Security Engineer - Threat Intel
This hands-on security engineer will research sophisticated threat actors, build intelligence pipelines, conduct threat hunts, analyze malware and infrastructure, and translate findings into durable detections. The role requires at least five years of cyber threat intelligence or related experience, strong Python engineering, and malware and detection-analysis expertise.
About the job
Responsibilities
- Research, track, and report on threat actors and campaigns targeting AI labs, cloud infrastructure, and the technology sector.
- Build and maintain tooling and automated pipelines to collect, enrich, correlate, and operationalize indicators of compromise into detection and alerting systems.
- Develop and execute intelligence-driven threat hunts across endpoint, cloud, identity, and SaaS telemetry, turning findings into durable detections.
- Perform technical analysis of malware, phishing infrastructure, and attacker tooling to extract indicators, tactics, techniques, procedures, and attribution signals.
- Partner with Detection Engineering and Incident Response to translate intelligence into detection rules, hunting hypotheses, and incident context.
- Curate and triage intelligence from commercial feeds, open sources, government, and trusted peers.
- Contribute to threat models and risk assessments informing security architecture and defensive investment.
- Build and maintain intelligence-sharing relationships with peer companies, ISACs, and government partners.
Requirements
- 5+ years of hands-on experience in cyber threat intelligence, threat hunting, or intrusion analysis against sophisticated adversaries.
- Deep knowledge of nation-state or advanced criminal threat actors, including tooling, infrastructure patterns, tradecraft, and targeting.
- Production-quality Python or similar programming experience, including automation and data pipelines.
- Experience with malware analysis, infrastructure analysis, passive DNS, certificate pivoting, NetFlow, and log analysis.
- Experience authoring detection logic using YARA, Sigma, Snort/Suricata, or SIEM-native queries.
- Clear and concise technical writing.
- Existing threat intelligence community network and a track record of productive bidirectional information sharing.
- Bachelor's degree or equivalent combination of education, training, and experience in a relevant field.
Nice-to-haves
- Experience defending cloud-native and research-heavy environments, including AWS, Google Cloud, Kubernetes, ML infrastructure, developer tooling, and software supply chains.
- Experience tracking sophisticated or state-sponsored adversaries where analysis informed detection, threat hunting, and incident response.
- Experience applying LLMs or other AI tooling to intelligence collection, enrichment, and analysis.
- Public research, conference talks, or open-source tooling contributions in cyber threat intelligence.
Compensation
- Annual salary: $320,000–$405,000 USD
Skills
Python, Threat Intelligence, Threat Hunting, Malware Analysis, Passive Dns, Netflow, Yara, Sigma, Snort, Suricata, SIEM, AWS, GCP, Kubernetes, LLMs
Similar jobs
Security Engineering jobsSenior hands-on security engineer responsible for endpoint hardening, device trust, identity and SaaS governance, and scalable corporate-security automation across a growing organization. Requires endpoint security expertise, Python scripting, IAM and zero-trust depth, and strong threat-modeling judgment.
Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.
Build and operate evaluations for cyber capabilities and safeguard robustness in AI models, analyze adversarial data, and develop cyber-abuse detection probes. The role requires hands-on cybersecurity experience, Python proficiency, evaluation expertise, and strong cross-functional communication.
Design and ship security-critical software and firmware at the boundary between policy systems and hardware-backed cryptographic protection. The role requires 5+ years of secure embedded development and deep C, C++, or Rust experience.
The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.