Senior Research Engineer, Threat Intelligence
Core
Bridge threat intelligence research with production engineering to ship detection rules, feeds, and platform APIs that protect 12M+ companies.
Role type
Senior Research Engineer (Threat Intelligence)
Builds
Production detection artifacts (YARA, Sigma, STIX), distribution feeds, sandbox orchestration, and research automation pipelines.
Domain
Cybersecurity / Threat Intelligence / Security Ratings
Deliverable
production ML models | product features | dashboards & analysis
Required skills
Python, TypeScript/Node, STIX 2.1, TAXII 2.1, YARA, Sigma, MISP, MITRE ATT&CK, relational databases, streaming/batch data platforms, AWS, containers, CI/CD, applied language models (RAG, eval harnesses), schema validation, cost/performance optimization
Preferred skills
Policy-as-code (CEL, OPA), Golang, Splunk/Kinesis/NetFlow, FAIR framework, open-source threat intel contributions
Technologies
Python, TypeScript, Node, AWS, Kubernetes, Docker, Kafka, Kinesis, Splunk, YARA, Sigma, STIX, TAXII, MISP, MITRE ATT&CK
Responsibilities
Own the end-to-end pipeline from research findings to production-ready detection rules and feeds; build and maintain STRIKE platform components including sandbox orchestration and rules engines; develop automation for indicator enrichment, report drafting, and corpus correlation; drive adoption of STIX 2.1 and TAXII 2.1 standards; coordinate cross-functionally to translate research outputs into product features.
Seniority
Senior, hands-on IC