Senior Research Engineer, Threat Intelligence
$127.5k - $162.5k per yearSecurityscorecard
About SecurityScorecard:
SecurityScorecard is the global leader in cybersecurity ratings, with over 12 million companies continuously rated, operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and funded by world-class investors, SecurityScorecard’s patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their digital footprint.
Headquartered in New York City, our culture has been recognized by Inc Magazine as a "Best Workplace,” by Crain’s NY as a "Best Places to Work in NYC," and as one of the 10 hottest SaaS startups in New York for two years in a row. Most recently, SecurityScorecard was named to Fast Company’s annual list of the World’s Most Innovative Companies for 2023 and to the Achievers 50 Most Engaged Workplaces in 2023 award recognizing “forward-thinking employers for their unwavering commitment to employee engagement.” SecurityScorecard is proud to be funded by world-class investors including Silver Lake Waterman, Moody’s, Sequoia Capital, GV and Riverwood Capital.
About the Role:
You'll join STRIKE, SecurityScorecard's Threat Intelligence team, as the engineering counterpart to research. STRIKE runs several research motions in parallel, each on its own clock: rapid response to active events, longer product-tied work, and standards-anchored research on a quarterly cadence. The path from a finding to a shipped detection or feed gets reinvented every time. That's the problem this role is here to solve.
You'll work directly with the senior technical leader who owns STRIKE's R&D direction, and report to the Head of Threat Research for people management. Technical direction comes from R&D leadership; you own delivery. You'll take a research artifact (a malware finding, an infrastructure cluster, a new indicator class, a behavioral pattern) and turn it into something the company can use without a second round of engineering: schemas, pipeline hooks, distribution feeds, detection rules, or platform APIs.
This isn't a pure research role, and it isn't a pure platform role either. Researchers ideate, you ship.
Key Responsibilities:
Research-to-Production Pipeline
- Own the path from research output to production-ready artifact: a detection rule, a distributed feed, a scoring input, or a customer alert. Partner with adjacent teams to define clean handoff contracts, so new signals arrive downstream with the schema, value framing, and consumption pattern already defined.
Threat Intelligence Platform Engineering
- Build and maintain STRIKE platform components across multiple services and runtimes, including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines that operate over standards-anchored predicates. Extend these systems without breaking the data contracts already in production.
Detection Content and Signal Production
- Turn research into shipped detection content: YARA, Sigma, STIX patterns, behavioral indicators, and the pipelines that distribute them. Build correlation pipelines that link scan data, attack surface signals, vulnerability data, and adversary tracking into customer-facing intelligence.
Data Model and Standards Adoption
- Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard. Define and govern schemas that hold up once they reach downstream teams.
Research Workflow Engineering
- Build the automation that removes commodity overhead from research work: indicator enrichment, report drafting, corpus correlation, feed normalization, and sandbox triage. Help move the team from analyst-driven, model-assisted workflows toward model-driven workflows with analyst review.
- The work that matters most here is often the unglamorous part: retrieval grounded in the team's own corpus so outputs cite sources rather than model priors, schema-constrained output so a generated indicator is a valid one, and eval harnesses that catch regressions before analysts do. Cost accounting, latency budgeting, prompt versioning, and output logging round out the infrastructure that makes a workflow safe to run unattended.
- You should have a clear sense of when a model is the wrong tool. A regex beats a model for known patterns; a SQL query beats a model for structured data. Knowing where that line sits, and respecting it, is part of the job.
Cross-Functional Delivery
- Coordinate with engineering, measurement, and platform product teams so research actually lands in product. You'll often serve as the engineering voice translating between researchers, product managers, and platform engineers, and you may occasionally explain the work to customers, journalists, or executives.
Qualifications
Education: Bachelor's or Master's in Computer Science, Cybersecurity, or a related technical field. Self-taught practitioners with strong public work are welcome.
Experience: 5 to 8 years in a hands-on engineering role with meaningful exposure to threat intelligence, security research, or detection engineering. Prior experience building production systems that consume or emit threat intel data is required.
Technical Skills:
- Python and TypeScript/Node at a production level
- Relational and cache data stores, plus at least one streaming or batch data platform
- Cloud infrastructure (AWS preferred), containers, and CI/CD pipelines
- Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK, and how they work together in practice
Detection and Research Tooling: Hands-on experience with YARA, Sigma, and STIX Patterning. Comfortable reading malware analysis output, parsing adversary infrastructure data, and writing detection logic that holds up under production load.
Applied Language Models: You've shipped production systems that use language models, not just demos. That includes retrieval over a real corpus, structured output with schema validation, eval harnesses that catch regressions before users do, and a solid understanding of where models fail: recency, long-tail facts, numerical reasoning, and adversarial input or prompt injection. You can do the cost-per-task math for your workloads, and you can make the case when a smaller, tightly scaffolded model beats a larger one.
You approach model output with healthy skepticism by default. The bar for shipping a model-generated indicator or detection is higher than for shipping a regex, and you understand why and design accordingly.
Bridge Mindset: You write code that ships, and you understand why researchers think the way they do. If you've only ever worked from a backlog handed down by a product manager, this probably isn't the right fit. If you've taken an idea sketched out in a chat message and turned it into a deployed pipeline before the next sprint began, that's the mode we're looking for.
Bonus:
- Experience with policy-as-code or expression-language engines (CEL, OPA, or similar)
- Published or co-authored security research (campaigns, vulnerabilities, adversary tracking)
- Large-scale telemetry experience (Splunk, Kinesis, NetFlow, or equivalent)
- Contributor or maintainer on open-source threat intel projects (MISP, OpenCTI, Sigma, STIX, ATT&CK)
- Familiarity with quantitative risk frameworks such as FAIR
- Familiarity with Golang at a production level
Benefits:
The estimated total compensation range for this position is $127,500-$162,500 CAD (base plus bonus). Actual compensation for the position is based on a variety of factors, including, but not limited to affordability, skills, qualifications and experience, and may vary from the range. In addition to base salary, employees may also be eligible for annual performance-based incentive compensation awards and equity, among other company benefits.
SecurityScorecard is committed to Equal Employment Opportunity and embraces diversity. We believe that our team is strengthened through hiring and retaining employees with diverse backgrounds, skill sets, ideas, and perspectives. We make hiring decisions based on merit and do not discriminate based on race, color, religion, national origin, sex or gender (including pregnancy) gender identity or expression (including transgender status), sexual orientation, age, marital, veteran, disability status or any other protected category in accordance with applicable law.
We also consider qualified applicants regardless of criminal histories, in accordance with applicable law. We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need assistance or accommodation due to a disability, please contact View email address on jobs.jobcopilot.com.
Any information you submit to SecurityScorecard as part of your application will be processed in accordance with the Company’s privacy policy and applicable law.
SecurityScorecard does not accept unsolicited resumes from employment agencies. Please note that we do not provide immigration sponsorship for this position. #LI-DNI
- ...GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer... ...of the role We're looking for a seasoned Threat Intelligence Engineer to join us as a dedicated Senior Security Engineer, TI. You'll be joining a program...SeniorIntelligenceRemote jobFull time
$120k - $155k per year
...About the Role: We are looking for a Senior Editor, Research & Intelligence to help us understand what our audience actually cares about and turn that into content, products, and measurable audience growth. This role sits at the center of our audience and editorial...SeniorIntelligenceRemote jobFull timeShift work- ...Responsibilities Track external threat actors, campaigns, tactics, and infrastructure across open and closed sources. Build and... ...enrich threat data from internal systems, external feeds, and intelligence partnerships. Conduct on-chain analysis across blockchain activity...IntelligenceFull time
$122k - $140k per year
...with some of the most talented people in the industry. Rockstar is on the lookout for a passionate Associate Principal Threat Intelligence Analyst to join our growing Game Security team. This role will be responsible for identifying and analyzing potential threats...IntelligenceFull timeWork at office- ...by the lack of trustworthy Internet intelligence, we set out to create the industry’s... ...Internet intelligence and actionable threat insights to global governments, over... ...Summary: We’re looking to hire a Senior Backend Software Engineer II to join our team. In this capacity...SeniorIntelligenceFull timeRemote workWorldwideFlexible hours
- ...our hybrid work program, wellness allowance, and year-round social activities and events. We are looking for a Senior Business Intelligence Engineer to join our Business Intelligence team in our Montreal, Toronto or Vancouver office! As a Senior Business Intelligence...SeniorFull timeWork at officeLocal area
- ...contact center. Our platform combines the best of AI and human intelligence to help contact centers discover customer insights and... ...decisions and enhance the overall customer experience. As a Senior Fullstack Engineer , you’ll play a key role in building and scaling the no-...SeniorIntelligenceFull timeWork at officeLocal areaRemote workWork from homeHome office
- ...world’s leading mobile-first Asset and Work Intelligence platform for industrial and frontline... ...seeking a highly skilled and motivated Senior Applied Machine Learning Developer to guide... ...to open-source ML frameworks or research in reliability, explainability, or digital...SeniorIntelligenceFull timeImmediate start
- ...Reviewing and analyzing SAP GRC Access Control reports Formulating remediation and security recommendations from GRC reports Hands‑on SAP Fiori security SAP BTP application security SAP Cloud security Enterprise Threat Detection (ETD)...Remote jobFull time
- ...is the global leader in Workforce Intelligence that powers every people decision.... ...Company. Position Overview This senior technical IC role owns Visier’s threat detection and response capabilities... ...the overarching strategy, tooling engineering, detection content, and incident...SeniorIntelligenceFull timeWork at officeImmediate start3 days per week
- ...entertainment businesses of all shapes and sizes all over the world. Two Circles is looking for a creative, modern QA Engineer to join our dynamic KORE Intelligence Platform team. In this role, you'll be part of the Partnership Intelligence team, building modern SaaS platforms...IntelligenceLong term contractFull timeWork at officeShift work2 days per week
- ...across the globe and over 20 vibrant national cultures, working with us means embracing thrilling challenges tailor-made for a star BI Engineer! At Kodify, data is at the heart of how we make decisions. From product and marketing to finance and operations, every team relies...Permanent employmentFull timeInternshipWork at officeRemote workWorldwideFlexible hours
$141.1k - $190.9k per year
...today! Your Role in Supporting Our Members: As the Senior Manager, Intelligent Automation & Orchestration , you will lead the enterprise... ...organization . You will lead a team of automation engineers and drive the integration of RPA, AI/ML, and GenAI capabilities...SeniorLong term contractPermanent employmentFull timeInternshipWork at officeImmediate startRemote workFlexible hours- ...motivated and enthusiastic Cyber Threat and Vulnerability Management... ..., and procedures. Conduct research and stay up to date with the... .... Collaborate with senior analysts and participate in projects... ...network security, threat intelligence, incident response, and vulnerability...SeniorIntelligencePermanent employmentFull timeRemote work
- ...2027 — and we’re expanding our engineering team to deliver the next generation of intelligent, connected flight safety systems... ...hands-on Electronics Engineering Research Specialist to assist with the... ...and reliability. Learn from senior engineers while growing into increasing...SeniorFull time
- ...are looking for a highly skilled and intellectually curious Senior Business Intelligence Analyst to completely modernize how we extract, automate,... ...easily digestible insights. This is not a backend data engineering or data science role. Our data is already structured in...SeniorFull timeWorldwideFlexible hoursShift work
- ...empower our people to be their best. The Business Intelligence Analyst plays a key role in expanding data-driven... ...BI dashboards and data models under the guidance of senior team members. Partner with Data Engineering to help keep our financial and operational data accurate...SeniorFull timeInternshipFlexible hours
$80k - $100k per year
...plus loin. L’opportunité : Partenaire en intelligence des talents Nous recherchons un(e)... ...aisance à interagir avec des parties prenantes senior et des candidats de niveau exécutif.... ...ll Own Talent Intelligence & Strategic Research Build deep understanding of Fluent’s...SeniorIntelligenceLong term contractFull timeApprenticeship- ..., ambiguous datasets to detect weak signals and evolving fraud threats. Develop and recommend upstream safeguards, detection triggers... ...~6+ years’ experience in fraud, financial crimes, cyber-risk, intelligence, or a high-stakes investigative function. ~ Proven ability to...IntelligenceFull timeCasual workLive InWork at officeRemote work
- ...by the lack of trustworthy Internet intelligence, we set out to create the industry’s... ...Internet intelligence and actionable threat insights to global governments, over... ...: We’re looking to hire a Senior Distributed Systems Engineer on our Internet Map Connections team...SeniorIntelligenceFull timeRemote workWorldwideFlexible hours
- ...Securitas, expanding our ability to deliver intelligence-led security at scale. Together, our... ...for a highly skilled and visionary Senior Software Engineer to help us continue to grow and enrich... ...the already sophisticated open source threat intelligence platform we have. You...SeniorIntelligenceFull timeLive InRemote workFlexible hours
- ...and infrastructure with this senior DevOps position. He/she would... ...manage continuous monitoring. Research new technologies to automate... ...to-date with emerging security threats and trends. Monitor and help... ...as a SRE/DevOps/Systems engineer. Minimum 3 years of hands-on...SeniorFull timeRemote workWork from homeFlexible hours
$130k - $150k per year
...About Your Role Tigera is hiring a Senior Security Engineer to own product and cloud security across our product suite. You will lead threat models and security design reviews of new... ...programs, public CVE disclosures, or security research publications Industry certifications...SeniorFull timeFlexible hours$120k - $130k per year
...About the Role Backcountry needs a senior security engineer to protect and harden the multi-cloud... ...cloud, Kubernetes-native stack — from threat detection and incident response to identity... ...protected] . We may use artificial intelligence (AI) tools to support parts of the...SeniorIntelligenceRemote jobFull timeInternshipWork at office- ...the precision of search and the intelligence of AI to enable everyone to accelerate... ..., and execution for Identity Threat Detection and Response (ITDR) within... ...of identity, detection engineering, and AI, partnering with threat researchers, data scientists, and engineers,...IntelligenceFull timeRemote work
$120k - $160k per year
...focused technology company redefining how intelligence specialists train and modernize. We... ...tactical data) into decision-ready outputs for senior stakeholders. Experience reviewing... ..., structured data, and technical teams (engineering depth not required). Nice to have...SeniorIntelligenceFull timeH-2A VisaLive InWork from homeRelocation- ...We are seeking a forward-thinking Senior Security Engineer, AI & DevSecOps to help shape the future... ...business teams to safely leverage artificial intelligence. You'll work at the intersection of AI... .... Perform AI security assessments, threat modeling, and architecture reviews....SeniorIntelligenceFull timeInternshipLocal areaFlexible hours
$159k - $176k per year
...percentage of our revenue back into research and development, ensuring our... .... You are a talented Senior Applied Researcher in AI /... ...scientists, UI/UX researchers, engineers, and healthcare professionals... .... We may use artificial intelligence (AI) tools to support parts of...SeniorIntelligenceRemote jobLong term contractFull timeManual laborWork at officeFlexible hours$120k - $150k per year
...The Role As a Cybersecurity Researcher, you'll be the engine behind what makes Safety's security... ...their code. Your research becomes the intelligence layer behind Safety's Firewall. When... ...rules that protect customers before threats reach production Enrich Vulnerability...IntelligenceFull timeInternshipLocal areaRemote workWorldwideFlexible hours$150k - $200k per year
...patients across North America. As a Senior Software Engineer on our Platform team, you'll build the... ...fundamentals (OWASP Top 10, IAM, threat modeling) Managing public/private networks... ...only. We may use artificial intelligence (AI) tools to support parts of the hiring...SeniorIntelligenceFull timeWork at officeRemote work2 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Research Engineer, Threat Intelligence. Be the first to apply!
