Skip to main content
SecurityScorecard

Senior Research Engineer, Threat Intelligence

RemoteUnited States only
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Mid-size
$140k–$180k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior research engineer building production threat intel pipelines from research output. Must have 5-8 years hands-on engineering with threat intelligence/security research, production Python and TypeScript, cloud infra, and STIX/TAXII/MISP/ATT&CK. Applied LLM experience with retrieval, structured output, and eval harnesses required.

Core skills

STIX 2.1Threat IntelligenceDetection Engineering

Required skills

PythonTypeScriptNode.jsAWSYARASigmaSTIX PatterningTAXII 2.1MISPMITRE ATT&CK

Optional skills

CELOPApolicy-as-codeSplunkKinesisNetFlowGoFAIR

What you'll do

  • Own the path from research output to production-ready artifact: a detection rule, a distributed feed, a scoring input, or a customer alert.
  • Partner with adjacent teams to define clean handoff contracts, so new signals arrive downstream with the schema, value framing, and consumption pattern already defined.
  • Build and maintain STRIKE platform components across multiple services and runtimes, including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines that operate over standards-anchored predicates.
  • Extend these systems without breaking the data contracts already in production.
  • Turn research into shipped detection content: YARA, Sigma, STIX patterns, behavioral indicators, and the pipelines that distribute them.
  • Build correlation pipelines that link scan data, attack surface signals, vulnerability data, and adversary tracking into customer-facing intelligence.
  • Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard.
  • Define and govern schemas that hold up once they reach downstream teams.
  • Build the automation that removes commodity overhead from research work: indicator enrichment, report drafting, corpus correlation, feed normalization, and sandbox triage.
  • Help move the team from analyst-driven, model-assisted workflows toward model-driven workflows with analyst review.
  • Coordinate with engineering, measurement, and platform product teams so research actually lands in product.

What they require

  • Bachelor's or Master's in Computer Science, Cybersecurity, or a related technical field; self-taught practitioners with strong public work are welcome.
  • 5 to 8 years in a hands-on engineering role with meaningful exposure to threat intelligence, security research, or detection engineering
  • Prior experience building production systems that consume or emit threat intel data is required
  • Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK, and how they work together in practice
  • Hands-on experience with YARA, Sigma, and STIX Patterning
  • Comfortable reading malware analysis output, parsing adversary infrastructure data, and writing detection logic that holds up under production load
  • You've shipped production systems that use language models, not just demos: retrieval over a real corpus, structured output with schema validation, eval harnesses that catch regressions before users do, and understanding of where models fail
  • Ability to do cost-per-task math and make the case for smaller, tightly scaffolded models
  • Bridge mindset: write code that ships and understand researcher thinking
  • Preferred: Experience with policy-as-code or expression-language engines (CEL, OPA, or similar)
  • Preferred: Published or co-authored security research (campaigns, vulnerabilities, adversary tracking)
  • Preferred: Large-scale telemetry experience (Splunk, Kinesis, NetFlow, or equivalent)
  • Preferred: Contributor or maintainer on open-source threat intel projects (MISP, OpenCTI, Sigma, STIX, ATT&CK)
  • Preferred: Familiarity with quantitative risk frameworks such as FAIR
  • Preferred: Familiarity with Golang at a production level

Benefits

  • Competitive salary
  • Stock options
  • Health benefits
  • Unlimited PTO
  • Parental leave
  • Tuition reimbursements
  • Annual performance-based incentive compensation awards
  • Equity
  • Other company benefits

SecurityScorecard is a global leader in cybersecurity ratings, with over 12 million companies continuously rated and operations in 64 countries. Its patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting.

🇺🇸 United StatesCybersecurityEnterprisesecurityscorecard.com/

Details

Visa sponsorshipNo
$140k–$180k/yr