Skip to main content
SecurityScorecard

Senior Research Engineer, Threat Intelligence

RemoteUnited States only
Published
Role
Security
Experience
Senior
$140k–$180k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior research-to-production engineer with 5–8 years of hands-on engineering experience in threat intelligence or detection engineering. Must be proficient in Python and TypeScript/Node, have production experience with STIX 2.1 / TAXII 2.1 and detection content (YARA, Sigma), and have shipped systems that use language models in production. Remote role listed as Remote (Boston, MA); employer does not provide immigration sponsorship.

Core skills

STIX 2.1YARA

Required skills

PythonTypeScriptNode.jsRelational databasesCache data storesStreaming or batch data platformAWSContainersCI/CD pipelinesTAXII 2.1MISPMITRE ATT&CKSigmaSTIX PatterningDetection engineeringLanguage models (production systems)

Optional skills

Policy-as-code / CEL / OPAPublished or co-authored security researchLarge-scale telemetry (Splunk, Kinesis, NetFlow or equivalent)Contributor/maintainer on open-source threat intel projects (MISP, OpenCTI, Sigma, STIX, ATT&CK)Familiarity with quantitative risk frameworks such as FAIRGolang (production level)

What you'll do

  • Own the path from research output to production-ready artifact: a detection rule, a distributed feed, a scoring input, or a customer alert.
  • Partner with adjacent teams to define clean handoff contracts so new signals arrive downstream with schema, value framing, and consumption pattern defined.
  • Build and maintain STRIKE platform components across multiple services and runtimes, including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines.
  • Extend systems without breaking the data contracts already in production.
  • Turn research into shipped detection content: YARA, Sigma, STIX patterns, behavioral indicators, and the pipelines that distribute them.
  • Build correlation pipelines linking scan data, attack surface signals, vulnerability data, and adversary tracking into customer-facing intelligence.
  • Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard; define and govern durable schemas.
  • Build automation to remove commodity overhead from research work: indicator enrichment, report drafting, corpus correlation, feed normalization, and sandbox triage.
  • Move team workflows toward model-driven workflows with analyst review, including retrieval grounded in the team's corpus, schema-constrained outputs, and eval harnesses.
  • Coordinate with engineering, measurement, and platform product teams so research actually lands in product; serve as engineering voice between researchers, PMs, and platform engineers.

What they require

  • Bachelor's or Master's in Computer Science, Cybersecurity, or a related technical field. Self-taught practitioners with strong public work are welcome.
  • 5 to 8 years in a hands-on engineering role with meaningful exposure to threat intelligence, security research, or detection engineering.
  • Prior experience building production systems that consume or emit threat intel data is required.
  • Production-level proficiency with Python and TypeScript/Node.
  • Experience with relational and cache data stores, plus at least one streaming or batch data platform.
  • Experience with cloud infrastructure (AWS preferred), containers, and CI/CD pipelines.
  • Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK, and how they work together in practice.
  • Hands-on experience with YARA, Sigma, and STIX Patterning. Comfortable reading malware analysis output, parsing adversary infrastructure data, and writing detection logic that holds up under production load.
  • Experience shipping production systems that use language models, including retrieval over a real corpus, structured output with schema validation, eval harnesses, and cost-per-task analysis.
  • You should have a clear sense of when a model is the wrong tool and design accordingly.
  • Bridge Mindset: able to write production code and translate researcher ideas into deployed pipelines.

Benefits

  • Competitive salary (specific to each country)
  • Stock options
  • Health benefits
  • Unlimited PTO
  • Parental leave
  • Tuition reimbursements
  • Annual performance-based incentive compensation awards and equity (may be eligible)

SecurityScorecard is a global leader in cybersecurity ratings, with over 12 million companies continuously rated and operations in 64 countries. Its patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting.

🇺🇸 United StatesCybersecurityEnterprisesecurityscorecard.com/

Details

Visa sponsorshipNo
$140k–$180k/yr