By joining the National Student Clearinghouse, you can be sure that the work you do now will help shape the future of education and the workforce in the U.S. As the trusted source for higher education data since 1993, the Clearinghouse is the leading provider of transcript and data exchange services, automated enrollment and degree verifications, learner insights and research, and compliance solutions for schools, businesses, and learners nationwide. As a 501(c)(3) nonprofit organization, the Clearinghouse works with nearly 3,600 postsecondary institutions to meet their compliance needs and with thousands of high schools and districts to provide continuing collegiate enrollment, progression, and completion statistics about their alumni. In addition, the Research Center publications inform policymakers and business leaders about student educational pathways. Using our unique combination of data, analytics, and software to drive our mission, security and privacy is paramount. Join us as we continue to invest in our talent and new advanced technologies to unlock the power of data on behalf of all learners.
About the Role:
The Technical Specialist, Threat Operations serves as a senior operational leader and key partner within the Cyber Operations team, acting as the functional second-in-command across threat operations activities. This role is responsible for building, scaling, and sustaining a comprehensive threat operations program that translates threat and exposure signals into actionable insights and business risk decisions.
This position combines hands-on operational oversightincluding detection, triage, investigation, and responsewith ownership of strategic program elements such as threat intelligence, lifecycle governance, and Continuous Threat Exposure Management (CTEM). The role also requires leadership through influence, driving consistent execution, talent development, and high-quality outcomes across analysts, partners, and stakeholders.
The Technical Specialist, Threat Operations is expected to maximize AI-assisted and agentic AI workflows while maintaining human accountability, secure data handling, and audit-ready evidence. All outputs must remain defensible, traceable, and aligned with enterprise governance standards.
Currently, this is a remote-first position, and this position may be required to periodically work on-site at our office and the frequency would depend on the department/division's requirements. Therefore, candidates must either reside within a reasonable distance to commute to our office or be willing to travel to our office in Herndon, when required.
How You Contribute:
Demonstrate the Clearinghouse's core competencies: Customer Focus, Optimizes Work Processes, Collaborates, Communicates Effectively, and Be Open and Authentic.
Oversee detection, triage, and validation of security alerts, ensuring timely and evidence-based disposition.
Translate technical findings into clear risk-based recommendations and actionable next steps.
Serve as escalation lead during high-severity incidents, ensuring proper scoping, documentation, and remediation to closure.
Develop and mature the threat operations program roadmap, including CTEM strategy and operating model.
Perform business-centric threat modeling to align adversary activity with enterprise risk and impact.
Define governance frameworks, including prioritization logic, escalation criteria, and executive reporting.
Design and continuously improve repeatable workflows, including AI-assisted triage, investigation, and reporting processes.
Establish and manage key performance indicators (e.g., MTTD, MTTR, detection quality, noise reduction).
Maintain playbooks, investigation templates, and escalation workflows to ensure consistency and audit readiness.
Drive continuous improvement of detection fidelity through tuning and feedback loops.
Implement AI-assisted workflows with clear human-in-the-loop validation and decision points.
Ensure secure handling of sensitive data and alignment with enterprise AI governance policies.
Validate AI outputs for accuracy and reliability and mitigate known risks such as hallucinations, bias, or incomplete context.
Harden AI processes against adversarial threats (e.g., prompt injection, data leakage).
Lead the threat intelligence lifecycle, including requirements, collection, analysis, dissemination, and feedback.
Translate intelligence into actionable outputs such as threat hunts, detection priorities, and control validation.
Deliver executive-ready threat assessments with clear sourcing and confidence levels.
Establish operating rhythms and performance expectations with external security partners.
Ensure alignment with MITRE ATTandCK coverage and measurable detection and response outcomes.
Integrate partner outputs into internal workflows, ensuring accountability and closure of findings.
Lead investigations involving cloud control plane threats (such as AWS and OCI), focusing on identity and configuration risks.
Correlate cloud, endpoint, identity, and network signals to prioritize remediation based on risk.
Partner with engineering teams to validate remediation and risk acceptance actions and decisions.
Coordinate with incident response, engineering, and business stakeholders to drive remediation.
Integrate third-party risk insights into threat analysis and recommendations.
Partner with architecture and assurance teams to improve long-term security controls.
Position may be required to perform other duties as required. These essential functions are representative of those that must be met by an employee to successfully perform the job. Reasonable accommodations will be made to enable individuals with disabilities to perform these essential functions.
What You Bring to the Table:
Bachelors degree in Cybersecurity, Computer Science, IT, or any related field. A combination of education and experience including military service will also be considered.
Current, active certification in one or more of the following is required: CISSP, CISM, GIAC, CySA+, Microsoft Security, or cloud security certifications.
10 years of direct experience in cybersecurity operations, incident response, or threat analysis.
Experience investigating cloud security issues (AWS and/or OCI).
Hands-on experience with AI-assisted security workflows and governance-aligned practices.
Experience developing threat intelligence or CTEM-aligned programs.
Experience managing external security partners and service delivery (e.g., MDR/MSSP), including performance outcomes, SLAs, and continuous improvement.
Strong knowledge of threat operations, incident response, and investigation methodologies.
Advanced understanding of MITRE ATTandCK framework and detection coverage strategies.
Knowledge of cloud security threats (AWS, OCI), particularly identity and control plane risks.
Understanding of threat intelligence lifecycle and CTEM program implementation.
Knowledge of enterprise AI governance, including generative AI risks and controls.
Ability to build and scale threat operations processes and programs.
Ability to develop metrics and reporting frameworks that drive decision-making.
Experience designing AI-assisted investigation and triage workflows.
Ability to translate technical risk into business-aligned remediation strategies.
Strong decision-