Intelligence Production Lead
Lead the end-to-end threat intelligence production pipeline at Cloudflare, managing schedules, quality gates, editing, and publication of reports and blogs. Requires 7+ years combined experience in technical writing, intelligence analysis, and cybersecurity, plus leadership in editorial/production functions.
About the job
Key Responsibilities
- Own the end-to-end intelligence production pipeline for intelligence reports, blog posts, briefing content, and technical documentation related to cyber threats and security research.
- Set and manage the production schedule and release calendar, coordinating across researchers and analysts to prioritize intelligence products.
- Serve as the final quality gate before customer-facing publication, running fact-check, technical-accuracy, and editorial review cycles.
- Write, edit, and publish high-quality intelligence content, translating raw researcher notes and technical analysis into accessible narratives.
- Develop, maintain, and enforce style guides, templates, classification markings, and source-handling standards for threat intelligence publications.
- Review and refine threat research content to ensure clarity, consistency, technical precision, and adherence to editorial standards.
- Mentor and coach technical writers and analysts on writing craft, intelligence tradecraft, and reporting standards.
- Collaborate with analysts and external partners to contextualize intelligence findings and communicate them effectively.
- Partner with marketing, design, PR, and communications teams to amplify intelligence content and develop a cohesive security narrative.
Requirements
- Minimum 5 years of experience in a threat intelligence role within the Five Eyes (FVEY) community.
- 7+ years of combined experience across technical writing, cybersecurity research, intelligence analysis, or a related field.
- Minimum 3 years of technical copy editing experience.
- Demonstrated experience leading or managing a threat intelligence reporting, editorial, or production function.
- Strong ability to craft clear, concise, and engaging technical content for technical defenders to executives.
- Experience collaborating with cybersecurity researchers and analysts, with strong understanding of intrusion analysis, incident response, malware, adversary TTPs, and network defense strategies.
- Ability to use researcher notes and raw analysis to author articles about threats and campaigns.
- Understanding of geopolitical issues and their impact on cyber threats.
- Familiarity with cyber threat intelligence frameworks such as the Cyber Kill Chain, MITRE ATT&CK, and the Diamond Model.
- Familiarity with specific threat actor groups, their operations, and TTPs.
- Experience with OSINT research and intelligence collection methodologies.
- Background in intelligence or criminal investigation reporting.
- Experience working in a threat intelligence or SOC environment.
- Demonstrated OPSEC awareness and experience with secure handling of sensitive information.
- Strong research, proofreading, and editing skills with keen attention to detail.
- Experience communicating with internal teams on style, grammar, and voice.
- Strong collaboration and leadership skills.
- Excellent project management and organizational skills.
- Proficiency in Google Suite and content management systems (e.g., WordPress, Jira).
- Bachelor's degree in English, Journalism, Cybersecurity, Computer Science, or related field (or equivalent experience).
Nice-to-Haves
- Experience using AI and LLM tools to accelerate research, drafting, editing, and intelligence production workflows.
- Experience leading or managing a team of threat intelligence technical writers.
- Certifications such as CISSP, GIAC GCTI, or similar.
- Portfolio of published, public-facing threat intelligence (bylined reports, advisories, or blog posts).
- Experience presenting threat research at industry conferences (e.g., Black Hat, DEF CON, RSA, FIRST, or SANS CTI Summit).
- Familiarity with threat intelligence platforms (TIPs) and structured threat-sharing standards.
Skills
Threat Intelligence, Technical Writing, Cybersecurity, Mitre Att&Ck, Cyber Kill Chain, Diamond Model, Osint, Ttps, Intrusion Analysis, Incident Response, Malware Analysis, Opsec, Jira, WordPress, Google Workspace
Similar jobs
Technical Writing jobsLeads technical content, education, and enablement programs that help customers, partners, Sales, Sales Engineering, and Customer Success adopt and communicate cybersecurity products. Requires 5+ years in cybersecurity or a related technical customer-facing function, plus strong writing, presentation, and training skills.
Leads knowledge governance and vendor-focused training and certification for risk operations, managing content writers and influencing federated teams without direct authority. Requires 7+ years in knowledge management, enablement, or operational training, ideally in regulated or outsourced environments.
Owns the end-to-end enablement content system for a SaaS company, including governance, instructional design, Help Center accuracy, release materials, and measurement. Requires 5–7+ years of experience, strong writing, systems thinking, and the ability to influence cross-functional contributors without formal authority.
Leads day-to-day customer education content operations, coordinating instructional designers, stakeholders, workflows, quality reviews, AI-enabled processes, and reporting. The role requires at least five years of relevant experience, strong project management and digital learning expertise, and the ability to coach or lead a content team.
Leads the design of annotator training and screening systems, establishing assessment methodology and using production data to improve learner readiness and hiring decisions. Requires 5+ years of professional experience, including 2+ years in instructional design, curriculum, assessment, or related EdTech work.