freehire is live on Product Hunt today.

Support the launch →

Counter-Threat Intelligence Engineer

Job Overview:

Cambium Learning Group is seeking a Counter-Threat Intelligence Engineer to enhance the organization’s ability to identify, understand, and counter cyber threats that could impact our learners, educators, associates, platforms, data, and business operations. This role combines threat intelligence, ethical hacking, exposure validation, adversary emulation, and security engineering to turn emerging threat information into actionable defenses. The engineer will work closely with Security Operations, IT Operations, Risk, Legal Compliance, Product, Engineering, and business stakeholders to help reduce attack surface, improve detection logic, support incident response, and translate technical findings into clear recommendations. The ideal candidate brings hands-on offensive security experience, exceptional analytical judgment, and the ability to communicate threat context in a way that drives practical remediation and measurable risk reduction.

Job Responsibilities:

  • Collect, analyze, and operationalize strategic, tactical, and operational threat intelligence from trusted internal and external sources, including indicators of compromise, adversary tactics, techniques, and procedures, emerging vulnerabilities, and targeted threat activity.
  • Perform adversary-focused research and ethical hacking activities, with authorization, to validate exposures, identify likely attack paths, and recommend defensive improvements across endpoints, cloud services, applications, identity platforms, networks, and third-party integrations.
  • Partner with Security Operations to create, tune, and validate detections, playbooks, threat hunting hypotheses, and response workflows in data log pipelines, SIEM, XDR, EDR, vulnerability management, and related security tools.
  • Support Continuous Threat Exposure Management efforts by helping scope assets, discover exposures, prioritize findings based on business risk, validate exploitability, and coordinate mobilization of remediation activities with IT, infrastructure, engineering, and business owners.
  • Produce concise, actionable threat intelligence reports, briefings, and technical recommendations for audiences ranging from security analysts to senior leadership, emphasizing relevance, impact, urgency, and practical next steps.
  • Contribute to incident response investigations by enriching alerts with threat context, malware or phishing analysis, infrastructure research, attack timeline reconstruction, and lessons learned.
  • Maintain awareness of threat actor tradecraft, vulnerability exploitation trends, cloud and identity attacks, education-sector threats, data protection risks, and changes in attacker use of automation and artificial intelligence.
  • Use independent judgment to make recommendations on defensive priorities, detection improvements, risk acceptance considerations, and escalation paths while staying aligned with Cambium policies, standards, and governance expectations.

Job Requirements:

  • 5+ years of progressive cybersecurity experience, with at least 2 years in threat intelligence, ethical hacking, penetration testing, detection engineering, security operations, incident response, vulnerability management, or a closely related role.
  • Certified Ethical Hacker (CEH) certification is highly preferred; similar hands-on offensive security or threat intelligence certifications may be considered, such as OSCP, GPEN, CompTIA PenTest+, CPENT, eJPT, GCTI, CTIA, or equivalent practical experience.
  • Proven working knowledge of the cyber kill chain, MITRE ATT&CK, common attack techniques, malware and phishing behaviors, cloud and identity threats, vulnerability exploitation, attacker infrastructure, and defensive countermeasures.
  • Hands-on experience with security tools and data sources such as SIEM, XDR/EDR, vulnerability scanners, threat intelligence platforms, cloud security tools, identity logs, endpoint telemetry, network telemetry, and ticketing/workflow platforms.
  • Ability to write clear threat intelligence summaries, detection recommendations, executive briefings, remediation guidance, and technical documentation that can be acted on by cross-functional teams.
  • Experience conducting authorized security testing, adversary emulation, attack surface analysis, detection validation, or threat hunts in a disciplined, evidence-based, and policy-aligned manner.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field preferred; equivalent professional experience and certifications may be considered.
  • High judgment, strong ethics, discretion with sensitive information, collaborative communication style, and commitment to protecting confidential, proprietary, student, customer, associate, and business data.

Preferred Qualifications:

  • Experience in education technology, SaaS, cloud-first, remote-first, or regulated environments.
  • Experience building threat hunting content, Sigma/YARA rules, KQL/SPL queries, detection-as-code, or automation for enrichment and triage.
  • Familiarity with scripting or automation using Python, PowerShell, Bash, APIs, or SOAR-style workflows.
  • Working knowledge of data privacy, secure software development, third-party risk, and compliance frameworks such as ISO 27001, SOC 2, NIST CSF, or NIST SP 800-series guidance.

To learn more about our organization and the exciting work we do, visit

Remote First Work Environment

Our Remote First approach gives employees the flexibility and trust they need to effectively balance work with life. It creates a culture in which all employees are valued and where success is measured in results. It allows us to work collaboratively, inclusively and for greater positive impact, regardless of our individual locations.

If you will be working remotely, either occasionally or on a permanent basis, you must have a reliable internet connection through a cable or fiber-optic broadband service with minimum speeds of 10 Mbps download and 5 Mbps upload.

The successful candidate will be expected to actively participate in video-based interviews during the recruiting process and ongoing virtual meetings with their camera on, as part of their role. To maintain confidentiality and ensure a fair evaluation process, the use of note-taking tools, reference materials, or AI-powered tools (including generative AI, language models, or similar technologies) during interviews or other selection activities is prohibited unless prior written approval has been obtained from the People Experience team. If you require an exception for medical, accessibility, or other reasons, please contact your Talent Acquisition team member to discuss accommodations in advance.

As part of our Remote-First benefits, Cambium offers reimbursement to help cover the cost of setting up your home or remote office.

An Equal Opportunity Employer

We are dedicated to fostering a culture that celebrates unique backgrounds, ideas, and experiences. All qualified applicants will receive consideration for employment without discrimination on the basis of race, color, age, religion, sex (including pregnancy, gender, gender identity/expression, or sexual orientation), national origin, protected veteran status, disability, or genetic information (including family medical history).

We will provide reasonable accommodations for qualified individuals with disabilities. You may request an accommodation during the recruiting process with your Talent Acquisition team member.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available