
Principal Threat Intelligence Engineer
Posted 5 hours ago

Posted 5 hours ago
This is a fully remote position, open to applicants in California.
• Develop and enhance Snowflake’s Threat Intelligence strategy, focusing on investments in personnel, processes, engineering, and AI-driven capabilities.
• Identify, profile, and monitor threat actors targeting Snowflake, its customers, partners, and the broader ecosystem.
• Convert threat intelligence into actionable insights and security priorities.
• Create intelligence reports, assessments, briefs, and communications suitable for leadership.
• Design automations, collection pipelines, enrichment workflows, and tools for analysts.
• Construct and refine AI-assisted intelligence workflows for tasks such as triage, enrichment, summarization, monitoring, and threat-informed hunts.
• Collaborate with Threat Detection, Incident Response, and other security teams to develop detections, conduct threat hunts, create investigative pivots, and provide control recommendations.
• Oversee alerts, intelligence feeds, vendor reports, and external developments.
• Establish standards for curating, assessing, delivering, and measuring intelligence.
• Mentor engineers and analysts, elevating technical, analytical, and operational maturity.
• Extensive experience in threat intelligence, encompassing adversary, intrusion, supply-chain, identity, domain intelligence, or threat-informed defense.
• Comprehensive understanding of nation-state actors, criminal organizations, ransomware groups, fraud ecosystems, and enabling platforms.
• Proven experience in operationalizing threat intelligence alongside detection, incident response, product security, cloud security, and anti-abuse teams.
• Strong engineering capabilities in Python or Go, automation, and data-intensive security workflows.
• Experience in developing AI-assisted workflows for intelligence analysis, research triage, summarization, collection, prioritization, or investigative support.
• Proficient in researching threat actor TTPs, infrastructure, targets, and objectives, and mapping risks to cloud-native environments.
• Familiarity with OSINT tools, data sources, investigative methodologies, and intelligence reporting.
• Solid understanding of threat hunting and detection methodologies.
• Risk-based approach to security with the ability to prioritize based on business impact and threat conditions.
• Considerable experience in threat intelligence, cyber threat research, intelligence engineering, or associated security fields.
• Experience tracking advanced threat actors targeting cloud-native and SaaS environments.
• Proficiency in coding with Python, Go, or another high-level programming language.
• Experience utilizing SQL and Python to manage security data programmatically at scale.
• Proven ability to collaborate across security functions and communicate effectively with technical stakeholders and leadership.
• Strong understanding of enterprise security controls, threat hunting, and detection methodologies.
• Familiarity with AWS, Azure, or GCP and the security risks associated with cloud/SaaS.
• Snowflake employees are required to adhere to confidentiality and security standards as well as the company's data security plan.
• Eligibility for bonus and equity plans.
• Medical insurance coverage.
• Dental insurance coverage.
• Vision insurance coverage.
• Life insurance coverage.
• Disability insurance coverage.
• 401(k) retirement savings plan.
• Flexible spending account options.
• Health savings account options.
• At least 12 paid holidays per year.
• Paid time off benefits.
• Parental leave offered.
• Employee assistance program available.
• Additional company benefits offered.
RTX
TRC Worldwide Engineering, Inc.
Versar Global Solutions
Alta Material Handling
Get handpicked remote jobs straight to your inbox weekly.