Skip to content

Security Engineer, Threat Intelligence

The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.

About the job

Responsibilities

  • Track nation-state and advanced criminal actors targeting frontier AI infrastructure, translating tooling, infrastructure patterns, and tradecraft into actionable intelligence.
  • Build and operate pipelines that collect, enrich, and correlate indicators, integrating intelligence into detection and agentic triage systems.
  • Lead intelligence-driven hunts across enterprise, cloud, identity, data center IT, and OT telemetry.
  • Convert threat intelligence findings into production-quality detections authored as code.
  • Analyze malware, phishing infrastructure, attacker tooling, and logs to extract indicators, TTPs, and attribution signals.
  • Curate intelligence from commercial feeds, open sources, government sources, and peer relationships.
  • Build and maintain intelligence-sharing relationships with ISACs, peer AI and cloud security teams, and government partners.
  • Collaborate with detection engineers and incident responders to produce detections, hunting hypotheses, and incident context.
  • Write intelligence products that translate complex campaigns into decisions and next steps for engineers and executives.

Requirements

  • Experience tracking specific nation-state or advanced criminal actors, including their tooling, infrastructure, and targeting.
  • Production-quality Python or a similar programming language, with experience building automation and data pipelines end to end.
  • Hands-on malware, infrastructure, and log analysis experience.
  • Experience authoring production detection logic using YARA, Sigma, or SIEM-native queries.
  • Experience partnering with detection engineering and incident response teams during active events.
  • Strong written communication and ability to produce actionable intelligence.

Nice-to-haves

  • Active threat intelligence community network and experience sharing intelligence.
  • Experience defending large-scale GPU or AI compute infrastructure, data centers, or multi-tenant cloud environments.
  • Experience applying LLMs or agentic tooling to collection, enrichment, and analysis.
  • Public research, conference talks, or open-source contributions in cyber threat intelligence.

Compensation and Benefits

  • Base salary: $200,000–$280,000 per year, depending on experience, skills, qualifications, and location.
  • Competitive total compensation may include equity in the form of stock options.
  • Retirement or pension plan, health, dental, and vision insurance.
  • Generous paid time off.

Skills

Python, Yara, Sigma, SIEM, Malware Analysis, Threat Intelligence, Incident Response, Detection Engineering, Log Analysis, Cloud Security, LLMs, Agentic Tooling

Tailscale

Tailscale

United States
Security Infrastructure Engineer
CA$218k+/yrRemoteSecurity Engineering

This role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.

OpenAI

OpenAI

San Francisco, CA
Red Team Specialist - Cyber
$198k+/yrHybridSecurity Engineering

The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.

Vercel

Vercel

San Francisco, CA
Software Engineer, Trust & Safety
$196k+/yrHybrid5+ YOESecurity Engineering

Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.

1Password

1Password

United States
Manager, Security Incident Response
$192k+/yrRemote5+ YOESecurity Engineering

Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.

Decagon

Decagon

San Francisco, CA

Governance, Risk, and Compliance Manager - Privacy
$190k+/yrOn-site5+ YOESecurity Engineering

Own and operate Decagon’s privacy and GRC programs, including regulatory compliance, data governance, customer security engagements, audits, and cross-functional privacy initiatives. The role requires 5+ years of GRC experience, strong communication and project management skills, and familiarity with enterprise security controls.