Threat Intelligence Engineer
New
C
CywareCybersecurity
United States, RemoteFull-TimeMiddle
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years
- Required Skills
- PythonArtificial IntelligenceRESTful APIs
Requirements
- 5+ years of experience in threat intelligence as an analyst, engineer, or specialist.
- Hands-on experience with enterprise-scale security products.
- Deep working knowledge of STIX/TAXII 2.1 objects, relationships, patterning, and markings.
- Proven experience implementing production-level STIX mappings.
- Proficiency in Python for building API clients, parsers, and normalizers.
- Practical fluency using LLMs for technical tasks like code generation and data mapping.
- Strong command of the intelligence lifecycle and MITRE ATT&CK framework.
- Experience handling IOCs, TTPs, and threat actors in SOC or incident response environments.
- Familiarity with commercial and open-source threat feeds (e.g., CrowdStrike, Mandiant, Recorded Future, MISP).
- Ability to operate in a customer-facing, cross-functional capacity.
Responsibilities
- Design and maintain mappings from commercial and open-source threat intelligence sources into STIX 2.1 objects and relationships.
- Inspect live payloads and sample data to establish ground truth when documentation is incomplete.
- Own connector lifecycle, from onboarding new sources to ensuring production reliability.
- Build and improve AI-assisted workflows for schema inference and data mapping with human oversight.
- Write threat intelligence use cases to drive product design and test capabilities against analyst workflows.
- Represent Cyware on MITRE and industry alliance committees.
- Serve as a technical expert for customers and enable internal Sales and Customer Success teams.
View Full Description & ApplyYou'll be redirected to the employer's site