SecurityScorecard

Senior Research Engineer, Threat Intelligence

SecurityScorecard
Apply
2 hours ago
Remote, United StatesSenior
H1B Sponsor

Responsibilities

  • Own the research-to-production pipeline, converting malware findings, infrastructure clusters, indicator classes, and behavioral patterns into production-ready detections, feeds, scoring inputs, alerts, and APIs.
  • Build and maintain STRIKE platform components including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines.
  • Create detection content and correlation pipelines using YARA, Sigma, STIX patterns, scan data, attack-surface signals, vulnerability data, and adversary tracking.
  • Drive adoption and governance of STIX 2.1 and TAXII 2.1 as unified output and distribution standards.
  • Automate indicator enrichment, report drafting, corpus correlation, feed normalization, sandbox triage, retrieval, structured output validation, and regression evaluation.
  • Design safe model-assisted workflows with source-grounded retrieval, schema-constrained outputs, prompt versioning, output logging, cost accounting, and latency budgeting.
  • Coordinate with engineering, measurement, platform product, researchers, customers, journalists, and executives to deliver and explain threat intelligence capabilities.

Requirements

  • Bachelor's or Master's degree in Computer Science, Cybersecurity, or a related technical field, or equivalent strong public work from a self-taught practitioner.
  • 5 to 8 years of hands-on engineering experience with meaningful exposure to threat intelligence, security research, or detection engineering.
  • Required experience building production systems that consume or emit threat intelligence data.
  • Production-level Python and TypeScript/Node experience.
  • Experience with relational and cache data stores and at least one streaming or batch data platform.
  • Experience with cloud infrastructure, preferably AWS, containers, and CI/CD pipelines.
  • Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK and how they work together in practice.
  • Hands-on experience with YARA, Sigma, and STIX Patterning, including writing detection logic suitable for production load.
  • Experience reading malware analysis output, parsing adversary infrastructure data, and building production systems using language models with retrieval, structured-output validation, and evaluation harnesses.
  • Ability to assess model limitations, cost, latency, adversarial input, prompt injection, and when deterministic tools such as regex or SQL are more appropriate.
  • Ability to translate between researchers, product managers, platform engineers, and other stakeholders while independently turning ideas into deployed pipelines.
  • Preferred experience with policy-as-code or expression-language engines such as CEL or OPA; published security research; large-scale telemetry such as Splunk, Kinesis, or NetFlow; open-source threat intelligence projects; quantitative risk frameworks such as FAIR; or production-level Golang.

Benefits

  • Competitive salary, stock options, health benefits, unlimited PTO, parental leave, tuition reimbursement, and additional country-specific benefits.
  • The position is based at SecurityScorecard, which states that benefits vary by country.
  • SecurityScorecard does not provide immigration sponsorship for this position.
SecurityScorecard

About SecurityScorecard

501-1,000 employees

Funded by world-class investors, including Evolution Equity Partners, Silver Lake Partners, Sequoia Capital, GV, Riverwood Capital, and others, SecurityScorecard is the global leader in cybersecurity ratings, response, and resilience, with more than 12 million companies continuously rated. Founded in 2013 by security and risk experts Dr. Aleksandr Yampolskiy and Sam Kassoumeh, SecurityScorecard's patented rating technology is used by over 25,000 organizations for enterprise risk management, third-party risk management, board reporting, due diligence, cyber insurance underwriting, and regulatory oversight. SecurityScorecard makes the world a safer place by transforming the way companies understand, improve and communicate cybersecurity risk to their boards, employees, and vendors. SecurityScorecard is listed as a free cyber tool and service by the U.S. Cybersecurity & Infrastructure Security Agency (CISA). Every organization has the universal right to its trusted and transparent Instant SecurityScorecard rating Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh, SecurityScorecard’s patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix security risks across their externally facing digital footprint. SecurityScorecard is the only provider of instant cyber risk ratings that automatically map to vendor cybersecurity questionnaire responses - providing a true 360 degree view of risk. SecurityScorecard continues to make the world a safer place by transforming the way companies understand, improve and communicate security risk to their boards, employees and vendors. To receive an email with your company’s current score, please visit instant.securityscorecard.com.