Overview
Threat Intelligence Engineer to build infrastructure for threat discovery, automated detections, and investigation tooling.
What you'll do
- Build automated detection systems that use disparate signals to identify abusive behavior.
- Take systems from idea to proof-of-concept to production with monitoring, documentation, and maintenance.
- Develop and maintain YARA rule infrastructure for writing, validating, and testing rules on real data.
- Integrate external threat intelligence platforms via MCP servers for multi-source correlation.
- Create data pipelines ingesting intelligence from RSS feeds, CTI news sources, and partner sharing, using Claude to extract TTPs and generate hunting queries.
- Develop behavioral analytics with DBT-based frameworks and implement searchable audit logging.
- Scrape and normalize external data to feed threat detection and enrichment workflows.
What you'll need
- Strong coding proficiency in Python and SQL for detection logic, data pipelines, and automation.
- Experience with data pipeline orchestration tools (Airflow, DBT, or similar).
- Familiarity with threat intelligence concepts including IOCs, YARA rules, and threat correlation techniques.
- Experience integrating external APIs and building data ingestion systems.
- Ability to translate investigator needs and workflows into technical requirements.
- Strong communication skills to work closely with non-engineering stakeholders.
Details
- Hybrid location-based policy: expected to be in an office at least 25% of the time.
- Annual compensation range: $320,000–$405,000 USD.
- Minimum education: Bachelor’s degree or equivalent combination of education, training, and/or experience.
- Security requirement: A Top Secret Clearance.
- Minimum education required field of study: a field relevant to the role as demonstrated through coursework, training, or professional experience.
Read the full description and apply on the company’s own careers page.