Women in Cyber Threat Intelligence: No Typical Path

- Sixteen women share how they built careers in CTI, and almost none of them followed the same route.
- Rebecca Taylor, Cheryl Biswas, and Maril Vernon came from research, freelance security work, and pentesting, proof that a CTI career doesn't require a single "correct" entry point.
- Across all 16 stories, three qualities keep showing up: comfort with uncertainty, strong communication, and curiosity that predates any formal CTI title.
- Several were trusted with real responsibility before their resumes "caught up," a pattern hiring managers should start looking for.
Ask most people to picture someone who works in cyber threat intelligence (CTI), and you get a fairly specific image. Computer science degree. A few years in a SOC. A move into intelligence once they'd proven themselves on the technical side.
Over the past few weeks, I watched the interviews behind our new eBook and listened to 16 women working across threat intelligence describe how they entered the field. Their experiences carry lessons for anyone considering a career in CTI, as well as the leaders hiring and developing its future talent.
Almost none of them followed a conventional career path.
One has a degree in English and creative writing. One spent 10 years at home raising her children. One was a barista, a wedding planner, and an IT recruiter before she ever touched a security tool. They now track ransomware groups, run threat intelligence functions, and build companies.
Together, their stories reveal a much wider set of entry points into CTI. Three of them are excerpted here. The eBook has all 16.
Cyber Threat Intelligence Has Many Entry Points
Rebecca Taylor: from personal assistant to threat hunter.
Rebecca Taylor has a degree in English and creative writing. She was headhunted into SecureWorks as a personal assistant, making tea, booking meeting rooms, and doing expenses. Within two weeks, she could see what the industry might offer her.
"I really felt that if I worked hard, I could be someone in cyber if I wanted to. And in essence, that's how I've lived my career, by seizing those opportunities, seizing those moments and pushing myself.”
She worked her way up to the company's first incident command team, where she sat alongside major ransomware incidents. Today she runs personas across underground forums at Sophos X-Ops, tracking access brokerage, data leaks, and new ransomware groups. She describes it as a long way from booking meeting rooms.
"That's how I've lived my career, by seizing those opportunities, seizing those moments and pushing myself." — Rebecca Taylor, Researcher, Sophos X-Ops Counter Threat Unit
Cheryl Biswas: from 10 years at home to hacker conference regular.
Cheryl Biswas spent 10 years out of the workforce raising her children. When she came back, she started at the bottom of a tiny managed services company, doing whatever needed doing. Then she read an article about Stuxnet, and a political science degree she had set aside for years suddenly made sense.
"I discovered the Kaspersky newsletter, and one of the first ones I read was about Stuxnet. I have a degree in poli-sci, and suddenly it was this aha moment of where tech and geopolitics and everything collides. Now I know what I want to do. This actually exists.”
She taught herself information security by reading everything she could find and asking questions. People in the community started inviting her to things. She turned up at a hacker conference in Indianapolis describing herself as a "middle-aged housewife." No one blinked. She now has a wall of conference lanyards behind her, most of them speaker badges. Today, she works as a cybersecurity researcher.
"Now I know what I want to do. This actually exists." — Cheryl Biswas, Cybersecurity Researcher
Maril Vernon: from wedding planner to penetration tester.
Maril Vernon came into cybersecurity cold at 30. Before that, she worked in marketing; before that, she was a barista, a wedding planner, and an IT recruiter. She re-enlisted in the military to get into a cyber unit, then landed a governance, risk, and compliance (GRC) role. When a penetration testing job opened, she lacked the technical skills for it.
She asked for the opportunity anyway.
“We both know I’m not the pen tester you wish you had today, but give me a shot, and a year from now you’ll have the one you wish you had.”
She got the job, and from there she advanced through pentesting, red teaming, application security, and consulting, a path that led to her current role as Horizon3's field CISO.
"Give me a shot, and a year from now you’ll have the one you wish you had." — Maril Vernon, Field CISO, Horizon3
Rebecca, Cheryl, and Maril started in very different places and built successful CTI careers on experience and skills that don't fit the profile most hiring managers screen for.
The Skills That Travel
Sixteen completely different starting points. So what do they all have in common?
Curiosity comes up first, and it's active: Mariana Mazi, a senior cybersecurity engineer and penetration tester at CERTH/ITI, reads about a new CVE and then builds a VM to try it herself, so she understands how a vulnerability behaves before encountering it during an assessment.
Amanda Capobianco, CTI Manager at Richemont, started there as an intern before the company had a CTI function, and puts it more bluntly.
"Everyone harps on the technical side of things, but really those curiosities and wanting to keep learning, being a really good listener and a really good problem solver. Soft skills like that really set you apart from everyone that has all the technical qualifications.”
Comfort with uncertainty comes next. Threat intelligence rarely provides a complete picture, and several contributors made the same point: acknowledging uncertainty and then investigating it builds greater trust than confident guessing.
The third quality often surprises people: communication. Rachel Mansson, Associate Director of Cyber Security Threat Intelligence at Deakin University, is building that function from scratch, and she thinks the biggest misconception about the field is that people need a technical background to enter it.
"That misconception that you need to be technical. Everything that you do in threat intelligence is communication and stakeholders, because it's all great to have all this intel coming in, but if we can't translate it into the business context, what's the point?”
"That misconception that you need to be technical. Everything that you do in threat intelligence is communication and stakeholders, because it's all great to have all this intel coming in, but if we can't translate it into the business context, what's the point?" — Rachel Mansson, Associate Director of Cyber Security Threat Intelligence, Deakin University
What This Means for Hiring
Taken together, these 16 women's stories carry a clear lesson for anyone building a team.
Their unusual backgrounds stand out, but the more consequential pattern appears in what happened next. In many cases, somebody gave them responsibility before their résumés reflected every qualification.
Saba Bagheri, now a Cyber Threat Intelligence Manager at Bupa APAC, was early in her CTI career when her manager asked her to build a threat intelligence function from scratch. She had to define the strategy, establish the processes, build the stakeholder connections, and make the case for why any of it mattered. She says it taught her more than inheriting a mature team ever would have.
“One lesson I've carried with me is that great leaders don't just hire experience, they recognize potential. Someone took that chance on me, and it's something I now try to do for others by giving people opportunities before they feel completely ready.”
“One lesson I've carried with me is that great leaders don't just hire experience, they recognize potential. Someone took that chance on me, and it's something I now try to do for others by giving people opportunities before they feel completely ready.” — Saba Bagheri, Cyber Threat Intelligence Manager, Bupa APAC
Alex Keedy, now a Senior Strategic Advisor at Flashpoint, had a mentor at Intel 471 who gave her autonomy on projects she had never worked on and buildouts she had never managed, before her résumé said she was ready. Rebecca Taylor got moved into the Counter Threat Unit by a C-suite executive who, in her words, just saw her.
These were informed bets on potential, and they paid off.
The pattern raises an obvious question about how organizations fill CTI roles. If curiosity, comfort with ambiguity, and the capacity to translate intelligence into business action are core skills, then a résumé screen built around technical background is filtering for the wrong thing. It will reliably surface people who look the part. It will also miss the person whose two years of proof live in self-directed work.
Every woman in the eBook got in because somebody decided to find out what she could do.
Meet the Community Behind Women in CTI
Women in CTI grew from a pattern its founders kept observing. Mary D'Angelo, Senior Solutions Lead at Filigran, co-founded the initiative with Einat Argon, Customer Success Manager at Filigran, after seeing how few women were contributing in the intelligence-sharing channels and communities they participated in.
This article shares three of their stories. The eBook includes 13 more, including a counterterrorism analyst who tracked a Russian influence operation across a decade of Olympic competitions, a game developer who now leads threat intelligence and the red team at Canva, and a recruiter who went on to negotiate with ransomware crews.
Read all 16 stories in our new eBook, Women in CTI: The Careers, Lessons, and Stories Shaping Cyber Threat Intelligence.
And, join the conversation over in the #women-in-cti channel on the Filigran community Slack. See you there.
続きを読む
関連トピックとインサイトをご覧ください

OpenCTI and Google SecOps SOAR: Threat Intel Flows Both Ways

OpenAEV v3: Adversarial Exposure Validation Goes Autonomous with Attack Chaining
