# Senior Threat Intelligence Engineer

**Company:** [Cloudflare](https://hotfix.jobs/companies/cloudflare)
**Location:** Austin, TX
**Role:** Security Engineering
**Experience:** 5+ years
**Skills:** Python, Machine Learning, Data Science, Mitre Att&Ck, Soar, SIEM, Edr, Terraform, AWS, Azure, GCP, Threat Intelligence Platforms, Threat Hunting, Malware Analysis, Reverse Engineering
**Posted:** 2026-08-18

> The engineer researches and operationalizes threat intelligence by building machine-learning detection capabilities, security-tool integrations, and SOAR automation. The role requires 4+ years of security, cyber threat intelligence, or security automation experience, strong scripting skills, and deep knowledge of adversary behavior and cloud security.

## Job Description

## Responsibilities
- Research, collect, and analyze threat intelligence from OSINT, commercial feeds, dark web sources, and internal security events.
- Design, implement, and maintain detection use cases across the machine-learning lifecycle, including data ingestion, training, deployment, and inference.
- Profile threat actors, document their tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK, and assess organizational impact.
- Produce and disseminate actionable intelligence reports and briefings for technical security teams and executive leadership.
- Engineer the ingestion, enrichment, correlation, and contextualization of Indicators of Compromise (IOCs) and Indicators of Attack (IOAs) in security platforms.
- Develop automation workflows and SOAR playbooks for incident triage, alert enrichment, vulnerability management, and threat response.
- Integrate security tools such as SIEM, EDR, cloud security posture management, vulnerability scanners, and threat intelligence platforms through APIs and scripting.
- Identify manual security processes and build scalable automation to improve operational efficiency.
- Support incident response with threat context during active incidents.
- Collaborate with detection engineers, security engineers, and software developers to embed intelligence-driven security practices into CI/CD pipelines and corporate infrastructure.

## Requirements
- 4+ years of hands-on experience in security engineering, cyber threat intelligence, or security automation.
- Strong proficiency in at least one scripting or programming language for automation, such as Python.
- Deep understanding of the cyber kill chain, threat actor TTPs, common attack vectors, networking protocols, and operating system internals.
- Proven experience designing SOAR playbooks and integrating security tools through APIs.
- Experience with commercial and open-source threat intelligence platforms and threat feeds.
- Familiarity with security services and automation in major cloud environments, including AWS, Azure, or Google Cloud.
- Understanding of attacker tools, techniques, and procedures and common attack components.
- Experience threat hunting in complex networks.
- Ability to contextualize attack briefs and vulnerability reports, validate vulnerability findings, and provide impact analysis.
- Experience gathering and analyzing data about perceived threats and generating operational context.
- Experience with common security operations tools and security event information.
- Strong communication, judgment, autonomy, ownership, and cross-functional collaboration skills.

## Nice-to-haves
- Understanding of nation-state motivations and operational capabilities.
- Experience with Infrastructure as Code tools such as Terraform.
- Familiarity with data analysis and visualization tools for threat intelligence.
- Experience with malware analysis and reverse engineering to extract actionable indicators.

## Compensation and Benefits
- Eligible to participate in Cloudflare’s equity plan.
- Medical, dental, and vision insurance.
- Flexible spending and commuter spending accounts.
- Fertility and family-forming benefits.
- Mental health support and Employee Assistance Program.
- Global travel medical insurance.
- Short- and long-term disability insurance.
- Life and accident insurance.
- 401(k) retirement savings plan.
- Employee stock participation plan.
- Flexible paid time off.
- Parental, pregnancy health, medical, and bereavement leave programs.

## Similar jobs

- [SOC Lead](https://hotfix.jobs/jobs/1b4ce51d-67b7-4000-a328-a6f0e74f22a6) - Idme - McLean, VA - $96k – $112k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/9286e91d-ca35-4449-bb47-da0dc51b2aaa) - ConductorOne - Remote - $100k – $200k/yr
- [Security GRC Lead](https://hotfix.jobs/jobs/2eb261b0-5ff9-435d-b0fb-eaf5933051d1) - Mercor - San Francisco, CA - $350k – $425k/yr
- [Lead, Security Controls Assurance - SOX](https://hotfix.jobs/jobs/a1c11627-c920-4e31-abc6-2e170042a626) - Anthropic - San Francisco, CA - $410k – $510k/yr
- [Senior Platform Security Engineer](https://hotfix.jobs/jobs/3ac667bf-62fa-4280-8ccb-2af3468d8579) - Discord - $196k – $245k/yr

**Apply:** https://hotfix.jobs/jobs/ec9a4930-ad1a-4688-824d-0b73979b50b3
**Canonical:** https://hotfix.jobs/jobs/ec9a4930-ad1a-4688-824d-0b73979b50b3