Senior Research Engineer, Threat Intelligence

3 weeks, 4 days ago
Full-time
Senior
Software Development
SecurityScorecard

SecurityScorecard

SecurityScorecard is a cybersecurity company that provides a powerful AI-driven platform to identify and eliminate cyber risks across all attack surfaces.

IT Services
251-1K
Founded 2014
$292M raised

Description

  • Own the path from research output to production-ready artifacts such as detection rules, distributed feeds, scoring inputs, and customer alerts.
  • Build and maintain STRIKE platform components across distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines.
  • Turn research into shipped detection content including YARA, Sigma, STIX patterns, behavioral indicators, and delivery pipelines.
  • Build correlation pipelines that connect scan data, attack surface signals, vulnerability data, and adversary tracking into customer-facing intelligence.
  • Drive adoption of STIX 2.1 as the unified output schema and TAXII 2.1 as the distribution standard.
  • Define, govern, and extend schemas that remain reliable for downstream teams.
  • Build automation for indicator enrichment, report drafting, corpus correlation, feed normalization, and sandbox triage.
  • Develop safe, production-grade workflows for model-assisted and model-driven research, including retrieval, schema-constrained output, eval harnesses, and logging.
  • Coordinate with engineering, measurement, and platform product teams to ensure research work lands in product.
  • Serve as the engineering bridge between researchers, product managers, platform engineers, and sometimes customers, journalists, or executives.

Requirements

  • Bachelor's or Master's degree in Computer Science, Cybersecurity, or a related technical field, or equivalent self-taught experience with strong public work.
  • 5 to 8 years of hands-on engineering experience with meaningful exposure to threat intelligence, security research, or detection engineering.
  • Prior experience building production systems that consume or emit threat intelligence data is required.
  • Production-level experience with Python and TypeScript/Node.
  • Experience with relational and cache data stores, plus at least one streaming or batch data platform.
  • Experience with cloud infrastructure, preferably AWS, containers, and CI/CD pipelines.
  • Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK.
  • Hands-on experience with YARA, Sigma, and STIX Patterning.
  • Experience reading malware analysis output, parsing adversary infrastructure data, and writing detection logic that performs in production.
  • Experience shipping production language-model systems with retrieval over a real corpus, structured output validation, eval harnesses, and awareness of model failure modes.
  • Strong judgment about when to use models versus simpler approaches such as regex or SQL.
  • Bonus: experience with policy-as-code or expression-language engines such as CEL or OPA.
  • Bonus: published or co-authored security research on campaigns, vulnerabilities, or adversary tracking.
  • Bonus: large-scale telemetry experience with tools such as Splunk, Kinesis, NetFlow, or equivalent.
  • Bonus: contributor or maintainer on open-source threat intel projects such as MISP, OpenCTI, Sigma, STIX, or ATT&CK.
  • Bonus: familiarity with quantitative risk frameworks such as FAIR.
  • Bonus: familiarity with Golang at a production level.

Benefits

  • Competitive salary with estimated total compensation of $140,000 to $150,000 base plus bonus.
  • Stock options and potential equity awards.
  • Health benefits.
  • Unlimited PTO.
  • Parental leave.
  • Tuition reimbursement.
  • Annual performance-based incentive compensation awards.
  • Flexible benefits that vary by country.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Quantum Applications Scientist

QuEra Computing 11-50 Internet Software & Services

QuEra Computing UK is hiring a theoretical researcher to co-design quantum simulation applications for its neutral-atom quantum hardware across materials, chemistry, and nuclear physics use cases.

10 hours, 46 minutes ago

Research Engineer

Cato Networks 251-1K Diversified Telecommunication Services

Cato Networks is hiring a Research Engineer to join its Security Threats team and analyze emerging threats to develop prevention logic for its cloud-based enterprise security platform.

Cybersecurity DNS HTTP IPS PowerShell Python TCP/IP TLS Wireshark
12 hours, 16 minutes ago

Simulation Engineer

Lever 251-1K Professional Services

Humble Robotics is hiring a software engineer for its simulation team to build the systems and tools behind closed-loop model testing, synthetic data generation, and sensor simulation for an autonomous freight platform.

Machine Learning Python
12 hours, 16 minutes ago

Research Engineer

Talentpluto, Inc. 1-10 Recruiting

Research Engineer at a YC-backed AI training data infrastructure company building automated systems to verify and improve data quality across a decentralized marketplace.

1 day, 12 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers