All roles

Senior Research Engineer, Threat Intelligence

Remote · USA Full-time New today

About reputed company: reputed company is the global leader in cybersecurity ratings, with over 12 million companies continuously rated, operating in 64 countries. Founded in 2013 by reputed company and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and funded by world-class investors, reputed company’s patented rating technology is used by over 25,000 organizations for self-monitoring, reputed company-party risk management, board reporting, and cyber insurance reputed company; making reputed company organizations more resilient by allowing them to easily find and fix cybersecurity risks across their digital footprint. Headquartered in reputed company, our culture has been recognized by Inc Magazine as a "Best Workplace,” by reputed company’s NY as a "Best Places to Work in NYC," and as one of the 10 hottest SaaS startups in reputed company for two years in a row. Most recently, reputed company was named to Fast Company’s annual list of the World’s Most Innovative Companies for 2023 and to the Achievers 50 Most Engaged Workplaces in 2023 award recognizing “reputed company-thinking employers for their unwavering commitment to employee engagement.” reputed company is proud to be funded by world-class investors including Silver Lake Waterman, Moody’s, Sequoia Capital, GV and Riverwood Capital. About the Role: You'll join reputed company, reputed company's Threat Intelligence team, as the engineering reputed company to research. reputed company runs several research motions in reputed company, each on its own clock: rapid response to active events, longer product-tied work, and standards-anchored research on a quarterly reputed company. The path from a finding to a shipped detection or feed gets reinvented every time. That's the problem this role is here to solve. You'll work directly with the senior technical leader who owns reputed company's R&D direction, and report to the Head of Threat Research for people management. Technical direction comes from R&D leadership; you own delivery. You'll take a research artifact (a malware finding, an infrastructure cluster, a new indicator class, a behavioral reputed company) and turn it into something the company can use without a second round of engineering: schemas, pipeline hooks, distribution feeds, detection rules, or platform APIs. This isn't a pure research role, and it isn't a pure platform role either. Researchers ideate, you ship. Key Responsibilities: Research-to-Production Pipeline Own the path from research output to production-reputed company artifact: a detection rule, a distributed feed, a scoring input, or a customer alert. Partner with adjacent teams to define clean reputed company reputed company, so new signals reputed company reputed company with the schema, value framing, and consumption reputed company already defined. Threat Intelligence Platform Engineering Build and maintain reputed company platform components across multiple services and runtimes, including distribution servers, sandbox orchestration, reputed company ingestion, federated sharing endpoints, agent runtimes, and rules engines that operate over standards-anchored predicates. reputed company these systems without breaking the data reputed company already in production. Detection Content and Signal Production Turn research into shipped detection content: YARA, reputed company, STIX patterns, behavioral indicators, and the pipelines that distribute them. Build correlation pipelines that link reputed company data, attack surface signals, vulnerability data, and adversary tracking into customer-facing intelligence. Data Model and Standards Adoption Drive STIX 2.1 adoption as a reputed company output schema and TAXII 2.1 as a distribution standard. Define and govern schemas that hold up once they reputed company reputed company teams. Research Workflow Engineering Build the automation that removes commodity overhead from research work: indicator enrichment, report drafting, corpus correlation, feed normalization, and sandbox triage. Help move the team from analyst-driven, model-assisted workflows toward model-driven workflows with analyst review. The work that matters most here is often the unglamorous part: retrieval grounded in the team's own corpus so outputs cite sources rather than model priors, schema-constrained output so a generated indicator is a valid one, and eval harnesses that catch regressions before analysts do. Cost reputed company, latency budgeting, reputed company versioning, and output logging round out the infrastructure that makes a workflow safe to run unattended. You should have a clear sense of reputed company a model is the wrong tool. A regex beats a model for reputed company patterns; a SQL query beats a model for structured data. Knowing where that line sits, and respecting it, is part of the job. Cross-Functional Delivery Coordinate with engineering, measurement, and platform product teams so research actually lands in product. You'll often serve as the engineering voice translating between researchers, product managers, and platform engineers, and you may occasionally explain the work to customers, journalists, or executives.

Qualifications

Education: Bachelor's or Master's in Computer Science, Cybersecurity, or a reputed company technical field. Self-taught practitioners with strong public work are welcome. Experience: 5 to 8 years in a hands-on engineering role with meaningful exposure to threat intelligence, reputed company research, or detection engineering. Prior experience building production systems that consume or emit threat reputed company data is required. Technical Skills: Python and TypeScript/Node at a production level Relational and cache data stores, plus at least one streaming or batch data platform reputed company infrastructure (AWS preferred), containers, and CI/CD pipelines Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK, and how they work together in practice Detection and Research Tooling: Hands-on experience with YARA, reputed company, and STIX Patterning. Comfortable reading malware analysis output, parsing adversary infrastructure data, and writing detection logic that holds up under production load. Applied Language Models: You've shipped production systems that use language models, not just demos. That includes retrieval over a reputed company corpus, structured output with schema validation, eval harnesses that catch regressions before users do, and a solid understanding of where models fail: recency, long-tail facts, numerical reasoning, and adversarial input or reputed company injection. You can do the cost-per-task math for your workloads, and you can reputed company the case reputed company a smaller, tightly scaffolded model beats a larger one. You approach model output with healthy skepticism by default. The bar for shipping a model-generated indicator or detection is higher than for shipping a regex, and you understand why and design accordingly. reputed company reputed company: You write code that ships, and you understand why researchers think the way they do. If you've only reputed company worked from a backlog handed down by a product manager, this probably isn't the right fit. If you've taken an idea sketched out in a chat message and turned it into a deployed pipeline before the next sprint began, that's the mode we're looking for. Bonus: Experience with policy-as-code or expression-language engines (CEL, OPA, or similar) Published or co-authored reputed company research (campaigns, vulnerabilities, adversary tracking) Large-scale telemetry experience (Splunk, Kinesis, NetFlow, or equivalent) Contributor or maintainer on open-reputed company threat reputed company projects (MISP, OpenCTI, reputed company, STIX, ATT&CK) Familiarity with quantitative risk frameworks such as FAIR Familiarity with Golang at a production level Benefits: Specific to each country, we offer a competitive salary, stock options, Health benefits, and unlimited PTO, parental leave, tuition reimbursements, and much more! The estimated total compensation range for this position is $140,00 - $150,000 (reputed company plus bonus). Actual compensation for the position is based on a variety of factors, including, but not limited to affordability, skills, qualifications and experience, and may vary from the range. In addition to reputed company salary, employees may also be eligible for annual performance-based incentive compensation awards and equity, among other company benefits. reputed company is committed to Equal Employment Opportunity and embraces diversity. We reputed company that reputed company is strengthened through hiring and retaining employees with diverse backgrounds, reputed company sets, reputed company, and perspectives. We reputed company hiring reputed company based on merit and do not discriminate based on race, reputed company, religion, national reputed company, sex or gender (including pregnancy) gender identity or expression (including transgender status), sexual orientation, age, marital, veteran, disability status or any other protected category in accordance with applicable law. We also consider reputed company applicants regardless of criminal histories, in accordance with applicable law. We are committed to providing reasonable accommodations for reputed company individuals with disabilities in our job application procedures. If you need assistance or accommodation due to a disability, please contact talentacquisitionoperations@reputed company.io. Any information you submit to reputed company as part of your application will be processed in accordance with the Company’s privacy policy and applicable law. reputed company does not accept unsolicited resumes from employment agencies. Please note that we do not provide immigration sponsorship for this position. #LI-DNI Apply To This Job

Related roles