Назад
Company hidden
3 дня назад

Senior Research Engineer (Threat Intelligence)

14 000 - 180 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Research Engineer (Threat Intelligence) (Python/TypeScript, STIX/TAXII): Turning threat research artifacts into production-ready detections, feeds, scoring inputs, customer alerts, and platform APIs with an accent on threat intelligence platform engineering, detection content, and standards-based data models. Focus on building research automation with retrieval, schema validation, evaluation harnesses, cost and latency controls, and safe model-assisted workflows.

Location: Remote (United States)

Salary: $140,00–$180,000 estimated total compensation range, including base salary and bonus.

Company

hirify.global provides cybersecurity ratings and threat intelligence products for monitoring organizations, managing third-party risk, board reporting, and cyber insurance underwriting.

What you will do

  • Own the path from threat research findings to production-ready detection rules, feeds, scoring inputs, customer alerts, and platform APIs.
  • Build and maintain threat intelligence platform components, including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines.
  • Develop detection content and correlation pipelines using YARA, Sigma, STIX patterns, scan data, attack surface signals, vulnerability data, and adversary tracking.
  • Drive adoption of STIX 2.1 as an output schema and TAXII 2.1 as a distribution standard.
  • Automate indicator enrichment, report drafting, corpus correlation, feed normalization, sandbox triage, retrieval, schema-constrained generation, and evaluation.
  • Coordinate with research, engineering, measurement, product, and platform teams to deliver threat intelligence capabilities into products.

Requirements

  • 5–8 years of hands-on engineering experience with meaningful exposure to threat intelligence, security research, or detection engineering.
  • Production experience building systems that consume or emit threat intelligence data.
  • Production-level Python and TypeScript/Node skills, plus experience with relational and cache data stores and a streaming or batch data platform.
  • Experience with cloud infrastructure, preferably AWS, containers, and CI/CD pipelines.
  • Working knowledge of STIX 2.1, TAXII 2.1, MISP, MITRE ATT&CK, YARA, Sigma, STIX Patterning, malware analysis output, and adversary infrastructure data.
  • Experience shipping production language-model systems with retrieval over a real corpus, schema validation, regression evaluation, and cost and latency controls.

Nice to have

  • Experience with policy-as-code or expression-language engines such as CEL or OPA.
  • Published or co-authored security research, large-scale telemetry experience, or contributions to open-source threat intelligence projects.
  • Familiarity with FAIR risk frameworks or production-level Golang.

Culture & Benefits

  • Remote work arrangement for the United States.
  • Competitive country-specific compensation, stock options, and health benefits.
  • Unlimited PTO, parental leave, and tuition reimbursement.
  • Equal employment opportunity and reasonable workplace accommodations.
  • Immigration sponsorship is not provided for this position.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →