Threat Intelligence Engineer

🕒 vor 7 Tagen

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👷🏻‍♀️ Ingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Jetzt Bewerben
Ähnliche Remote-Jobs finden

📊 Überprüfen Sie Ihre Lebenslauf-Bewertung für diese Stelle

Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

Logo of Cyware

Cyware

201 - 500 Mitarbeiter

💼 Beratung

🎖️ Verteidigung

🏥 Gesundheitswesen

💰 €30.000.000 Series B im 2021-03

Consulting • Defense • Healthcare

Cyware ist ein Unternehmen, das sich auf informationsgestützte Sicherheitsautomatisierung spezialisiert hat und fortschrittliche Lösungen zur Modernisierung von Sicherheitsoperationen bietet. Cyware bietet Bedrohungsinformationsplattformen (TIPs), die es Organisationen ermöglichen, fragmentierte Bedrohungsdaten miteinander zu verknüpfen, um Geschwindigkeit, Genauigkeit und effektive Sicherheitsresultate zu erleichtern. Durch den Einsatz von Low-Code/No-Code-Automatisierung, KI-gesteuerten Erkenntnissen und nahtloser Orchestrierung zwischen Sicherheits-, IT- und Entwicklungsabläufen befähigt Cyware Organisationen, vom informationsgestützten zum führenden Bedrohungsansatz überzugehen. Ihre Lösungen umfassen Bedrohungsanalyse, Priorisierung und Kollaborationsmöglichkeiten, um Verteidigungsstrategien zu verbessern und Risiken zu mindern. Cywares innovative Technologie wird von führenden Organisationen weltweit vertraut und bietet umfassende Integrationen über den gesamten Cybersecurity-Technologie-Stack hinweg, um intelligentere Ergebnisse und einheitliche Reaktionen zu ermöglichen.

Beschreibung

• Map feeds to STIX and own the connector portfolio • Design and maintain mappings from commercial, open-source, and community threat intelligence sources into STIX 2.1 objects, relationships, markings, patterning, and extensions while preserving semantic fidelity. • Understand threat intel feed data models when API documentation is incomplete, or missing: inspect live payloads, sample data, and vendor dashboards to establish ground truth • Own connector lifecycle and quality—from onboarding new sources to detecting schema drift, validating mappings, and ensuring production reliability • Work directly with feed, sandbox, DRP, and enrichment partners on integrations and joint use cases • Leverage AI to accelerate engineering workflows • Build and improve an AI-assisted mapping workflow: infer schemas from sample payloads, propose candidate field-to-STIX mappings from documentation, and flag schema changes, while maintaining rigorous validation and human oversight • Be the threat intelligence SME for Product • Write threat intelligence use cases that drive product design, and pressure-test new capabilities against real analyst workflows. • Partner with Product to shape intelligence workflows, including PIRs, ATT&CK-aligned investigations, threat modeling, prioritization, collaboration, and intelligence-driven automation • Represent Cyware on MITRE and industry alliance committees, and bring what you learn back inside • Be the threat intelligence SME for the field • Serve as the technical threat intelligence expert for customers, prospects, and partners, translating complex intelligence concepts into practical business value • Enable Solution Architects, Sales Engineers, and Customer Success Managers with the threat intelligence knowledge and use cases they need to win and deliver

🎯 Anforderungen

• US Citizenship is a requirement of this position in accordance with 8 U.S.C 1324b(a)(2)(C) • 5+ years in threat intelligence as an analyst, engineer, or specialist, with hands-on experience on enterprise-scale security products • Deep working knowledge of STIX/TAXII 2.1 objects, relationships, patterning, markings, and how to handle source data that does not fit the standard cleanly. You have implemented STIX mappings in production—not just studied the specification • Hands-on experience with commercial and open-source threat feeds and enrichment sources (CrowdStrike, Mandiant, Recorded Future, Flashpoint, Intel 471, MISP, etc.), and with threat intelligence platforms • Python: you write real code. API clients, parsers, normalizers, validators. This role builds and debugs; it does not spec and hand off • Practical AI fluency. You have used LLMs for real technical work: schema inference, data mapping, documentation parsing, code generation, and you know where they fail • Strong command of the intelligence lifecycle, MITRE ATT&CK, and the handling of IOCs, TTPs, and threat actors in conjunction with SOC, incident response, and threat hunting operations • Comfortable in a customer-facing, cross-functional seat: you can defend a mapping decision to an engineer and explain the value of intelligence to a CISO • Demonstrated ability to work successfully with colleagues across different time zones and geographies.

🏖️ Vorteile

• We foster an exciting and challenging start-up culture. • We’re not just employees. We’re people. • We offer a comprehensive benefits package including time off, paid holidays, retirement plans, insurance coverage and much more. • We’ll invest in your career. Our company is growing quickly and we will give you the opportunity to do the same. You will have access to a number of professional development opportunities so that you can keep up with the company’s evolving needs. • We offer competitive compensation packages. We deeply value the talent our team brings to the table and believe that fair and equitable total compensation packages are part of our commitment to everyone who works here. • We value diversity of people, culture, and ideas.

Jetzt Bewerben

Ähnliche Jobs

🕒 vor 7 Tagen

Cornelis Networks

51 - 200

🤖 Künstliche Intelligenz

🔧 Hardware

🏢 Unternehmen

Senior Ethernet Performance Engineer leading performance validation for Ethernet-based networking silicon products. Collaborating with customers and field teams to optimize system performance in production environments.

🇺🇸 Vereinigte Staaten – Remote

💰 €29.000.000 Series B im 2022-11

⏰ Vollzeit

🟠 Senior

👷🏻‍♀️ Ingenieur

🦅 H1B-Visum-Sponsor

info

🗣️🇺🇸🇬🇧 Englisch erforderlich

Python

Switching

🕒 vor 7 Tagen

Navarro Research and Engineering

201 - 500

💼 Beratung

🎖️ Verteidigung

📦 Logistik

Senior Piping Engineer providing technical leadership for nuclear fuel facility. Focus on high-temperature piping systems and ensuring safety and operability of piping systems.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟠 Senior

👷🏻‍♀️ Ingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 7 Tagen

Navarro Research and Engineering

201 - 500

💼 Beratung

🎖️ Verteidigung

📦 Logistik

Mid to Senior I&C Engineer providing instrumentation and controls engineering support for nuclear fuel facility. Develop and maintain engineering documentation and support integration activities.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟠 Senior

👷🏻‍♀️ Ingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Cyber Security

🕒 vor 7 Tagen

Navarro Research and Engineering

201 - 500

💼 Beratung

🎖️ Verteidigung

📦 Logistik

Mid-to-senior Process Engineer providing engineering support for a nuclear fuel facility at Navarro Research. Focused on calculations, design documentation, and vendor coordination.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟠 Senior

👷🏻‍♀️ Ingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 7 Tagen

Navarro Research and Engineering

201 - 500

💼 Beratung

🎖️ Verteidigung

📦 Logistik

Senior Lead I&C Engineer providing technical leadership for instrumentation and controls in nuclear fuel facility projects. Leading design work, coordinating interfaces, and guiding implementation from design through testing.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟠 Senior

👷🏻‍♀️ Ingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Cyber Security