
Research Systems Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in California, +3 more states.
• Design, construct, and maintain both static and dynamic file analysis pipelines that process artifacts at scale.
• Optimize and manage YARA rule sets and associated tools for testing, performance evaluation, and false-positive control.
• Operate and enhance threat indicator enrichment systems for real-time metadata extraction, scanning, and enrichment.
• Develop and expand threat graph intelligence systems that model the relationships among indicators, malware, infrastructure, and actors.
• Create and sustain dynamic analysis sandboxing and detonation capabilities featuring behavioral telemetry and secure execution environments.
• Establish ingestion and normalization pipelines that connect Censys scan data with external threat intelligence feeds.
• Instrument pipelines for reliability and observability, incorporating logging, monitoring, alerting, and service level agreements (SLAs).
• Collaborate with threat research and detection engineering teams to translate analytical requirements into scalable systems.
• Ensure secure handling and isolation of malicious samples and analysis environments.
• Document architecture, runbooks, and operational procedures.
• Build and manage pipelines and platforms that power Censys threat detection and intelligence capabilities.
• Bachelor’s degree in Computer Science, Engineering, or a related field with equivalent practical experience.
• Over 6 years of experience in building security data pipelines, detection engineering systems, or threat intelligence platforms.
• Proficiency with Synapse or similar graph-based threat intelligence platforms, including graph data modeling.
• Strong programming capabilities in Python and/or Go.
• Practical knowledge of static and dynamic malware analysis tools and pipelines.
• Experience with distributed data pipelines, message queuing systems like Kafka and RabbitMQ, and data storage solutions such as Elasticsearch and S3.
• Familiarity with Docker and Kubernetes for isolated execution environments.
• Proven experience with AWS, GCP, or Azure infrastructures and highly available production systems.
• Demonstrated ability to utilize LLM-based coding aids and agent-based development workflows like Claude Code or Copilot.
• Experience with Synapse, MISP, OpenCTI, or other Threat Intelligence Platforms (TIPs).
• Knowledge of STIX/TAXII.
• Experience analyzing internet-wide scan data.
• Contributions to open source security tools.
• CI/CD experience applied to detection content development.
• Familiarity with security and compliance frameworks such as SOC 2, ISO 27001, or similar.
• Hands-on experience in authoring and managing YARA rules at scale.
• Experience with Strelka or similar file scanning frameworks.
• Eligibility for bonuses and an annual bonus plan for non-sales roles.
• Equity options.
• Comprehensive health, dental, and vision insurance.
• Retirement plan with company contributions.
• Parental leave provisions.
• Mental health and wellness support.
• Flexible paid time off (PTO).
• Professional development stipend.
• Location-specific benefits available for employees outside the U.S.
• Reasonable accommodations for individuals with disabilities.
• In-person onboarding visit to Ann Arbor, Michigan.
CDW
Pipeworks Studios
Fortinet
Get handpicked remote jobs straight to your inbox weekly.