Senior Research Engineer, Threat Intelligence

SecurityScorecard
United States
Workplace: RemoteFull timeUSD 14,000 - 180,000 annuallyFunction: Research & Scientific (R&D)Experience: 5-8 yearsSkills: ["Cross-functional collaboration","Healthy skepticism","Shipping mindset"]

Build and maintain the Threat Intelligence (STRIKE) platform components that turn research artifacts into production-ready detections, feeds, scoring inputs, and customer alerts. Own the research-to-production pipeline with clear handoff contracts and production-safe data models. Ship detection content using standards (STIX/TAXII) and tools (YARA/Sigma/MISP/ATT&CK), automate research workflows, and collaborate cross-functionally to ensure signals land in product.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
SecurityScorecard
SecurityScorecard
2 days ago

Senior Research Engineer, Threat Intelligence

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 7 hours agoStatus: Live
Reposted: similar role first listed 1 month ago

Job Summary

Build and maintain the Threat Intelligence (STRIKE) platform components that turn research artifacts into production-ready detections, feeds, scoring inputs, and customer alerts. Own the research-to-production pipeline with clear handoff contracts and production-safe data models. Ship detection content using standards (STIX/TAXII) and tools (YARA/Sigma/MISP/ATT&CK), automate research workflows, and collaborate cross-functionally to ensure signals land in product.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Research & Scientific (R&D)
Seniority: Mid level

Key Responsibilities

  • •Own the research-to-production pipeline by converting research outputs into production-ready artifacts such as detection rules, distributed feeds, scoring inputs, or customer alerts.
  • •Build and maintain STRIKE platform components across services and runtimes, including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines.
  • •Produce detection content and signals using YARA, Sigma, STIX patterns, behavioral indicators, and correlation pipelines that connect scan data, attack surface signals, vulnerability data, and adversary tracking.
  • •Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard, defining and governing schemas that hold up downstream.
  • •Engineer research workflow automation such as indicator enrichment, report drafting, corpus correlation, feed normalization, and sandbox triage, including retrieval grounded in the team’s corpus.

Pay and Benefits

Salary: USD 14,000 - 180,000 annually
Equity and Bonus:Equity
Perks:Health InsurancePaid LeaveParental LeaveLearning Budget

Key Requirements

  • •Bachelor’s or Master’s in Computer Science, Cybersecurity, or a related technical field; self-taught practitioners with strong public work are welcome.
  • •5 to 8 years in a hands-on engineering role with exposure to threat intelligence, security research, or detection engineering, including building production systems that consume or emit threat intel data.
  • •Production-level Python and TypeScript/Node, plus experience with relational and cache data stores and at least one streaming or batch data platform.
  • •Cloud infrastructure (AWS preferred), containers, and CI/CD pipelines.
  • •Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK, plus hands-on experience with YARA, Sigma, and STIX patterning.
Experience:5-8 yearsThreat intelligenceSecurity researchDetection engineering
Education:
Skills:Cross-functional collaborationHealthy skepticismShipping mindset
Languages:English
Tech Stack:PythonTypeScriptNodeAWSContainersCI/CDSTIX 2.1TAXII 2.1MISPMITRE ATT&CKYARASigmaSTIX PatterningSQLSplunkKinesisNetFlowGolangCELOPA

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

SecurityScorecard
Provides a cybersecurity ratings platform that continuously assesses and monitors organizations' and third-party vendors' security posture using external data and analytics to help enterprises manage risk, prioritize remediation, and inform vendor risk decisions.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Headquarters: New York, United States
Founded: 2013
WebsiteLinkedIn