Logo for Lexia Learning

Counter-Threat Intelligence Engineer

Role overview

Qualifications

  • 5+ years of progressive cybersecurity experience
  • Certified Ethical Hacker (CEH) certification preferred
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field preferred
  • Proven working knowledge of the cyber kill chain and MITRE ATTCK

Responsibilities

  • Collect, analyze, and operationalize strategic, tactical, and operational threat intelligence
  • Perform adversary-focused research and ethical hacking activities to validate exposures
  • Partner with Security Operations to create, tune, and validate detections and response workflows
  • Produce concise threat intelligence reports for various audiences

About the company

Lexia Learning logo

Lexia Learning

E-Learning / EdTech

Lexia believes that strong literacy foundations have impact far beyond the classroom—that they are essential to our ability to communicate, express ourselves, and engage with the world around us. We believe everyone has a right to literacy, and that as educators, we have an obligation to deliver. We believe every student deserves to be taught literacy in a way that works for them, no matter who they are, where they live, what level they are at, and what learning challenges they face. We believe every teacher deserves the support they need to teach literacy confidently and effectively. We know that literacy is fully within reach for the vast majority of learners (both students and teachers) when instruction is based on the science of reading—with sound methodology; with engaging experiences supported by innovative, committed experts; and with a focus on the value of each individual learner. We’re Lexia. We’re all for literacy because literacy can and should be for all.

Company details

IndustryE-Learning / EdTech
Company size501 - 1000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Job Overview:

Cambium Learning Group is seeking a Counter-Threat Intelligence Engineer to enhance the organization’s ability to identify, understand, and counter cyber threats that could impact our learners, educators, associates, platforms, data, and business operations. This role combines threat intelligence, ethical hacking, exposure validation, adversary emulation, and security engineering to turn emerging threat information into actionable defenses. The engineer will work closely with Security Operations, IT Operations, Risk, Legal Compliance, Product, Engineering, and business stakeholders to help reduce attack surface, improve detection logic, support incident response, and translate technical findings into clear recommendations. The ideal candidate brings hands-on offensive security experience, exceptional analytical judgment, and the ability to communicate threat context in a way that drives practical remediation and measurable risk reduction.

Job Responsibilities:

  • Collect, analyze, and operationalize strategic, tactical, and operational threat intelligence from trusted internal and external sources, including indicators of compromise, adversary tactics, techniques, and procedures, emerging vulnerabilities, and targeted threat activity.
  • Perform adversary-focused research and ethical hacking activities, with authorization, to validate exposures, identify likely attack paths, and recommend defensive improvements across endpoints, cloud services, applications, identity platforms, networks, and third-party integrations.
  • Partner with Security Operations to create, tune, and validate detections, playbooks, threat hunting hypotheses, and response workflows in data log pipelines, SIEM, XDR, EDR, vulnerability management, and related security tools.
  • Support Continuous Threat Exposure Management efforts by helping scope assets, discover exposures, prioritize findings based on business risk, validate exploitability, and coordinate mobilization of remediation activities with IT, infrastructure, engineering, and business owners.
  • Produce concise, actionable threat intelligence reports, briefings, and technical recommendations for audiences ranging from security analysts to senior leadership, emphasizing relevance, impact, urgency, and practical next steps.
  • Contribute to incident response investigations by enriching alerts with threat context, malware or phishing analysis, infrastructure research, attack timeline reconstruction, and lessons learned.
  • Maintain awareness of threat actor tradecraft, vulnerability exploitation trends, cloud and identity attacks, education-sector threats, data protection risks, and changes in attacker use of automation and artificial intelligence.
  • Use independent judgment to make recommendations on defensive priorities, detection improvements, risk acceptance considerations, and escalation paths while staying aligned with Cambium policies, standards, and governance expectations.

Job Requirements:

  • 5+ years of progressive cybersecurity experience, with at least 2 years in threat intelligence, ethical hacking, penetration testing, detection engineering, security operations, incident response, vulnerability management, or a closely related role.
  • Certified Ethical Hacker (CEH) certification is highly preferred; similar hands-on offensive security or threat intelligence certifications may be considered, such as OSCP, GPEN, CompTIA PenTest+, CPENT, eJPT, GCTI, CTIA, or equivalent practical experience.
  • Proven working knowledge of the cyber kill chain, MITRE ATT&CK, common attack techniques, malware and phishing behaviors, cloud and identity threats, vulnerability exploitation, attacker infrastructure, and defensive countermeasures.
  • Hands-on experience with security tools and data sources such as SIEM, XDR/EDR, vulnerability scanners, threat intelligence platforms, cloud security tools, identity logs, endpoint telemetry, network telemetry, and ticketing/workflow platforms.
  • Ability to write clear threat intelligence summaries, detection recommendations, executive briefings, remediation guidance, and technical documentation that can be acted on by cross-functional teams.
  • Experience conducting authorized security testing, adversary emulation, attack surface analysis, detection validation, or threat hunts in a disciplined, evidence-based, and policy-aligned manner.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field preferred; equivalent professional experience and certifications may be considered.
  • High judgment, strong ethics, discretion with sensitive information, collaborative communication style, and commitment to protecting confidential, proprietary, student, customer, associate, and business data.

Preferred Qualifications:

  • Experience in education technology, SaaS, cloud-first, remote-first, or regulated environments.
  • Experience building threat hunting content, Sigma/YARA rules, KQL/SPL queries, detection-as-code, or automation for enrichment and triage.
  • Familiarity with scripting or automation using Python, PowerShell, Bash, APIs, or SOAR-style workflows.
  • Working knowledge of data privacy, secure software development, third-party risk, and compliance frameworks such as ISO 27001, SOC 2, NIST CSF, or NIST SP 800-series guidance.

To learn more about our organization and the exciting work we do, visit www.cambiumlearning.com 

Remote First Work Environment 

Our Remote First approach gives employees the flexibility and trust they need to effectively balance work with life. It creates a culture in which all employees are valued and where success is measured in results. It allows us to work collaboratively, inclusively and for greater positive impact, regardless of our individual locations.

If you will be working remotely, either occasionally or on a permanent basis, you must have a reliable internet connection through a cable or fiber-optic broadband service with minimum speeds of 10 Mbps download and 5 Mbps upload.

The successful candidate will be expected to actively participate in video-based interviews during the recruiting process and ongoing virtual meetings with their camera on, as part of their role. To maintain confidentiality and ensure a fair evaluation process, the use of note-taking tools, reference materials, or AI-powered tools (including generative AI, language models, or similar technologies) during interviews or other selection activities is prohibited unless prior written approval has been obtained from the People Experience team. If you require an exception for medical, accessibility, or other reasons, please contact your Talent Acquisition team member to discuss accommodations in advance.

As part of our Remote-First benefits, Cambium offers reimbursement to help cover the cost of setting up your home or remote office.

An Equal Opportunity Employer

We are dedicated to fostering a culture that celebrates unique backgrounds, ideas, and experiences. All qualified applicants will receive consideration for employment without discrimination on the basis of race, color, age, religion, sex (including pregnancy, gender, gender identity/expression, or sexual orientation), national origin, protected veteran status, disability, or genetic information (including family medical history).

We will provide reasonable accommodations for qualified individuals with disabilities.  You may request an accommodation during the recruiting process with your Talent Acquisition team member.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Cyber Threat Intelligence Analyst Related jobs

Other jobs at Lexia Learning

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.