Senior Threat Intelligence Engineer

Cloudflare
Austin, Lisbon
Workplace: HybridFull timeFunction: Administration & Executive AssistanceExperience: 4+ yearsSkills: ["Communication","Collaboration","Problem-solving","Ownership","Initiative"]

We are seeking an experienced Threat Intelligence Engineer who blends threat intelligence with machine learning to transform raw threat data into automated defenses. You’ll research adversaries, profile threat actors, develop detection use cases for the ML lifecycle, integrate security tools, and build automated workflows to reduce MTTD/MTTR across Cloudflare’s security operations.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Cloudflare
Cloudflare
7 months ago

Senior Threat Intelligence Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 5 hours agoStatus: Live

Job Summary

We are seeking an experienced Threat Intelligence Engineer who blends threat intelligence with machine learning to transform raw threat data into automated defenses. You’ll research adversaries, profile threat actors, develop detection use cases for the ML lifecycle, integrate security tools, and build automated workflows to reduce MTTD/MTTR across Cloudflare’s security operations.
Location: Austin, Lisbon
Workplace: Hybrid
Employment Type: Full time
Job Function: Administration & Executive Assistance

Key Responsibilities

  • •Intelligence Collection & Analysis: Proactively research, collect, and analyze threat intelligence from various sources (OSINT, commercial feeds, dark web, and internal security events) to understand the current and emerging threat landscape.
  • •Machine Learning and Data Science: Design, implement, and maintain detection use cases for the entire machine learning lifecycle (data ingestion, training, deployment, and inference).
  • •Threat Actor Profiling: Develop detailed profiles of relevant threat actors, their TTPs using MITRE ATT&CK, and identify potential impacts to the organization.
  • •Actionable Intelligence Dissemination: Produce and disseminate timely, relevant, and actionable intelligence reports and briefings for both technical security teams and executive leadership.
  • •IOC/IOA Management: Engineer the ingestion, enrichment, correlation, and contextualization of Indicators of Compromise (IOCs) and Indicators of Attack (IOAs) into security platforms.

Key Requirements

  • •4+ years of hands-on experience in a Security Engineering, Cyber Threat Intelligence, or Security Automation role.
  • •Strong proficiency in at least one scripting/programming language for automation (e.g., Python).
  • •Deep understanding of the cyber kill chain, threat actor TTPs, common attack vectors, networking protocols, and operating system internals.
  • •Automation Expertise: Proven experience designing and implementing SOAR playbooks and integrating security tools via APIs.
  • •Experience working with commercial and open-source Threat Intelligence Platforms (TIPs) and threat feeds.
Experience:4+ yearsCybersecurityThreat intelligenceSecurity automation
Skills:CommunicationCollaborationProblem-solvingOwnershipInitiative
Languages:English
Tech Stack:PythonSOARSIEMEDRCSPMTerraformAWSAzureGCPAPIs

Company Brief

Cloudflare
Provides a global network and cloud platform that delivers security, performance, and reliability services for web applications, APIs, and Internet properties, including CDN, DDoS protection, DNS, and zero-trust security solutions.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2009
WebsiteLinkedIn