketplaces, encrypted messaging platforms, and closed communities, using sound tradecraft and operational security.
Hunt emerging activity. Proactively hunt for new actor activity, tooling, and TTPs across internal telemetry and external sources, and pull threads before they become incidents.
Produce finished intelligence. Write assessments that hold up to scrutiny, with clear judgments, stated confidence levels, articulated assumptions, and specific recommendations, for audiences ranging from engineers to the executive team to external partners.
Make intelligence operational. Convert research into detections, fraud signals, blocklists, enrichment, and platform data. Work with detection engineering, data science, and product to get it deployed and measure whether it worked.
Advance the team's analytic tradecraft. Improve threat modeling standards, structured analytic methods, reporting templates, source evaluation, and the team's use of frameworks such as MITRE ATT&CK and the Diamond Model.
Build tooling and automation. Identify where manual work is limiting coverage and build or specify the tooling, pipelines, and enrichment to remove it.
Mentor and raise the bar. Coach analysts on collection tradecraft, analytic writing, and structured analysis. Review their work and help develop their judgment.
Represent the function. Brief senior leadership, partners, and where appropriate, industry peer groups, law enforcement, and information-sharing communities.
Qualifications
5+ years of experience in threat intelligence, cyber threat hunting, fraud intelligence, or a closely related discipline, including experience producing finished intelligence for decision-makers.
3+ years of hands-on collection across the deep and dark web, including illicit marketplaces and encrypted communication platforms, with demonstrated tradecraft and operational security practices.
Deep, applied experience with common analysis models and frameworks (MITRE ATT&CK, the Diamond Model, kill chain, structured analytic techniques). Not just familiarity, but a track record of using them to reach and defend analytic judgments.
Demonstrated ability to take ambiguous, fragmentary, and conflicting information and produce a clear assessment with appropriately expressed confidence.
Exceptional written and verbal communication, including experience writing for both deeply technical and executive audiences.
Track record of working independently: scoping your own problems, setting priorities, and driving work to a result without close direction.
Proven ability to influence stakeholders outside of security, and to translate intelligence into changes other teams actually make.
Preferred Qualifications
Experience with identity fraud, account takeover, synthetic identity, document and biometric fraud, or the fraud-as-a-service ecosystem.
Strong SQL skills for independent data analysis at scale, and scripting in Python or similar for collection, enrichment, and automation.
Experience turning intelligence into production detections or fraud controls alongside engineering and data science teams.
Experience mentoring analysts or leading intelligence projects across multiple contributors.
Relevant certifications such as GCTI, GREM, GCFA, GOSI, CISSP, or Security+.
Working proficiency in a foreign language relevant to threat actor communities.
Experience in a regulated or government-facing environment, or supporting external partners with intelligence products.
ID.me maintains a work environment free from discrimination, where employees are treated with dignity and respect. All ID.me employees share in the responsibility for fulfilling our commitment to equal employment opportunity. ID.me does not discriminate against any employee or applicant on the basis of age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. ID.me adheres to these principles in all aspects of employment, including recruitment, hiring, training, compensation, promotion, benefits, social and recreational programs, and discipline. In addition, ID.me's policy is to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations and ordinances where a particular employee works. Upon request we will provide you with more information about such acc
Listed on hirly, a job board. hirly is not the employer: ID.me is hiring for this role.
Similar jobs
- Cyber All- Source Intelligence Analyst Senior- TS/SCI w/polyGdit · USA MD College ParkFirst seen today
- Intelligence Analyst Senior - Data Governance _ Division of Information SystemsUmmc · Jackson, MS - Main CampusFirst seen yesterday
- Senior Intelligence AnalystUchicago · Hyde Park CampusFirst seen yesterday
- Senior Acquisition Intelligence AnalystKbr · El Segundo, CaliforniaFirst seen yesterday
- Senior PNT Intelligence AnalystKbr · Beavercreek Township, OhioFirst seen yesterday
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job