What are the responsibilities and job description for the Director, Threat Intelligence Collections Manager position at CLS Group?
About CLS:
CLS is the trusted party at the centre of the global FX ecosystem. Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective. Trillions of dollars’ worth of currency flows through our systems each day.
Created by the market for the market, our unrivalled global settlement infrastructure reduces systemic risk and provides standardization for participants in many of the world’s most actively traded currencies. We deliver huge efficiencies and savings for our clients: in fact, our approach to multilateral netting shrinks funding requirements by over 96% on average, so clients can put their capital and resources to better use.
CLS products are designed to enable clients to manage risk most effectively across the full FX lifecycle – whether through more efficient processing tools or market intelligence derived from the largest single source of FX executed data available to the market.
Our ambition to make a positive difference starts with our people. Our values – Protect, Improve, Grow – underpin everything that we do at CLS and define and shape a supportive and inclusive working environment in which everyone is encouraged to be open and forward-thinking
Job Information:
- Functional Title: Threat Intelligence Collections Manager
- Department: IT Security
- Corporate Level: Director
- Reports To: Executive Director
- Location: New Jersey, on-site 2 days per week
Job purpose:
CLS is seeking a highly motivated, self-driven Cyber Threat Intelligence Director for Collection Management to join a global threat intelligence team. The role will be located in London. The position will report to the Head of Cyber Threat Intelligence and Proactive Cyber Defense and will lead the development, implementation, and continuous improvement of our intelligence collection. The ideal candidate will be aware of industry trends and frameworks and how they could impact our business, including threat actor groups, their TTPs, intrusion activities, and geopolitical relevance. The candidate will be responsible for maintaining our intelligence requirements through internal stakeholder engagement and coordinating our various intelligence sources. The candidate will also interact with established industry and government partners on a daily basis to share intelligence and build out new partnerships. This role will also be responsible for mentoring others on the team.
This position requires someone with an analytical mind, a quick learner, and the ability to create and deliver briefings, propose, and execute program initiative’s/improvements, and collaborate with a wide range of key internal and external stakeholders.
Job Description:
- Lead the collections and processing of cyber threat intelligence from varying sources, including open-source reports, information sharing partners, and vendor reports to create actionable results for internal stakeholders
- Collaborate with stakeholders across the firm to evaluate intelligence requirements regularly
- Develop strategies for intelligence collection through developing requirements and determining appropriate sources to answer requirements
- Drive the relationship with intelligence vendors and partners to ensure intelligence requirements are being answered
- Actively manage external intelligence sharing engagements with other financial institutions and government partners
- Evaluate intelligence sources using measures of performance and measures of effectiveness
- Coordinate and produce strategic, operational, and tactical intelligence products for business units, technical teams, and executive stakeholders
- Provide situational awareness on current threat landscape and maintain knowledge of adversary activities including geopolitical implications and TTPs to brief varying teams
- Assess emerging threats against our operational environment and work in partnership with our security teams for detection, mitigation, and remediation efforts
- Perform trend and correlation of cyber intelligence for recommendation-based countermeasures
- Support and engage in incident response investigations
- Perform basic network security analysis in support of intrusion detection operations, including the development and enrichment of indicators used to enhance network security posture
- Review other analysts work and provide mentorship and guidance
Experience:
- 6-10 years of direct cyber threat intelligence experience
- 5 years of progressive experience in information security (cyber security) field, preferable in Threat Intelligence
- Understanding of intelligence lifecycle and risk management
- Knowledge of fundamentals of threat actors’ TTPs
- Understanding of IOC validation practices and sources
- Familiarity with MITRE ATT&CK framework and mapping
- Geopolitical knowledge and potential impacts to the financial sector
- Excellent interpersonal and relationship management skills
- Individual contributor whilst also contributing to a small team
- Self-motivated with ability to work with minimal supervision
- Demonstrated strong writing skills; ability to convey complex technical and non-technical concepts
Qualifications/Certifications:
- Bachelor’s Degree in Cybersecurity studies, Intelligence Studies, International Relations, Economics, Computer Science, or related discipline
- Security certification such as SANS GIAC (or equivalent) ideally GCTI or working towards certification (or equivalent)
- Experience with threat intelligence and SOC/CIRT interaction
- Experience with Threat Intelligence Platforms
- Experience with threat intelligence vendors
- Experience with private-public information partnership organizations
- Ability to work on-site at least twice a week in London and/or participate in local intelligence sharing groups
Desired Skills:
- Financial sector experience
Our commitment to employees:
We are a small company with a big mandate, so every person is essential to our success. We are also committed to employing and retaining the most talented and dedicated people.
What makes us interesting goes beyond our competitive salaries and great benefits. Our work environment is designed around quality outcomes, not output. The FX market would cease to function without our services, and we take pride in being responsible for keeping it running smoothly.
We are different from other financial institutions in that we have a flatter and more transparent structure with accessible leadership. You will be seen, heard and empowered to develop your career.
We are a purpose-driven organization, with an inclusive culture that focuses on doing what is right. The well-being of our people is as important to us as the resilience of our systems. In addition to encouraging our people to ‘locate for their day,’ we run a range of initiatives that support employees’ sense of belonging and physical, emotional and mental well-being.
Our extensive benefits for employees typically include:
- Vacation/annual leave: 25 days in UK/Asia 3 life days, 23 in US 3 life days
- Private medical and dental cover and life insurance
- Generous pension contributions in the UK and Asia; matching 401(k) in the US
- Paid volunteer days
- ‘Locate for your day’ hybrid working – 2 days a week in office.
- Access to Discover – our learning platform with 1000 courses from LinkedIn Learning.
- Paid parental leave / Coaching and support services
- Career development / LinkedIn Learning
- ‘Heads down days’ with no meetings on the last Friday of every month
- Wellbeing / Mental health support
- Diversity Council / Affinity groups (Women’s Forum, Black Employee Network, Pride Network, Parents & Caregivers Network, Sustainability Network)
- Social events
Awards:
- The Sunday Times Best Places to Work 2023 & 2024 / Big Company / The Sunday Times Awards
- Third place in Britain’s Healthiest Workplace 2022 / Medium Company / Vitality Awards