
Senior Research Engineer, Threat Intelligence
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in United States.
• Become a part of STRIKE, the Threat Intelligence team at SecurityScorecard, serving as the engineering liaison to research.
• Take ownership of the transition from research artifacts to production-ready alerts, scoring inputs, detections, or feeds.
• Establish handoff agreements with related teams, which include schemas, value framing, and consumption patterns.
• Develop and maintain platform components across various areas, including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines.
• Enhance production systems while ensuring existing data contracts remain intact.
• Transform research into YARA, Sigma, STIX patterns, behavioral indicators, and distribution pipelines.
• Create correlation pipelines that connect scan data, attack surface signals, vulnerability data, and adversary tracking into customer-facing intelligence.
• Promote the use of STIX 2.1 as a singular output schema and TAXII 2.1 as a distribution standard.
• Define and oversee schemas that are ready for downstream usage.
• Automate processes for indicator enrichment, report generation, corpus correlation, feed normalization, and sandbox triage.
• Construct workflows based on retrieval, schema-constrained outputs, regression evaluation harnesses, cost accounting, latency budgets, prompt versioning, and output logging.
• Collaborate with engineering, measurement, and platform product teams to integrate research into products.
• Serve as a translator between researchers, product managers, and platform engineers; occasionally presenting work to customers, journalists, or executives.
• Report to the Head of Threat Research for personnel management while receiving technical guidance from R&D leadership.
• A Bachelor's or Master's degree in Computer Science, Cybersecurity, or a related technical field; self-taught professionals with impressive public portfolios are encouraged to apply.
• Between 5 to 8 years in a practical engineering role with significant experience in threat intelligence, security research, or detection engineering.
• Previous experience in developing production systems that utilize or generate threat intelligence data is essential.
• Proficiency in Python and TypeScript/Node at a production level.
• Familiarity with relational and cache data stores, along with experience in at least one streaming or batch data platform.
• Knowledge of cloud infrastructure (AWS preferred), containers, and CI/CD pipelines.
• A solid understanding of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK, and their practical applications.
• Practical experience with YARA, Sigma, and STIX Patterning.
• Ability to interpret malware analysis results, analyze adversary infrastructure data, and devise detection logic that performs well under production load.
• Experience in deploying production systems that leverage language models, including retrieval capabilities over a real corpus, structured outputs with schema validation, evaluation harnesses, and an understanding of model failure modes.
• Capability to conduct cost-per-task assessments and compare smaller, tightly scaffolded models with larger counterparts.
• Proficiency in writing production code while comprehending research workflows.
• This position does not offer immigration sponsorship.
• Bonus: Experience with policy-as-code or expression-language engines (CEL, OPA, or similar).
• Bonus: Published or co-authored research in the field of security.
• Bonus: Experience with large-scale telemetry tools (Splunk, Kinesis, NetFlow, or equivalent).
• Bonus: Contributor or maintainer of open-source threat intelligence projects.
• Bonus: Familiarity with quantitative risk frameworks such as FAIR.
• Bonus: Experience with Golang at a production level.
• Competitive salary.
• Stock options.
• Health benefits.
• Unlimited paid time off (PTO).
• Parental leave.
• Tuition reimbursement.
• Annual performance-based incentive compensation awards.
• Equity opportunities.
• Reasonable accommodations provided for qualified individuals with disabilities.
Oregon Health & Science University Foundation
LiveKit
Netflix
XBOX
Get handpicked remote jobs straight to your inbox weekly.