Remote job
Threat Intelligence Engineer
Job details
About this role
Role overview
Build the engineering foundation that enables a threat-intelligence function to collect, process, analyze, and disseminate security information at scale. This individual-contributor role combines data engineering, security automation, infrastructure, platform integration, and operational visibility. You will work closely with intelligence analysts to turn requirements into dependable tools, workflows, dashboards, and data services.
Responsibilities
- Architect, build, and maintain infrastructure for collecting, processing, storing, and analyzing cyber-threat-intelligence data. - Create scalable automations, data pipelines, integrations, and centralized access patterns for intelligence operations. - Apply engineering practices that improve data quality, reliability, observability, and operational awareness. - Partner with analysts to translate operational needs into high-performing technical solutions. - Configure and maintain threat-intelligence platforms and connect structured threat data to enterprise security tools. - Produce technical documentation, interactive dashboards, and metrics that show system performance and business impact.
Requirements
- At least 3 years of experience in threat-intelligence engineering, incident response, security automation, or data engineering. - Hands-on experience using generative AI in security operations, including prompt design, model benchmarking, and integration into intelligence workflows. - Experience deploying and maintaining threat-intelligence platforms and integrating structured threat data. - Proficiency creating and managing interactive Python notebooks, configuring data connections, building reusable workflows, and documenting analysis. - Bachelor’s or master’s degree in Computer Science, Cybersecurity, or a related field, or equivalent practical experience. - Strong written and verbal communication skills for explaining complex technical concepts.
Nice to have
- Experience with cloud data platforms, automation services, and infrastructure as code in AWS, Azure, or GCP. - Git-based development practices including pull requests, code review, CI/CD, and automated testing. - Integrations with SIEM, SOAR, EDR/XDR, vulnerability-management, or case-management systems. - Familiarity with STIX/TAXII, MITRE ATT&CK, Python, SQL, APIs, and relational, graph, or search databases.
Benefits and work setup
- Hybrid position requiring access to an office and typically at least two in-office days per week; frequency may vary by team.