Senior Threat Intelligence Engineer
The engineer researches and operationalizes threat intelligence by building machine-learning detection capabilities, security-tool integrations, and SOAR automation. The role requires 4+ years of security, cyber threat intelligence, or security automation experience, strong scripting skills, and deep knowledge of adversary behavior and cloud security.
About the job
Responsibilities
- Research, collect, and analyze threat intelligence from OSINT, commercial feeds, dark web sources, and internal security events.
- Design, implement, and maintain detection use cases across the machine-learning lifecycle, including data ingestion, training, deployment, and inference.
- Profile threat actors, document their tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK, and assess organizational impact.
- Produce and disseminate actionable intelligence reports and briefings for technical security teams and executive leadership.
- Engineer the ingestion, enrichment, correlation, and contextualization of Indicators of Compromise (IOCs) and Indicators of Attack (IOAs) in security platforms.
- Develop automation workflows and SOAR playbooks for incident triage, alert enrichment, vulnerability management, and threat response.
- Integrate security tools such as SIEM, EDR, cloud security posture management, vulnerability scanners, and threat intelligence platforms through APIs and scripting.
- Identify manual security processes and build scalable automation to improve operational efficiency.
- Support incident response with threat context during active incidents.
- Collaborate with detection engineers, security engineers, and software developers to embed intelligence-driven security practices into CI/CD pipelines and corporate infrastructure.
Requirements
- 4+ years of hands-on experience in security engineering, cyber threat intelligence, or security automation.
- Strong proficiency in at least one scripting or programming language for automation, such as Python.
- Deep understanding of the cyber kill chain, threat actor TTPs, common attack vectors, networking protocols, and operating system internals.
- Proven experience designing SOAR playbooks and integrating security tools through APIs.
- Experience with commercial and open-source threat intelligence platforms and threat feeds.
- Familiarity with security services and automation in major cloud environments, including AWS, Azure, or Google Cloud.
- Understanding of attacker tools, techniques, and procedures and common attack components.
- Experience threat hunting in complex networks.
- Ability to contextualize attack briefs and vulnerability reports, validate vulnerability findings, and provide impact analysis.
- Experience gathering and analyzing data about perceived threats and generating operational context.
- Experience with common security operations tools and security event information.
- Strong communication, judgment, autonomy, ownership, and cross-functional collaboration skills.
Nice-to-haves
- Understanding of nation-state motivations and operational capabilities.
- Experience with Infrastructure as Code tools such as Terraform.
- Familiarity with data analysis and visualization tools for threat intelligence.
- Experience with malware analysis and reverse engineering to extract actionable indicators.
Compensation and Benefits
- Eligible to participate in Cloudflare’s equity plan.
- Medical, dental, and vision insurance.
- Flexible spending and commuter spending accounts.
- Fertility and family-forming benefits.
- Mental health support and Employee Assistance Program.
- Global travel medical insurance.
- Short- and long-term disability insurance.
- Life and accident insurance.
- 401(k) retirement savings plan.
- Employee stock participation plan.
- Flexible paid time off.
- Parental, pregnancy health, medical, and bereavement leave programs.
Skills
Python, Machine Learning, Data Science, Mitre Att&Ck, Soar, SIEM, Edr, Terraform, AWS, Azure, GCP, Threat Intelligence Platforms, Threat Hunting, Malware Analysis, Reverse Engineering
Similar jobs
Security Engineering jobsLeads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.
Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.
Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.
Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.
Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.