3 months ago
São Paulo, BrazilSenior
Responsibilities
- Engineer and maintain enterprise threat intelligence platforms and data sources.
- Design ingestion, enrichment, correlation, and automation pipelines for external, internal, and open-source intelligence.
- Maintain repositories of indicators, threat actor artifacts, metadata, campaigns, and TTPs.
- Integrate CTI with SIEM, SOAR, EDR/XDR, email, identity, and cloud tooling.
- Build automation hooks between CTI platforms and SOAR workflows.
- Provide intelligence support during active incidents and enable detection engineering and threat hunting.
- Support vulnerability management with intelligence about actively exploited vulnerabilities.
- Monitor feed efficacy, improve intelligence quality and delivery speed, and retire low-value sources.
- Define engineering standards and support audits, assurance, and documentation for CTI integrations.
Requirements
- Experience engineering or operating enterprise threat intelligence platforms.
- Hands-on experience integrating CTI with SIEM, SOAR, or EDR/XDR.
- Strong capability with APIs, data transformation, enrichment logic, and automation.
- Solid understanding of threat intelligence concepts and operationalization.
- Experience with Google Threat Intelligence, Recorded Future, or similar platforms.
- Familiarity with MITRE ATT&CK and threat-led detection models.
- Experience supporting incident response or detection engineering teams.
- Relevant certifications such as GCTI, GCIA, GCED, or cloud security certifications.
- Fluent written and spoken English.
Benefits
- Opportunity to work with passionate, inspired people in a collaborative culture.
- Scale and opportunity to influence projects across a global organization.
- Challenging and stimulating work with creative problem solvers.
- Hybrid work arrangement with teams generally in the office around four days per week.
- Accommodation or flexibility may be discussed with the hiring team.
