Full-Time

Senior Threat Intelligence Analyst

Updated on 9/10/2026

Trellix

Trellix

1,001-5,000 employees

XDR security platform for threat detection

No salary listed

No H1B Sponsorship

Reston, VA, USA

In Person

The role is on-site at Fort Belvoir, Virginia; the ATS location lists Reston.

US Top Secret Clearance Required

Bachelor's

Category
Cybersecurity (1)
Required Skills
Malware Analysis
Incident Response
Cybersecurity
Vulnerability Analysis
Data Analysis

Get referred to Trellix

See people who can refer or advise you

Requirements
  • Five or more years of intelligence gathering, analysis, and reporting experience.
  • Expertise in cyber threats, attack vectors, detection capabilities, and countermeasures.
  • Experience with open-source intelligence collection methods and tools.
  • Background working within a Security Operations Center to monitor, respond to, and remediate detected issues.
  • Knowledge of organizational incident management processes as they relate to threats and vulnerabilities.
  • Technical knowledge of extended detection and response, endpoint detection and response, endpoint security tools, antivirus, application whitelisting, and threat hunting.
  • High-level comprehension of malware types, detection methods, and analysis techniques.
  • Familiarity with MITRE ATT&CK, D3FEND, the Cyber Kill Chain, and the Diamond Model.
  • Experience identifying and mitigating cyber threats using various detection strategies.
  • Understanding of technical vulnerabilities and their associated risks.
  • Hands-on experience with security information and event management tools, including event correlation and analysis.
  • The candidate must have or be willing to obtain 8140 IAT III and 8140 IASAE II certifications.
  • An active Top Secret SCI clearance is required.
Responsibilities
  • Serve as a cyber threat intelligence subject matter expert and trusted advisor.
  • Integrate with customers' operations-intelligence cycles to inject cyber threat intelligence effectively.
  • Collaborate with Trellix employees, customers, and third parties to support defense of the customer's network and mission elements.
  • Develop information and intelligence requirements and establish associated priorities.
  • Identify intelligence gaps and opportunities to improve intelligence sharing and utility.
  • Create tailored strategies for research, data collection, analysis, and reporting focused on customers' areas of interest.
  • Draft comprehensive responses to customer requests for information and intelligence.
  • Perform all-source research and analysis using Trellix tools, datasets, third-party tools, and open sources.
  • Produce written and oral reporting, including participation in peer review and quality assurance.
  • Map relationships between malicious cyber activity and global events such as geopolitical shifts, natural disasters, and crises.
  • Deliver threat intelligence presentations to diverse customer teams, including technical staff and senior executives.
  • Maintain current understanding of the cyber threat landscape, including advanced persistent threats, motivations, attack vectors, and tactics, techniques, and procedures.
  • Support customer security operations through planning, risk assessment, continuous monitoring, and incident response.
  • Serve as a primary customer interface and become immersed in customer operations.

Trellix provides an extended detection and response (XDR) platform that integrates endpoint, network, and cloud security into a single system. The platform works by using Generative AI and threat intelligence to help security teams detect and respond to cyberattacks across their entire digital infrastructure. Unlike many competitors that offer isolated security tools, Trellix uses an "open" architecture that allows its software to connect with a wide variety of third-party applications and hardware. The company's goal is to provide organizations with a unified, automated defense system that simplifies how they manage and resolve complex security threats.

Company Size

1,001-5,000

Company Stage

Growth Equity (Venture Capital)

Total Funding

$435M

Headquarters

Plano, Texas

Founded

2021

Get referred to Trellix

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • On August 24, 2026, Trellix added Adam Philpott, Michael Alicea, and Tara Flanagan.
  • Joe Chen became CTO in May 2026, accelerating secure AI engineering and roadmap execution.
  • Trellix launched AI data security, SecondSight, and NDR upgrades to monetize GenAI security demand.

What critics are saying

  • Trellix disclosed unauthorized access to its source-code repository on May 8, 2026.
  • Palo Alto Networks, Microsoft, and CrowdStrike are compressing Trellix’s differentiation with bundled AI platforms.
  • Repeated leadership reshuffles signal execution fatigue inside a post-merger company under constant reinvention.

What makes Trellix unique

  • Trellix unifies endpoint, network, email, OT, cloud, and air-gapped defense in one XDR.
  • Its intelligence-led heritage from FireEye and McAfee gives deep threat-intel and incident-response credibility.
  • Joe Chen’s May 2026 AI-native engineering push hardens delivery across complex security products.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

Paid Vacation

Paid Parental Leave

Flexible Work Hours

Growth & Insights and Company News

Headcount

6 month growth

14%

1 year growth

14%

2 year growth

-1%
Yahoo Finance
Aug 24th, 2026
Trellix appoints David Pieterse as COO-GTM and David Soto as CISO to drive growth

Trellix has appointed two senior executives to strengthen its leadership team. David Pieterse joins as Chief Operating Officer for Go-To-Market, bringing over 20 years of enterprise technology experience. He previously served as Chief Revenue Officer at Recorded Future, leading global revenue functions through its acquisition by Mastercard. David Soto has been named Chief Information Security Officer. He will oversee Trellix's enterprise security programme and lead its Customer Zero initiative. The appointments aim to advance Trellix's growth strategy and go-to-market execution. CEO Vishal Rao said Pieterse joins at a pivotal moment as AI transforms the threat landscape, requiring organisations to adopt proactive security responses. Pieterse will focus on translating security innovations into measurable outcomes for customers and partners. The San Jose-based company describes itself as a global leader in intelligence-led cyber resilience.

Trellix
Aug 24th, 2026
Trellix expands leadership team to accelerate growth and cyber resilience.

Trellix expands leadership team to accelerate growth and cyber resilience. Newly appointed cyber veterans advance Trellix's growth initiatives, go-to-market strategy, and intelligence-led cyber resilience SAN JOSE, Calif. - Trellix, the global leader in intelligence-led cyber resilience, today announced the appointments of David Pieterse as Chief Operating Officer - Go-To-Market (COO-GTM) and David Soto as Chief Information Security Officer (CISO). The appointments strengthen Trellix's leadership across go-to-market execution, strategic partnerships, and enterprise security. David Pieterse Joins Trellix as Chief Operating Officer - Go-To-Market Pieterse joins Trellix to lead GTM and accelerate execution across its core strategic growth engines. He will focus on empowering front-line teams with the velocity and clarity to win, translating its innovation into measurable customer value and driving durable, long-term growth. "DP joins Trellix at a pivotal moment, as AI continues to transform the threat actor playbook, demanding organizations adopt a proactive, AI-native security response," said Vishal Rao, CEO, Trellix. "He is uniquely equipped to execute on this market opportunity, building the engine and trust necessary to turn this momentum into sustained growth and resilience for our customers and partners." Pieterse brings more than two decades of enterprise technology and revenue leadership at the intersection of cybersecurity, enterprise software, and data analytics. Most recently, he served as Chief Revenue Officer at Recorded Future, the world's largest threat intelligence company, where he led all global revenue functions through the company's acquisition by Mastercard. Before Recorded Future, he was Chief Revenue Officer at Snow Software, where he built and scaled the company's global revenue organization through its acquisition by Flexera, and SVP of Global Revenue at Kong, Inc. "The cybersecurity market is at a genuine inflection point, and Trellix has the security foundation, threat intelligence, and team needed to lead it," said David Pieterse, COO-GTM, Trellix. "My focus will be on building the strategic relationships and execution mechanisms translating security innovations into measurable outcomes for our customers and partners." David Soto Joins Trellix as Chief Information Security Officer Soto will lead Trellix's enterprise security program, drive its shared resilience transformation, and serve as the executive steward of Trellix's Customer Zero program, exemplifying the defense-grade protection Trellix Inc deliver to customers within its own environment. "David's background in building resilient programs at scale is exactly what Trellix needs to advance our enterprise security mission," said Vishal. "We're adapting our security culture to address the realities of today's threat landscape, and I am confident his leadership will further strengthen our foundation from within." Soto brings more than 25 years of cybersecurity leadership across regulated industries. Most recently, as Head of Infrastructure Security at Amazon, where he scaled a resilient security program across more than 4,000 sites and 30 countries, embedding security into global operations infrastructure from the ground up, including anomaly detection systems protecting employees working alongside automation and robotics at scale. Prior to Amazon, Soto also held positions at Check Point, Optiv, and Pacific Life. He has served on the board of the Orange County CISO Roundtable since 2017. "Cybersecurity leadership today means more than defending a perimeter; it's being a genuine partner to the business, operating with transparency, and building a program the entire team is proud to stand behind," said David Soto, CISO, Trellix. "At a moment when machine-speed adversaries are redefining what resilience requires, I'm energized to join a team already at the frontier of this fight, and I look forward to partnering with them to continue strengthening the hardened foundation our customers rely on." With Pieterse and Soto on board, Trellix's leadership team is focused on what matters most: helping the world's most security-conscious organizations achieve cyber resilience in the face of machine-speed threats. About Trellix Trellix is a global cybersecurity leader delivering intelligence-led cyber resilience to help organizations address the modern threat landscape. Combining AI-native security, operational threat intelligence, and automated detection and response, Trellix provides defense-grade protection at machine speed across on-premises, air-gapped, operational technology, hybrid, and cloud environments. Trellix helps customers anticipate threats, scale effective security operations, maintain business continuity, and adapt their security posture to build resilience and meet the challenges ahead. More at https://trellix.com. Follow Trellix on LinkedIn and X.

Aibots
Aug 24th, 2026
AI-Driven cyber defense explodes: Prevalent AI secures £16.1M as Anthropic deploys Claude Mythos 5.

AI-Driven cyber defense explodes: Prevalent AI secures £16.1M as Anthropic deploys Claude Mythos 5. Today, August 25, 2026, the global cybersecurity landscape is undergoing a massive paradigm shift as artificial intelligence transitions from a speculative defensive asset into the very core of enterprise infrastructure. Organizations are no longer just defending their perimeters; they are re-architecting their entire security stacks around context-aware AI models and identity governance. The AI arms race receives a multi-million dollar capital injection. The financial markets are reflecting this architectural shift. Prevalent AI has successfully secured 16.1 million British pounds in its latest funding round, capital earmarked to accelerate its proprietary AI context engine. By understanding the deep context of enterprise data flows, Prevalent AI aims to cut through the noise of legacy security alerts to deliver highly precise threat detection. Simultaneously, AI pioneer Anthropic has expanded the capabilities of its Claude Mythos 5 model. Engineered specifically for cyber defense, Claude Mythos 5 allows security operations centers (SOCs) to automate complex threat hunting and incident response workflows at machine speed, signaling a new era of automated defense. Securing the ai-first enterprise. As enterprises rush to adopt these generative technologies, identity governance is emerging as the primary battleground. In response, Oleria has announced a strategic partnership with Happiest Minds. Together, the two firms will deliver modern identity governance solutions designed explicitly for AI-first enterprises, ensuring that automated agents and employees alike have tightly controlled, context-specific access rights. This focus on resilience is also driving global expansion. Inspira Enterprise has officially expanded its operations into Australia, aiming to accelerate AI-driven cybersecurity and digital resilience for enterprises across the continent. This move coincides with an industry-wide realization, highlighted by financial platforms like Maya, that robust cybersecurity has transitioned from a backend IT concern into the single most critical driver of customer trust. Corporate shakeups and market records. The financial strength of the cybersecurity sector is breaking records. Palo Alto Networks (PANW) continues to hit new historical highs on the stock market, driven by its platformization strategy and robust enterprise demand. To navigate this rapid growth, major security vendors are reshuffling their executive ranks. Trellix has announced a dual leadership appointment, naming David Pieterse as Chief Operating Officer of Go-To-Market (COO-GTM) and David Soto as Chief Information Security Officer (CISO). Meanwhile, OpenAI has signaled its aggressive enterprise expansion by appointing tech veteran Dali Rajic as its new Chief Revenue Officer (CRO). The bottom line. * AI Defense Funding: Prevalent AI's 16.1 million pound funding and Anthropic's Claude Mythos 5 rollout prove that context-aware AI is the new standard in cyber defense. * Identity is Key: The partnership between Oleria and Happiest Minds highlights that securing AI-first enterprises requires a fundamental redesign of identity governance. * Executive Shifts: High-profile moves at Trellix and OpenAI showcase a hyper-competitive market scrambling to capture enterprise market share. * Trust Equals Security: Enterprise digital resilience, championed by expansion efforts from Inspira and trust initiatives from Maya, is now a primary business differentiator. Stay Connected for Daily Security Intelligence Follow Aibots Sdn Bhd to get the latest breaking cybersecurity reports and threat analysis delivered daily. Aibots Sdn Bhd | [Beyond Future]

Trellix
Aug 10th, 2026
Accelerating Trellix's transformation with AI-native security engineering.

Accelerating Trellix's transformation with AI-native security engineering. By Joe Chen · August 10, 2026 Cybersecurity is at an inflection point. Recent Trellix research shows a 67% increase in AI-driven APT campaigns and a 300% increase in the monthly attack cadence, underscoring a fundamental shift in the speed and scale of today's threats. These increases have made one thing clear: incremental improvement isn't enough. Recent examples of OpenAI and Anthropic models breaking out of sandboxes further reinforce the new "machine speed" the cybersecurity industry is facing. Trellix is meeting this challenge head-on by enhancing how Trellix build, secure, and optimize its technology through AI-native security engineering. When I joined Trellix as CTO in May, the stakes couldn't have been clearer. Frontier AI models were changing traditional time-to-exploit, compressing it across the industry and forcing vulnerability management to evolve alongside it. Simultaneously, Trellix was navigating its own security matter that required a thorough, expedited review of its codebase, architecture, and supply chain. So Trellix leaned in all the way, moving from experimental AI-enabled pilots available to a few teams to a standardized AI-enabled framework for all teams. Trellix embraced frontier AI models to review its entire codebase on an accelerated timeline, and Trellix embedded AI-powered auditing directly into its development pipelines, so potential vulnerabilities surface earlier in the development process. What began as a response to an immediate challenge has become a catalyst for fundamentally elevating its engineering standards. The result is a hardened foundation and an evolved engineering philosophy embracing the modern landscape. Driving innovation with a secure AI adoption framework. With high-performance AI-native security engineering as its foundation, Trellix is guided by the principles of accelerated, intentional, and responsible adoption of leading-edge technology, where security isn't a constraint on innovation but the condition that makes it sustainable. Here are a few examples of how Trellix is putting shift-left AI security into practice: * Trellix has retooled its engineering system around AI, not as a layer on top of existing processes, but woven into how Trellix build. Features will ship in smaller, highly validated increments. * AI capabilities and frontier models now identify and remediate vulnerabilities earlier in the software development lifecycle. Trellix is embracing a simplified architectural philosophy: AI maintains visibility throughout the development cycle, and secure-by-design principles remain at the forefront. * Trellix has also established strategic partnerships with two leading AI companies: Anthropic and LangChain. These aren't just vendor agreements; they're foundational alignments for its engineering and research teams. These partnerships grant Trellix privileged access to cutting-edge models, frameworks, observability, and roadmaps as they evolve, and its spend commitment with Anthropic, signed in May, signals the depth of its investment in this space. * Trellix is embracing both closed and open-source AI models for various tasks, depending on which is best suited, adapting to the new pace of AI innovation. AI amplifies what its engineering teams have always prioritized, bringing continuous intelligence and real-time visibility to its rigorous security practices, so its engineers can direct more of their expertise toward innovation, architecture, and customer outcomes. Leading the next era of cyber defense. Trellix has a lot of work to do, but Trellix is at the beginning of what I believe will be a defining chapter, not just for Trellix, but for the broader industry. The organizations leading the next era of cyber defense aren't the ones who add AI to their slide decks. They're the ones willing to rebuild their engineering foundations to make AI native to how they think, build, and protect. Its mission is clear: set the standard for high-performance engineering, responsible AI adoption, and the kind of customer trust that can be earned only through consistent execution. The threat landscape will keep evolving. So will Trellix.

Trellix
May 19th, 2026
Trellix appoints Joe Chen as Chief Technology Officer.

Trellix appoints Joe Chen as Chief Technology Officer. Cybersecurity veteran to lead mission-critical technology roadmap and harden R&D processes for the modern threat landscape SAN JOSE, Calif. - Trellix, a global leader in intelligence-led cyber resilience, today announced the appointment of Joe Chen as Chief Technology Officer. Chen will advance Trellix's mission-critical cybersecurity vision, strengthen engineering execution, and lead the next phase of the company's technology roadmap. Chen brings more than 25 years of experience driving product portfolio transformation for global cybersecurity providers. Chen will partner closely with Alex Au Yeung, Chief Product Officer, to deliver next-generation security technology for the era of AI and frontier models. The duo shares a successful history of product portfolio transformations, evolving complex, multi-product offerings into unified solutions that advance customer outcomes through clear roadmaps and rapid development cycles. "Joe is a proven technology leader who excels at simplifying complex solutions and delivering innovation at scale," said Vishal Rao, CEO of Trellix. "He brings the cybersecurity expertise, disciplined execution, and AI-forward disposition required to relentlessly strengthen our security posture and R&D processes for the modern world. I also want to thank Steve Tait for his steady leadership as interim CTO and for ensuring continuity during this transition." Chen joins Trellix at a critical moment, with a priority focus on optimizing the processes used to securely deliver high-quality innovations to the market. His leadership will reinforce the systems and practices that underpin secure product development, ensuring Trellix remains at the forefront of cyber resilience. "Cybersecurity is at an inflection point, with today's threat landscape and the rise of AI and frontier models demanding uncompromising security in everything we do," said Chen. "I'm thrilled to be joining Trellix at this pivotal time, with a sharp focus on hardening our R&D engine and applying a continuous improvement mindset to engineering operations, so we deliver the most secure, reliable, and innovative solutions to our customers at speed." Prior to Trellix, Chen was an Operating Partner at Crosspoint Capital, focusing on engineering transformation. He previously held senior leadership roles at Broadcom's Symantec Enterprise Division and Carbon Black, overseeing large-scale integration and security product development. Chen is a founding member of the Cyber Threat Alliance and holds more than 55 U.S. patents. About Trellix Trellix is a global cybersecurity company delivering intelligence-led cyber resilience for security-conscious organizations at any stage of their journey. Transforming over 30 years of threat intelligence into high-fidelity detections and automating AI-driven detection and response across cloud, on-premises, air-gapped, and operational technology environments, Trellix helps customers adapt to the constantly evolving threat landscape. More at https://trellix.com. Follow Trellix on LinkedIn and X.