
Threat Intelligence Engineer
Posted Jul 30

Posted Jul 30
This is a fully remote position, open to applicants in United States.
• Oversee the mapping of feeds to STIX and manage the connector portfolio.
• Design and sustain mappings from various commercial, open-source, and community threat intelligence sources into STIX 2.1 objects, relationships, markings, patterning, and extensions while maintaining semantic accuracy.
• Comprehend threat intel feed data models even when API documentation is lacking or absent: analyze live payloads, sample data, and vendor dashboards to establish a reliable foundation.
• Manage the entire connector lifecycle and quality—from onboarding new sources to identifying schema drift, validating mappings, and ensuring reliability in production.
• Collaborate directly with feed, sandbox, DRP, and enrichment partners on integrations and shared use cases.
• Utilize AI to enhance engineering workflows.
• Develop and refine an AI-assisted mapping workflow: infer schemas from sample payloads, suggest candidate field-to-STIX mappings based on documentation, and identify schema changes, while ensuring thorough validation and human oversight.
• Act as the subject matter expert (SME) for threat intelligence within the Product team.
• Create threat intelligence use cases that inform product design and rigorously test new capabilities against actual analyst workflows.
• Collaborate with Product to shape intelligence workflows, including PIRs, ATT&CK-aligned investigations, threat modeling, prioritization, collaboration, and automation driven by intelligence.
• Represent Cyware in MITRE and industry alliance committees, bringing insights back into the organization.
• Serve as the field's threat intelligence SME.
• Function as the technical threat intelligence expert for customers, prospects, and partners, translating complex intelligence concepts into actionable business value.
• Equip Solution Architects, Sales Engineers, and Customer Success Managers with the necessary threat intelligence knowledge and use cases for success.
• US Citizenship is a prerequisite for this position in compliance with 8 U.S.C 1324b(a)(2)(C).
• A minimum of 5 years of experience in threat intelligence as an analyst, engineer, or specialist, with practical experience in enterprise-scale security products.
• Extensive working knowledge of STIX/TAXII 2.1 objects, relationships, patterning, markings, and the ability to manage source data that may not align perfectly with the standard. You have implemented STIX mappings in production—not just reviewed the specifications.
• Direct experience with commercial and open-source threat feeds and enrichment sources (such as CrowdStrike, Mandiant, Recorded Future, Flashpoint, Intel 471, MISP, etc.), along with familiarity with threat intelligence platforms.
• Proficiency in Python: you write functional code, including API clients, parsers, normalizers, and validators. This role involves building and debugging rather than simply specifying and handing off.
• Practical understanding of AI. You have used LLMs for genuine technical tasks: schema inference, data mapping, documentation parsing, code generation, and you recognize their limitations.
• Strong grasp of the intelligence lifecycle, MITRE ATT&CK framework, and the management of IOCs, TTPs, and threat actors in conjunction with SOC, incident response, and threat hunting activities.
• Comfortable in a customer-facing, cross-functional role: capable of defending a mapping decision to an engineer and articulating the value of intelligence to a CISO.
• Proven ability to collaborate effectively with colleagues across various time zones and geographic locations.
• We cultivate a dynamic and stimulating start-up culture.
• Our employees are not just staff members; we are individuals.
• We provide a comprehensive benefits package that includes time off, paid holidays, retirement plans, insurance coverage, and much more.
• We are committed to investing in your career. As our company grows rapidly, we will provide you with opportunities to advance as well. You will have access to numerous professional development opportunities to stay aligned with the evolving needs of the company.
• We offer competitive compensation packages. We highly value the talent our team brings and believe that fair and equitable total compensation packages reflect our commitment to everyone who works here.
• We embrace diversity in people, culture, and ideas.
LiteLLM AI Gateway
Snowflake
RTX
C-MORE
Get handpicked remote jobs straight to your inbox weekly.