
Senior Research Engineer, Threat Intelligence
SecurityScorecardBase Salary
$140k - $150k/yr
Responsibilities
- Own the path from research findings to production-ready detections, distributed feeds, scoring inputs, customer alerts, and other usable artifacts.
- Build and maintain threat-intelligence platform components including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines.
- Create and distribute YARA, Sigma, STIX patterns, behavioral indicators, and correlation pipelines linking scan, attack-surface, vulnerability, and adversary-tracking data.
- Drive adoption of STIX 2.1 as an output schema and TAXII 2.1 as a distribution standard while governing durable data contracts.
- Automate indicator enrichment, report drafting, corpus correlation, feed normalization, and sandbox triage for research workflows.
- Build safe model-assisted and model-driven workflows with corpus-grounded retrieval, schema-constrained outputs, evaluation harnesses, cost accounting, latency budgets, prompt versioning, and output logging.
- Coordinate with engineering, measurement, and platform product teams to ensure research lands in products and serve as the engineering bridge between researchers, product managers, and platform engineers.
Requirements
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, or a related technical field, or equivalent demonstrated experience through strong public work.
- 5–8 years of hands-on engineering experience with meaningful exposure to threat intelligence, security research, or detection engineering.
- Required experience building production systems that consume or emit threat-intelligence data.
- Production-level Python and TypeScript/Node experience.
- Experience with relational and cache data stores and at least one streaming or batch data platform.
- Experience with cloud infrastructure, preferably AWS, containers, and CI/CD pipelines.
- Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK.
- Hands-on experience with YARA, Sigma, and STIX Patterning, including writing production-grade detection logic.
- Experience reading malware-analysis output and parsing adversary infrastructure data.
- Production experience using language models, including retrieval over a real corpus, schema-validated structured output, regression evaluation harnesses, and understanding of model failure modes and prompt injection.
- Ability to bridge research and engineering, independently turn ideas into deployed pipelines, and collaborate with engineering, measurement, product, customers, journalists, or executives.
- Bonus qualifications include policy-as-code or expression-language experience with CEL or OPA, published security research, large-scale telemetry experience with Splunk, Kinesis, or NetFlow, contributions to open-source threat-intelligence projects, familiarity with FAIR, and production-level Golang experience.
Benefits
- Competitive salary, stock options, health benefits, unlimited PTO, parental leave, and tuition reimbursement are offered, with benefits varying by country.
- The company does not provide immigration sponsorship.
Categories
About SecurityScorecard
Funded by world-class investors, including Evolution Equity Partners, Silver Lake Partners, Sequoia Capital, GV, Riverwood Capital, and others, SecurityScorecard is the global leader in cybersecurity ratings, response, and resilience, with more than 12 million companies continuously rated. Founded in 2013 by security and risk experts Dr. Aleksandr Yampolskiy and Sam Kassoumeh, SecurityScorecard's patented rating technology is used by over 25,000 organizations for enterprise risk management, third-party risk management, board reporting, due diligence, cyber insurance underwriting, and regulatory oversight. SecurityScorecard makes the world a safer place by transforming the way companies understand, improve and communicate cybersecurity risk to their boards, employees, and vendors. SecurityScorecard is listed as a free cyber tool and service by the U.S. Cybersecurity & Infrastructure Security Agency (CISA). Every organization has the universal right to its trusted and transparent Instant SecurityScorecard rating Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh, SecurityScorecard’s patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix security risks across their externally facing digital footprint. SecurityScorecard is the only provider of instant cyber risk ratings that automatically map to vendor cybersecurity questionnaire responses - providing a true 360 degree view of risk. SecurityScorecard continues to make the world a safer place by transforming the way companies understand, improve and communicate security risk to their boards, employees and vendors. To receive an email with your company’s current score, please visit instant.securityscorecard.com.