Threat Collections Engineer
Core
Build infrastructure for threat discovery, integrating external data sources and developing automated detection systems to identify abusive behavior.
Role type
Infrastructure engineer for threat intelligence
Builds
Automated detection systems, data pipelines, and tooling for threat investigators
Domain
Cybersecurity / Threat Intelligence
Deliverable
production ML models | infrastructure
Required skills
Python, SQL, data pipeline orchestration (Airflow, DBT), YARA rules, external API integration, web scraping, behavioral analytics
Preferred skills
Threat intelligence frameworks (MISP, STIX/TAXII), MCP servers, LLM automation, anomaly detection
Technologies
Python, SQL, Airflow, DBT, YARA, VirusTotal, Censys, Urlscan, Claude, DBT
Responsibilities
Build automated detection systems using disparate signals; develop and maintain YARA rule infrastructure; create integrations with external threat intelligence platforms; build data pipelines ingesting intelligence from RSS feeds and CTI sources; develop behavioral analytics capabilities; establish feedback loops with investigators; scrape and normalize data from external sources
Seniority
Mid-level to Senior, hands-on IC