Systems Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Fully remote with no regular office attendance required. Candidates outside the US may be considered; compensation is localized according to work location. In-person onboarding in Ann Arbor, Michigan may be required.
Salary: $190,000–$240,000 USD annually for high-cost US locations; $170,000–$220,000 USD annually for other US locations. Candidates outside the US receive location-specific compensation data.
Company
provides internet intelligence and threat insights by mapping internet infrastructure and supporting governments, Fortune 500 companies, and threat intelligence providers.
What you will do
- Design, build, and operate static and dynamic file analysis pipelines for large-scale artifact processing.
- Maintain and optimize YARA rule sets, including testing, performance optimization, and false-positive management.
- Operate threat indicator enrichment systems for metadata extraction, scanning, and real-time enrichment.
- Build threat graph systems that model relationships among indicators, malware, infrastructure, and actors.
- Develop sandboxing and detonation environments with behavioral telemetry collection and secure sample isolation.
- Build ingestion, normalization, observability, documentation, and operational processes for security data systems while partnering with threat researchers and detection engineers.
Requirements
- Bachelor’s degree in Computer Science, Engineering, or equivalent practical experience.
- 6+ years of experience building security data pipelines, detection engineering systems, or threat intelligence platforms.
- Experience with graph-based threat intelligence platforms and graph data modeling, such as Synapse, Maltego, or Neo4j.
- Strong programming skills in Python and/or Go, plus experience with malware analysis tools and pipelines.
- Experience with distributed data pipelines, message queues, data stores, Docker, Kubernetes, and cloud infrastructure such as AWS, GCP, or Azure.
- Demonstrated use of LLM-based coding harnesses and agent-based development workflows.
Nice to have
- Experience with Synapse, MISP, OpenCTI, STIX/TAXII, or other threat intelligence platforms.
- Experience with internet-wide scan data, YARA rule authoring at scale, Strelka, Assemblyline, or FAME.
- Open source contributions to security tooling.
- CI/CD experience for detection content and familiarity with SOC 2 or ISO 27001.
Culture & Benefits
- Fully remote work with location-specific benefits outside the US.
- US benefits include equity, health, dental and vision coverage, retirement contributions, parental leave, mental health and wellness benefits, flexible PTO, and a professional development stipend.
- Annual bonus eligibility is available for eligible non-sales roles.
- Video interviews require cameras to remain on, and candidates may meet a employee during the process.
- Offer recipients complete identity verification through CLEAR.
Hiring process
- Participate in video interviews with cameras on.
- Meet a employee during the interview process if required.
- Complete identity verification through CLEAR after receiving an offer.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →