Threat Intelligence Engineer
The job description
Tech stack. MISP, STIX/TAXII feeds, VirusTotal and Recorded Future, Sigma and YARA, Python, MITRE ATT&CK, dark web monitoring sources, link analysis tools
About the role
You will turn raw threat data into operational decisions for a technology company's security team, tracking the specific actors and campaigns most likely to target the business. The threat intelligence function feeds detection engineering, informs security architecture choices, and briefs leadership on the evolving adversary landscape. You will produce finished intelligence, automate indicator pipelines, and build the sharing relationships that provide early warning. This role matters because defenders who truly understand their adversary stop reacting to background noise and start preparing for what is actually coming, which is the fundamental difference between intelligence and trivia. You will also brief product and engineering leaders so threat insight shapes roadmaps and architecture decisions, not just SOC workflows. Your reporting will distinguish assessed judgments from raw data, always.
What you will achieve
- Produce finished intelligence reports that directly drive at least 10 detection or control improvements per quarter across the security program.
- Build and maintain actor profiles for the top threats facing the company's industry, mapped to MITRE ATT&CK techniques defenders can operationalize.
- Automate indicator ingestion and validation so high-confidence IOCs reach blocking controls within one hour.
- Brief leadership quarterly on the threat landscape with clear, honest implications for security investment priorities.
- Establish trusted information-sharing relationships with industry peers providing early warning of sector-targeted campaigns.
What you will bring
Must-haves
- 2 to 5 years in threat intelligence, SOC analysis, or incident response with dedicated intelligence responsibilities.
- Experience with threat intelligence platforms such as MISP and STIX/TAXII-based sharing communities.
- Ability to write finished intelligence: properly assessed, transparently sourced, and tied to specific defensive actions.
- Familiarity with common threat actor TTPs across ransomware, espionage, and fraud ecosystems.
- Python skills for automating collection, enrichment, correlation, and dissemination workflows.
- Strong writing skills adaptable to audiences ranging from SOC analysts to C-level executives.
- Analytical skepticism: you grade sources, challenge assumptions, and mark confidence levels explicitly.
Nice-to-haves
- GCTI or an equivalent threat intelligence certification.
- Foreign language skills relevant to the threat actors under active monitoring.
- Experience with malware sandbox analysis or adversary infrastructure tracking.
- Familiarity with the Diamond Model or kill chain analytic frameworks.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta