Назад
Company hidden
обновлено 3 дня назад

Senior Research Engineer (Threat Intelligence)

140 000 - 180 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Research Engineer (Threat Intelligence) (Python/TypeScript): Building production pipelines, detection content, distribution feeds, and platform components that turn threat research into customer-facing intelligence with an accent on STIX/TAXII schemas, YARA and Sigma detection logic, and applied language-model workflows. Focus on designing schema-constrained automation, correlating threat signals at production scale, and shipping reliable research artifacts across distributed services.

Location: Remote (Washington, DC), United States

Salary: $140,000–$180,000 annual total compensation, including base salary and bonus.

Company

hirify.global provides cybersecurity ratings and risk-management products used by organizations worldwide to identify and remediate risks across their digital footprints.

What you will do

  • Turn threat research findings such as malware discoveries, infrastructure clusters, indicator classes, and behavioral patterns into production-ready detections, feeds, scoring inputs, and customer alerts.
  • Build and maintain threat intelligence platform components, including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines.
  • Develop detection content and signal-production pipelines using YARA, Sigma, STIX patterns, behavioral indicators, and correlated attack-surface, vulnerability, and adversary data.
  • Drive adoption of STIX 2.1 as an output schema and TAXII 2.1 as a distribution standard.
  • Automate research workflows for indicator enrichment, report drafting, corpus correlation, feed normalization, sandbox triage, and model-assisted analysis.
  • Coordinate delivery with engineering, measurement, platform product, research, and security teams, translating research outputs into shipped product capabilities.

Requirements

  • 5–8 years of hands-on engineering experience with meaningful exposure to threat intelligence, security research, or detection engineering.
  • Production experience building systems that consume or emit threat intelligence data.
  • Production-level Python and TypeScript/Node experience, plus relational and cache data stores and a streaming or batch data platform.
  • Experience with cloud infrastructure, preferably AWS, containers, and CI/CD pipelines.
  • Working knowledge of STIX 2.1, TAXII 2.1, MISP, MITRE ATT&CK, YARA, Sigma, and STIX Patterning.
  • Experience shipping production systems that use language models, including retrieval over real corpora, schema validation, evaluation harnesses, cost accounting, latency budgeting, and protection against prompt injection.

Nice to have

  • Experience with policy-as-code or expression-language engines such as CEL or OPA.
  • Published or co-authored security research and experience with large-scale telemetry.
  • Contributions to open-source threat intelligence projects such as MISP, OpenCTI, Sigma, STIX, or ATT&CK.
  • Familiarity with FAIR risk frameworks or production-level Golang.

Culture & Benefits

  • Remote work specific to the United States location.
  • Competitive salary, stock options, and health benefits.
  • Unlimited paid time off and parental leave.
  • Tuition reimbursement and additional country-specific benefits.
  • Immigration sponsorship is not provided for this position.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →