Skip to main content
SecurityScorecard

Senior Research Engineer, Threat Intelligence

RemoteUnited States only
Published
Role
Security
Experience
Senior
$140k–$180k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior engineer to take threat-research artifacts into production (detections, feeds, schemas). Requires 5–8 years engineering experience with threat intelligence, production Python and TypeScript/Node, STIX/TAXII and detection tooling (YARA, Sigma). Remote — United States only; we do not provide immigration sponsorship.

Core skills

STIX 2.1YARASigma

Required skills

PythonTypeScriptNode.jsRelational databasesCache data storesStreaming or batch data platformAWSContainersCI/CD pipelinesTAXII 2.1MISPMITRE ATT&CKSTIX PatterningLarge language models / applied language modelsSandbox orchestration

Optional skills

Policy-as-code / expression-language engines (CEL, OPA, or similar)Published or co-authored security researchLarge-scale telemetry experience (Splunk, Kinesis, NetFlow, or equivalent)Contributor or maintainer on open-source threat intel projects (MISP, OpenCTI, Sigma, STIX, ATT&CK)Familiarity with quantitative risk frameworks such as FAIRGo

What you'll do

  • Own the path from research output to production-ready artifact: detection rule, distributed feed, scoring input, or customer alert.
  • Partner with adjacent teams to define clean handoff contracts so new signals arrive downstream with schema, value framing, and consumption pattern defined.
  • Build and maintain STRIKE platform components across multiple services and runtimes including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines.
  • Extend systems without breaking existing production data contracts.
  • Turn research into shipped detection content: YARA, Sigma, STIX patterns, behavioral indicators, and distribution pipelines.
  • Build correlation pipelines linking scan data, attack surface signals, vulnerability data, and adversary tracking into customer-facing intelligence.
  • Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard; define and govern durable schemas.
  • Automate research workflows: indicator enrichment, report drafting, corpus correlation, feed normalization, sandbox triage, and related automation to reduce commodity overhead.
  • Move team workflows toward model-driven workflows with analyst review, including eval harnesses, prompt/versioning controls, cost accounting, latency budgeting, and output logging.
  • Coordinate with engineering, measurement, and platform product teams to land research in product and occasionally explain work to customers, journalists, or executives.

What they require

  • Bachelor's or Master's in Computer Science, Cybersecurity, or a related technical field (self-taught practitioners with strong public work are welcome).
  • 5 to 8 years in a hands-on engineering role with meaningful exposure to threat intelligence, security research, or detection engineering.
  • Prior experience building production systems that consume or emit threat intel data is required.
  • Production-level Python and TypeScript/Node experience.
  • Experience with relational and cache data stores, plus at least one streaming or batch data platform.
  • Cloud infrastructure experience (AWS preferred), containers, and CI/CD pipelines.
  • Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK and how they work together in practice.
  • Hands-on experience with YARA, Sigma, and STIX Patterning; comfortable reading malware analysis output, parsing adversary infrastructure data, and writing production-grade detection logic.
  • Experience shipping production systems that use language models, including retrieval over a real corpus, structured output with schema validation, eval harnesses, and cost-per-task reasoning.
  • Ability to judge when models are appropriate vs. simpler methods (regex, SQL) and to design accordingly.
  • Bridge mindset: able to ship code and translate between researchers, product managers, and platform engineers.

Benefits

  • Specific to each country, we offer a competitive salary
  • stock options
  • Health benefits
  • unlimited PTO
  • parental leave
  • tuition reimbursements
  • and much more

SecurityScorecard is a global leader in cybersecurity ratings, with over 12 million companies continuously rated and operations in 64 countries. Its patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting.

🇺🇸 United StatesCybersecurityEnterprisesecurityscorecard.com/

Details

Visa sponsorshipNo
$140k–$180k/yr