Senior Research Engineer, Threat Intelligence

SecurityScorecard


Job Location:

Raleigh, WV - USA

Monthly Salary: Not Disclosed
Posted on: Yesterday
Vacancies: 1 Vacancy

Job Summary

About SecurityScorecard:

SecurityScorecard is the global leader in cybersecurity ratings with over 12 million companies continuously rated operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and funded by world-class investors SecurityScorecards patented rating technology is used by over 25000 organizations for self-monitoring third-party risk management board reporting and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their digital footprint.

Headquartered in New York City our culture has been recognized by Inc Magazine as a Best Workplace by Crains NY as a Best Places to Work in NYC and as one of the 10 hottest SaaS startups in New York for two years in a row. Most recently SecurityScorecard was named to Fast Companys annual list of the Worlds Most Innovative Companies for 2023 and to the Achievers 50 Most Engaged Workplaces in 2023 award recognizing forward-thinking employers for their unwavering commitment to employee engagement. SecurityScorecard is proud to be funded by world-class investors including Silver Lake Waterman Moodys Sequoia Capital GV and Riverwood Capital.


About the Role:

Youll join STRIKE SecurityScorecards Threat Intelligence team as the engineering counterpart to research. STRIKE runs several research motions in parallel each on its own clock: rapid response to active events longer product-tied work and standards-anchored research on a quarterly cadence. The path from a finding to a shipped detection or feed gets reinvented every time. Thats the problem this role is here to solve.

Youll work directly with the senior technical leader who owns STRIKEs R&D direction and report to the Head of Threat Research for people management. Technical direction comes from R&D leadership; you own delivery. Youll take a research artifact (a malware finding an infrastructure cluster a new indicator class a behavioral pattern) and turn it into something the company can use without a second round of engineering: schemas pipeline hooks distribution feeds detection rules or platform APIs.

This isnt a pure research role and it isnt a pure platform role either. Researchers ideate you ship.


Key Responsibilities:


Research-to-Production Pipeline

  • Own the path from research output to production-ready artifact: a detection rule a distributed feed a scoring input or a customer alert. Partner with adjacent teams to define clean handoff contracts so new signals arrive downstream with the schema value framing and consumption pattern already defined.


Threat Intelligence Platform Engineering

  • Build and maintain STRIKE platform components across multiple services and runtimes including distribution servers sandbox orchestration OSINT ingestion federated sharing endpoints agent runtimes and rules engines that operate over standards-anchored predicates. Extend these systems without breaking the data contracts already in production.


Detection Content and Signal Production

  • Turn research into shipped detection content: YARA Sigma STIX patterns behavioral indicators and the pipelines that distribute them. Build correlation pipelines that link scan data attack surface signals vulnerability data and adversary tracking into customer-facing intelligence.


Data Model and Standards Adoption

  • Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard. Define and govern schemas that hold up once they reach downstream teams.


Research Workflow Engineering

  • Build the automation that removes commodity overhead from research work: indicator enrichment report drafting corpus correlation feed normalization and sandbox triage. Help move the team from analyst-driven model-assisted workflows toward model-driven workflows with analyst review.
  • The work that matters most here is often the unglamorous part: retrieval grounded in the teams own corpus so outputs cite sources rather than model priors schema-constrained output so a generated indicator is a valid one and eval harnesses that catch regressions before analysts do. Cost accounting latency budgeting prompt versioning and output logging round out the infrastructure that makes a workflow safe to run unattended.
  • You should have a clear sense of when a model is the wrong tool. A regex beats a model for known patterns; a SQL query beats a model for structured data. Knowing where that line sits and respecting it is part of the job.


Cross-Functional Delivery

  • Coordinate with engineering measurement and platform product teams so research actually lands in product. Youll often serve as the engineering voice translating between researchers product managers and platform engineers and you may occasionally explain the work to customers journalists or executives.


Qualifications

Education: Bachelors or Masters in Computer Science Cybersecurity or a related technical field. Self-taught practitioners with strong public work are welcome.

Experience: 5 to 8 years in a hands-on engineering role with meaningful exposure to threat intelligence security research or detection engineering. Prior experience building production systems that consume or emit threat intel data is required.

Technical Skills:

  • Python and TypeScript/Node at a production level
  • Relational and cache data stores plus at least one streaming or batch data platform
  • Cloud infrastructure (AWS preferred) containers and CI/CD pipelines
  • Working knowledge of STIX 2.1 TAXII 2.1 MISP and MITRE ATT&CK and how they work together in practice

Detection and Research Tooling: Hands-on experience with YARA Sigma and STIX Patterning. Comfortable reading malware analysis output parsing adversary infrastructure data and writing detection logic that holds up under production load.

Applied Language Models: Youve shipped production systems that use language models not just demos. That includes retrieval over a real corpus structured output with schema validation eval harnesses that catch regressions before users do and a solid understanding of where models fail: recency long-tail facts numerical reasoning and adversarial input or prompt injection. You can do the cost-per-task math for your workloads and you can make the case when a smaller tightly scaffolded model beats a larger one.

You approach model output with healthy skepticism by default. The bar for shipping a model-generated indicator or detection is higher than for shipping a regex and you understand why and design accordingly.

Bridge Mindset: You write code that ships and you understand why researchers think the way they do. If youve only ever worked from a backlog handed down by a product manager this probably isnt the right fit. If youve taken an idea sketched out in a chat message and turned it into a deployed pipeline before the next sprint began thats the mode were looking for.


Bonus:

  • Experience with policy-as-code or expression-language engines (CEL OPA or similar)
  • Published or co-authored security research (campaigns vulnerabilities adversary tracking)
  • Large-scale telemetry experience (Splunk Kinesis NetFlow or equivalent)
  • Contributor or maintainer on open-source threat intel projects (MISP OpenCTI Sigma STIX ATT&CK)
  • Familiarity with quantitative risk frameworks such as FAIR
  • Familiarity with Golang at a production level


Benefits:


Specific to each country we offer a competitive salary stock options Health benefits and unlimited PTO parental leave tuition reimbursements and much more!

The estimated total compensation range for this position is $14000 - $150000 (base plus bonus). Actual compensation for the position is based on a variety of factors including but not limited to affordability skills qualifications and experience and may vary from the addition to base salary employees may also be eligible for annual performance-based incentive compensation awards and equity among other company benefits.

SecurityScorecard is committed to Equal Employment Opportunity and embraces diversity. We believe that our team is strengthened through hiring and retaining employees with diverse backgrounds skill sets ideas and perspectives. We make hiring decisions based on merit and do not discriminate based on race color religion national origin sex or gender (including pregnancy) gender identity or expression (including transgender status) sexual orientation age marital veteran disability status or any other protected category in accordance with applicable law.

We also consider qualified applicants regardless of criminal histories in accordance with applicable law. We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need assistance or accommodation due to a disability please contact

Any information you submit to SecurityScorecard as part of your application will be processed in accordance with the Companys privacy policy and applicable law.

SecurityScorecard does not accept unsolicited resumes from employment agencies. Please note that we do not provide immigration sponsorship for this position. #LI-DNI


Required Experience:

Senior IC

About SecurityScorecard:SecurityScorecard is the global leader in cybersecurity ratings with over 12 million companies continuously rated operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and funded by world-class investors SecurityScorecar...

About Company

Company Logo

Reduce third-party incidents by 75% and transform how your team identifies, monitors, mitigates, and reports on risk.

View Profile View Profile