Senior Research Engineer, Threat Intelligence

SecurityScorecard
Atlanta
Workplace: RemoteFull timeFunction: Research & Scientific (R&D)Experience: 5-8 yearsEducation: bachelorsSkills: ["Cross-functional collaboration","Healthy skepticism","Research-to-delivery mindset","Engineering ownership","Communication"]

Join STRIKE, SecurityScorecard’s Threat Intelligence team, and turn research findings into production-ready threat intelligence artifacts. You’ll build and maintain threat-intelligence platform components across services and runtimes, generate detection content (YARA, Sigma, STIX patterns), and drive standards adoption with STIX 2.1 and TAXII 2.1. Partner with adjacent teams to define handoffs, automate research workflows, and ship signals safely into customers’ products.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
SecurityScorecard
SecurityScorecard
2 months ago

Senior Research Engineer, Threat Intelligence

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 13 hours agoStatus: Live

Job Summary

Join STRIKE, SecurityScorecard’s Threat Intelligence team, and turn research findings into production-ready threat intelligence artifacts. You’ll build and maintain threat-intelligence platform components across services and runtimes, generate detection content (YARA, Sigma, STIX patterns), and drive standards adoption with STIX 2.1 and TAXII 2.1. Partner with adjacent teams to define handoffs, automate research workflows, and ship signals safely into customers’ products.
Location: Atlanta
Workplace: Remote
Employment Type: Full time
Job Function: Research & Scientific (R&D)
Seniority: Mid level

Key Responsibilities

  • •Own the end-to-end path from research output to production-ready artifacts such as detection rules, distributed feeds, scoring inputs, or customer alerts.
  • •Build and maintain threat-intelligence platform components across multiple services and runtimes, including distribution servers, sandbox orchestration, OSINT ingestion, and rules engines.
  • •Translate research into shipped detection content (YARA, Sigma, STIX patterns), and build correlation pipelines across scan data, attack surface signals, vulnerability data, and adversary tracking.
  • •Drive standards adoption by defining and governing STIX 2.1 output schemas and TAXII 2.1 distribution, ensuring downstream compatibility.
  • •Engineer automation for research workflows, including indicator enrichment, corpus-grounded retrieval with citations, feed normalization, sandbox triage, and eval harnesses to catch regressions.

Pay and Benefits

Salary: USD 150,000
Equity and Bonus:Equity
Perks:EquityHealth InsurancePaid LeaveParental LeaveLearning Budget

Key Requirements

  • •Bachelor's or Master's in Computer Science, Cybersecurity, or a related technical field, or strong self-taught background with public work.
  • •5 to 8 years in hands-on engineering with exposure to threat intelligence, security research, or detection engineering.
  • •Experience building production systems that consume or emit threat intel data.
  • •Production-level proficiency in Python and TypeScript/Node.
  • •Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK, plus hands-on YARA and Sigma/detection patterning.
Experience:5-8 yearsThreat intelligenceSecurity researchDetection engineeringCybersecurityPlatform engineeringOpen-source threat intel
Education:Bachelor's in Computer Science, Cybersecurity, or a related technical field
Skills:Cross-functional collaborationHealthy skepticismResearch-to-delivery mindsetEngineering ownershipCommunication
Tech Stack:PythonTypeScriptNodeAWSContainersCI/CDSTIX 2.1TAXII 2.1MISPMITRE ATT&CKYARASigmaSTIX patternsSQLRegexCELOPASplunkKinesisNetFlow

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

SecurityScorecard
Provides a cybersecurity ratings platform that continuously assesses and monitors organizations' and third-party vendors' security posture using external data and analytics to help enterprises manage risk, prioritize remediation, and inform vendor risk decisions.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Headquarters: New York, United States
Founded: 2013
WebsiteLinkedIn