Threat Collections Engineer
Builds threat detection infrastructure, data pipelines, and tooling for threat intelligence team. Requires strong Python/SQL skills, experience with orchestration tools, YARA rules, and external API integrations.
About the job
Responsibilities
- Build automated detection systems using disparate signals to identify abusive behavior.
- Take systems from idea to proof-of-concept to production-grade with monitoring, documentation, and maintenance.
- Develop and maintain YARA rule infrastructure, including tools for writing, validating, and testing rules.
- Create integrations with external threat intelligence platforms (e.g. VirusTotal, Censys, Urlscan) via MCP servers.
- Build data pipelines ingesting intelligence from RSS feeds, CTI news, and partners, using Claude for TTP extraction and hunting queries.
- Develop behavioral analytics using DBT-based frameworks and searchable audit logging.
- Establish feedback loops with investigators to tune detections and reduce false positives.
- Scrape and normalize data from external sources for threat detection workflows.
You may be a good fit if you:
- Strong coding proficiency in Python and SQL for detection logic, data pipelines, and automation.
- Experience with data pipeline orchestration tools (Airflow, DBT, or similar).
- Familiarity with threat intelligence concepts including IOCs, YARA rules, and threat correlation.
- Experience integrating external APIs and building data ingestion systems.
- Can translate investigator needs into technical requirements.
- Comfortable building v0 systems and iterating on feedback.
- Strong communication skills for non-engineering stakeholders.
Strong candidates may also have:
- Experience with threat intelligence sharing frameworks (MISP, STIX/TAXII).
- Background in cyber threat intelligence, security operations, or abuse detection.
- Experience building MCP servers or similar AI tool integrations.
- Familiarity with web scraping and data extraction at scale.
- Experience with behavioral analytics or anomaly detection.
- Understanding of LLM capabilities for automation.
- Top Secret Clearance.
Annual Salary: $300,000—$320,000 USD
Skills
Python, SQL, Yara, dbt, Airflow, Virustotal, Censys, Urlscan, Misp, Stix/Taxii
Similar jobs
Security Engineering jobsConduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.
Build and operate evaluations for cyber capabilities and safeguard robustness in AI models, analyze adversarial data, and develop cyber-abuse detection probes. The role requires hands-on cybersecurity experience, Python proficiency, evaluation expertise, and strong cross-functional communication.
This hands-on security engineer will research sophisticated threat actors, build intelligence pipelines, conduct threat hunts, analyze malware and infrastructure, and translate findings into durable detections. The role requires at least five years of cyber threat intelligence or related experience, strong Python engineering, and malware and detection-analysis expertise.
Senior hands-on security engineer responsible for endpoint hardening, device trust, identity and SaaS governance, and scalable corporate-security automation across a growing organization. Requires endpoint security expertise, Python scripting, IAM and zero-trust depth, and strong threat-modeling judgment.
Design and ship security-critical software and firmware at the boundary between policy systems and hardware-backed cryptographic protection. The role requires 5+ years of secure embedded development and deep C, C++, or Rust experience.