Threat Intelligence Engineer

New
C
CywareCybersecurity
United States, RemoteFull-TimeMiddle
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
5+ years
Required Skills
PythonArtificial IntelligenceRESTful APIs

Requirements

  • 5+ years of experience in threat intelligence as an analyst, engineer, or specialist.
  • Hands-on experience with enterprise-scale security products.
  • Deep working knowledge of STIX/TAXII 2.1 objects, relationships, patterning, and markings.
  • Proven experience implementing production-level STIX mappings.
  • Proficiency in Python for building API clients, parsers, and normalizers.
  • Practical fluency using LLMs for technical tasks like code generation and data mapping.
  • Strong command of the intelligence lifecycle and MITRE ATT&CK framework.
  • Experience handling IOCs, TTPs, and threat actors in SOC or incident response environments.
  • Familiarity with commercial and open-source threat feeds (e.g., CrowdStrike, Mandiant, Recorded Future, MISP).
  • Ability to operate in a customer-facing, cross-functional capacity.

Responsibilities

  • Design and maintain mappings from commercial and open-source threat intelligence sources into STIX 2.1 objects and relationships.
  • Inspect live payloads and sample data to establish ground truth when documentation is incomplete.
  • Own connector lifecycle, from onboarding new sources to ensuring production reliability.
  • Build and improve AI-assisted workflows for schema inference and data mapping with human oversight.
  • Write threat intelligence use cases to drive product design and test capabilities against analyst workflows.
  • Represent Cyware on MITRE and industry alliance committees.
  • Serve as a technical expert for customers and enable internal Sales and Customer Success teams.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now