Skip to main content
SecurityScorecard

Senior Research Engineer, Threat Intelligence

RemoteUnited States only
Published
Role
Security
Experience
Senior
Employment
Full-time
$140k–$180k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior research engineer in SecurityScorecard's threat intelligence team — you turn research into production detection, feeds and platform artifacts that ship, not demos. 5-8 yrs in hands-on engineering with production-level Python and TypeScript, detection/naming (YARA, Sigma, STIX 2.1), and proven shipped LLM production systems built with healthy skepticism of model output. Remote US role anchored to Washington, DC.

Core skills

PythonSTIX 2.1YARA

Required skills

TypeScriptNode.jsAWSContainersCI/CDTAXII 2.1MISPMITRE ATT&CKSigmaSTIX PatterningLarge Language Models (LLMs)

Optional skills

GoCELOPASplunkKinesisNetFlowOpenCTI

What you'll do

  • 100%
  • Own the path from research output to production-ready artifact: detection rule, distributed feed, scoring input, or customer alert; partner with adjacent teams to define handoff contracts so new signals arrive with the schema and consumption pattern defined.
  • Build and maintain the STRIKE platform components across services and runtimes — distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, rules engines — without breaking production data contracts.
  • Turn research into shipped detection content: YARA, Sigma, pattern language and behavioral indicators, plus the pipelines that distribute them; build correlation pipelines linking scan data, attack surface signals, vulnerability data and adversary tracking into customer content.
  • Drive STIX 2.1 adoption as the unified output schema and TAXII 2.1 as the distribution standard; define and govern downended schemas that hold up for downstream teams.
  • Build automation that removes commodity overhead from research: indicator enrichment, report drafting, corpus correlation, feed normalization, sandbox triage — move the team from model-assisted to model-controlled workflows with analyst review.
  • Apply rigor to model work: retrieval grounded in the team's corpus, schema-constrained output, eval harnesses, cost/latency awareness, prompt versioning, output logging; know when a regex or SQL query is the right tool instead of a model.
  • Act as the engineering voice coordinating delivery across engineering, measurement, and platform product teams; occasionally explain the work to customers, journalists, or executives.

What they require

  • 5 8 years in a hands-on engineering role with meaningful exposure to threat intelligence, security research, or detection engineering.
  • Prior experience building production systems that consume or emit threat intelligence data (required).
  • Devoted to practice: Bachelor's or Master's in Computer Science, Cybersecurity, or a related field; self-taught practitioners with strong experience are welcome.

Benefits

  • Health benefits
  • Stock options
  • Unlimited PTO
  • Parental leave
  • Tuition reimbursements
  • Annual performance-based incentive compensation and equity

SecurityScorecard is a global leader in cybersecurity ratings, with over 12 million companies continuously rated and operations in 64 countries. Its patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting.

🇺🇸 United StatesCybersecurityEnterprisesecurityscorecard.com/

Details

Visa sponsorshipNo
$140k–$180k/yr