Overview
Security Engineer focused on Threat Intelligence for AI and technology targets, producing actionable intelligence that drives detections, hunts, and defensive priorities.
What you'll do
- Research, track, and report on threat actors and campaigns targeting AI labs and other technology sectors.
- Build and maintain tooling and automated pipelines to collect, enrich, correlate, and operationalize indicators of compromise.
- Develop and execute intelligence-driven threat hunts across endpoint, cloud, identity, and SaaS telemetry.
- Perform technical analysis of malware, phishing infrastructure, and attacker tooling to extract indicators, TTPs, and attribution signals.
- Partner with Detection Engineering and Incident Response to translate intelligence into detection rules, hunting hypotheses, and incident context.
- Curate and triage inbound intelligence from commercial feeds, open source, government, and trusted peer relationships.
- Contribute to threat models and risk assessments and maintain external intelligence-sharing relationships.
What you'll need
- 5+ years of hands-on experience in cyber threat intelligence, threat hunting, or intrusion analysis.
- Deep, demonstrable knowledge of specific nation-state or advanced criminal threat actors (tooling, infrastructure patterns, tradecraft, targeting).
- Production-quality Python (or similar) and experience building automation and data pipelines.
- Comfort with malware analysis, infrastructure analysis (passive DNS, certificate pivoting, netflow), and log analysis.
- Experience authoring detection logic (YARA, Sigma, Snort/Suricata, or SIEM-native queries) and understanding detection durability.
- Ability to write clearly and concisely for intelligence products that are acted on.
- Existing network in the threat intelligence community with a track record of bidirectional sharing.
Details
- Location listed as New York City, NY; Remote-Friendly (Travel-Required) | San Francisco, CA | Washington, DC; San Francisco, CA | New York City, NY.
- Location-based hybrid policy: expected to be in one of the offices at least 25% of the time.
- Visa sponsorship is available, but not guaranteed for every role/candidate.
Read the full description and apply on the company’s own careers page.