Skip to main content
SecurityScorecard

Senior Research Engineer, Threat Intelligence

RemoteUnited States only
Published
Role
Security
Experience
Senior
$140k–$180k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior research engineer for SecurityScorecard's STRIKE threat-intel team. Needs 5–8 yrs hands-on threat-intel/detection engineering — building production systems that emit or consume intel data in Python and TypeScript/Node, plus familiarity with STIX, TAXII, MISP, ATT&CK. Must have shipped production LLM systems (retrieval over a real corpus, schema-constrained output, eval harnesses). Remote, based in Raleigh, NC; US-focused and no immigration sponsorship.

Core skills

PythonSTIX/TAXIIYARA/Sigma

Required skills

TypeScriptNode.jsSQLRedisAWSDockerCI/CDYARASigmaSTIXSTIX patternTAXIIMISPMITRE ATT&CKstreaming data platform/batch data platform

Optional skills

CELOPASplunkAmazon KinesisNetFlowGoOpenCTIFAIR

What you'll do

  • Own the path from research output to production-ready artifact: detection rule, distributed feed, scoring input, or customer alert.
  • Define clean handoff contracts so new signals arrive downstream with schema, value framing, and consumption pattern already defined.
  • Build and maintain STRIKE platform components — infərmation distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, rules engines.
  • Turn research into shipped detection content: YARA, Sigma, STIX patterns, behavioral indicators, and the pipelines that distribute them.
  • Build correlation pipelines linking scan data, attack surface signals, vulnerability data, and adversary tracking into customer-facing intelligence.
  • Drive STIX 2.1 adoption as unified output schema and TAXII 2.1 as distribution standard; define and govern schemas.
  • Build workflow automation removing overhead from research: indicator enrichment, report drafting, corpus correlation, feed normalization, sandbox triage.
  • Coordinate with engineering, measurement, and platform product teams so research lands in product.

What they require

  • 5+ years in a hands-on engineering role with meaningful exposure to threat intelligence, security research, or detection engineering.
  • Prior experience building production systems that consume or emit threat intelligence data (required).
  • Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK.
  • Hands-on experience with YARA, Sigma, and STIX Patterns; comfortable reading malware analysis output and writing detection logic.
  • Shipped production systems that use language models — retrieval over real corpus, structured output with schema validation, eval harnesses.
  • Understanding of when a model is the wrong tool vs regex or SQL.
  • Ability to take an idea sketched in a chat message into a deployed pipeline.
  • Degree in Computer Science/Cybersecurity or self-taught with strong public work.
  • No immigration sponsorship provided.

Benefits

  • Competitive salary
  • Stock options
  • Health benefits
  • Unlimited PTO
  • Parental leave
  • Tuition reimbursements

SecurityScorecard is a global leader in cybersecurity ratings, with over 12 million companies continuously rated and operations in 64 countries. Its patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting.

🇺🇸 United StatesCybersecurityEnterprisesecurityscorecard.com/
$140k–$180k/yr