Joseph Wood
Cybersecurity Researcher | Threat Intel | Malware Reverse Engineering
- Role
- Principal Engineer - Cyber Threat Intelligence at HP
- Location
- Dallas-Fort Worth, TX, US
- LinkedIn followers
- 500 followers
About Joseph Wood
I’m a hands-on Cyber Threat Intelligence Engineer and DFIR practitioner with over 15 years of experience building and leading advanced CTI operations, malware analysis programs, and deception frameworks.My work blends deep technical expertise with leadership and program architecture, from designing enterprise-scale Threat Intelligence Platforms and MISP/SOAR integrations to developing Golang and Python tools for malware emulation, forensic automation, and IOC enrichment.I’ve built and led global CTI programs, created advanced forensic tooling, integrated dark-web and open-source intelligence pipelines, and engineered deception systems that proactively identify adversary activity before impact. I enjoy bridging the gap between intelligence and engineering; creating practical, scalable tools that empower defenders and shorten response time.Specialties:• Threat Intelligence Architecture & Program Development • Digital Forensics & Incident Response (DFIR, Malware Reversing, Memory Analysis)• Deception Frameworks & Canary Token Engineering• Custom Tool Development (Golang, Python, C++, REST APIs)• SOAR & Automation Engineering (Splunk, Elastic, Phantom, Turbine)• Dark Web Monitoring, OSINT, and Threat Actor Attribution
Experience
Principal Engineer - Cyber Threat Intelligence
Jun 2019 — Present · Dallas-Fort Worth, TX, US
Built and lead Hewlett Packard’s enterprise Threat Intelligence Program, responsible for strategy, architecture, tooling, and operations supporting Security Operations, Incident Response, Fraud, and executive leadership. Designed and operationalized the function from inception, establishing collection, analysis, and intelligence dissemination workflows.Produce and present executive threat briefings, risk assessments, and strategic intelligence on APT, cybercrime, fraud, and emerging threat activity.Conduct active intelligence collection across OSINT, dark web forums, breach sources, infostealer logs, and adversary infrastructure. Monitor for data leaks, phishing, brand abuse, and threat actor campaigns targeting HP.Perform malware analysis and adversary capability research to validate exploit techniques across Windows, Linux, and cloud environments. Model attacker behavior to identify defensive gaps and high-risk attack paths.Lead enterprise threat hunting across endpoint, network, and cloud telemetry. Develop high-confidence IOCs/IOAs, custom detections (YARA/behavioral), and scalable forensic collection capabilities in partnership with Splunk.Built deception capabilities including honeypots and canary tokens to detect early-stage attacker activity.Implemented a MISP-based Threat Intelligence Platform integrated with SIEM/SOAR. Develop custom automation and analysis tooling in Go and Python for OSINT, malware analysis, NetFlow forensics, and threat infrastructure tracking.Lead vendor evaluations, proof-of-concepts, and deployment of threat intelligence and incident response technologies.
Education
Navy Leadership School
Navy Leadership Qualified, Organizational Leadership
2002 — 2002
FC "C" SChool
RF Electronics Certification (NSSMS), Electrical and Electronics Engineering
2000 — 2001
Western Hills HIgh School
High School Diploma
Tarrant County College
Associate's Degree, Computer and Information Systems Security/Information Assurance
2014 — 2017
US Navy Instructor Training (9502)
9502 Certification US Navy, Adult and Continuing Education and Teaching
2004 — 2004
US Navy Advanced Electronic Computer Field School
Electrical and Electronics Engineering
1999 — 2001
FC "A" School
Electrical, Electronics and Communications Engineering
1999 — 2001
3D University
3D Systems Certified SLA Engineer, Stereolithography
2008 — 2008
SANS Technology Institute
GPEN
Skills
- Linux
- Data Analysis
- Malware Analysis
- Strategic Planning
- Network Security
- Rapid Prototyping
- Incident Response
- Radar
- Electronics
- Customer Service
- Fire Control Systems
- Threat & Vulnerability Management
- Management
- Training
- Testing
- Technical Writing
- Arcsight
- Threat Intelligence
- Project Management
- Solidworks
- Network Administration
- Manufacturing
- Vulnerability Management
- Incident Handling
- Computer Hardware
- Threat Hunting
- Engineering
- Troubleshooting
- Leadership
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.