Senior Research Engineer, Threat Intelligence

SecurityScorecard
Raleigh
Workplace: RemoteFull timeUSD 140,000 - 150,000 annuallyFunction: Research & Scientific (R&D)Experience: 5-8 yearsEducation: mastersSkills: ["Cross-functional delivery","Engineering ownership","Healthy skepticism","Automation thinking","Bridge mindset"]

Join STRIKE, SecurityScorecard’s Threat Intelligence team, turning threat research into production-ready detections, distributed feeds, and intelligence pipelines. Own delivery from research outputs to shipped artifacts by partnering on handoff contracts and maintaining platform components across services and runtimes. Build detection content (YARA, Sigma, STIX patterns), drive STIX 2.1/TAXII 2.1 adoption, and engineer automation that makes research workflow safe and scalable.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
SecurityScorecard
SecurityScorecard
2 months ago

Senior Research Engineer, Threat Intelligence

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 13 hours agoStatus: Live

Job Summary

Join STRIKE, SecurityScorecard’s Threat Intelligence team, turning threat research into production-ready detections, distributed feeds, and intelligence pipelines. Own delivery from research outputs to shipped artifacts by partnering on handoff contracts and maintaining platform components across services and runtimes. Build detection content (YARA, Sigma, STIX patterns), drive STIX 2.1/TAXII 2.1 adoption, and engineer automation that makes research workflow safe and scalable.
Location: Raleigh
Workplace: Remote
Employment Type: Full time
Job Function: Research & Scientific (R&D)
Seniority: Sr. Manager level

Key Responsibilities

  • •Own the path from research output to production-ready artifacts such as detection rules, distributed feeds, scoring inputs, or customer alerts.
  • •Build and maintain STRIKE threat intelligence platform components across multiple services and runtimes, extending systems without breaking data contracts.
  • •Turn research into shipped detection content using YARA, Sigma, and STIX patterns, and build correlation pipelines that link scan, attack surface, vulnerability, and adversary tracking data.
  • •Drive STIX 2.1 adoption as the unified output schema and TAXII 2.1 for distribution, defining and governing downstream-ready schemas.
  • •Engineer automation for research workflows, including enrichment, corpus correlation, feed normalization, sandbox triage, and eval harnesses to catch regressions.

Pay and Benefits

Salary: USD 140,000 - 150,000 annually
Perks:EquityHealth InsurancePaid LeaveParental LeaveLearning Budget

Key Requirements

  • •Bachelor’s or Master’s in Computer Science, Cybersecurity, or a related technical field, or strong self-taught background with public work.
  • •5 to 8 years in a hands-on engineering role with meaningful exposure to threat intelligence, security research, or detection engineering.
  • •Prior experience building production systems that consume or emit threat intel data.
  • •Production-level Python and TypeScript/Node, with relational/cache data stores and at least one streaming or batch platform.
  • •Hands-on experience with STIX 2.1/TAXII 2.1, MISP, MITRE ATT&CK, plus detection tooling like YARA and Sigma.
Experience:5-8 yearsCybersecurityThreat intelligenceSecurity researchDetection engineering
Education:Master's in Computer Science, Cybersecurity, or a related technical field
Skills:Cross-functional deliveryEngineering ownershipHealthy skepticismAutomation thinkingBridge mindset
Languages:English
Tech Stack:PythonTypeScriptNodeAWSContainersCI/CDSTIX 2.1TAXII 2.1MISPMITRE ATT&CKYARASigmaSTIX PatterningSQLRegexOPACELSplunkKinesisNetFlow

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

SecurityScorecard
Provides a cybersecurity ratings platform that continuously assesses and monitors organizations' and third-party vendors' security posture using external data and analytics to help enterprises manage risk, prioritize remediation, and inform vendor risk decisions.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Headquarters: New York, United States
Founded: 2013
WebsiteLinkedIn