SecurityScorecard

SecurityScorecard

Senior Research Engineer, Threat Intelligence

Remote (Washington, DC) · Senior

Work authorization required$14k-$150kDetected 14 days ago
TypeScriptPythonGoNode.jsSQLAWSCloud PlatformsCI/CDPlatform EngineeringCybersecurityDetection EngineeringAccountingBudgetingResearchLeadershipUnderwriting

About the role

  • You'll join STRIKE, SecurityScorecard's Threat Intelligence team, as the engineering counterpart to research.
  • The path from a finding to a shipped detection or feed gets reinvented every time.
  • That's the problem this role is here to solve.

Responsibilities

  • Own the path from research output to production-ready artifact: a detection rule, a distributed feed, a scoring input, or a customer alert.
  • Partner with adjacent teams to define clean handoff contracts, so new signals arrive downstream with the schema, value framing, and consumption pattern already defined.
  • Build and maintain STRIKE platform components across multiple services and runtimes, including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines that operate over standards-anchored predicates.
  • Build correlation pipelines that link scan data, attack surface signals, vulnerability data, and adversary tracking into customer-facing intelligence.
  • Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard. Define and govern schemas that hold up once they reach downstream teams.
  • Build the automation that removes commodity overhead from research work: indicator enrichment, report drafting, corpus correlation, feed normalization, and sandbox triage.
  • The work that matters most here is often the unglamorous part: retrieval grounded in the team's own corpus so outputs cite sources rather than model priors, schema-constrained output so a generated indicator is a valid one, and eval harnesses that catch regressions before analysts do.

Requirements

  • Bachelor's or Master's in Computer Science, Cybersecurity, or a related technical field.
  • 5 to 8 years in a hands-on engineering role with meaningful exposure to threat intelligence, security research, or detection engineering.
  • Prior experience building production systems that consume or emit threat intel data is required.
  • Hands-on experience with YARA, Sigma, and STIX Patterning.
  • Education: Bachelor's or Master's in Computer Science, Cybersecurity, or a related technical field. Self-taught practitioners with strong public work are welcome.

Skills

  • Python and TypeScript/Node at a production level
  • Relational and cache data stores, plus at least one streaming or batch data platform
  • Cloud infrastructure (AWS preferred), containers, and CI/CD pipelines
  • Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK, and how they work together in practice
  • Experience with policy-as-code or expression-language engines (CEL, OPA, or similar)
  • Published or co-authored security research (campaigns, vulnerabilities, adversary tracking)
  • Large-scale telemetry experience (Splunk, Kinesis, NetFlow, or equivalent)
  • Contributor or maintainer on open-source threat intel projects (MISP, OpenCTI, Sigma, STIX, ATT&CK)
  • Familiarity with quantitative risk frameworks such as FAIR
  • Familiarity with Golang at a production level
  • Detection and Research Tooling: Hands-on experience with YARA, Sigma, and STIX Patterning.

Compensation

  • Most recently, SecurityScorecard was named to Fast Company's annual list of the World's Most Innovative Companies for 2023 and to the Achievers 50 Most Engaged Workplaces in 2023 award recognizing "forward-thinking employers for their unwav

Benefits

  • Specific to each country, we offer a competitive salary, stock options, Health benefits, and unlimited PTO, parental leave, tuition reimbursements, and much more!
  • The estimated total compensation range for this position is $140,00 - $150,000 (base plus bonus).
  • In addition to base salary, employees may also be eligible for annual performance-based incentive compensation awards and equity, among other company benefits.

Company info

  • SecurityScorecard is the global leader in cybersecurity ratings, with over 12 million companies continuously rated, operating in 64 countries.
  • Founded in 2013 by security and risk experts Dr.
  • Alex Yampolskiy and Sam Kassoumeh and funded by world-class investors, SecurityScorecard's patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their digital footprint.
  • Headquartered in New York City, our culture has been recognized by Inc Magazine as a "Best Workplace," by Crain's NY as a "Best Places to Work in NYC," and as one of the 10 hottest SaaS startups in New York for two years in a row.
  • Most recently, SecurityScorecard was named to Fast Company's annual list of the World's Most Innovative Companies for 2023 and to the Achievers 50 Most Engaged Workplaces in 2023 award recognizing "forward-thinking employers for their unwavering commitment to employee engagement." SecurityScorecard is proud to be funded by world-class investors including Silver Lake Waterman, Moody's, Sequoia Capital, GV and Riverwood Capital.
  • a SQL query beats a model for structured data. Knowing where that line sits, and respecting it, is part of the job.
  • We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures.

Equal opportunity

  • If you need assistance or accommodation due to a disability, please contact talentacquisitionoperations@securityscorecard.io.

Visa & Work Authorization

  • Please note that we do not provide immigration sponsorship for this position. #LI-DNI

This listing is sourced directly from SecurityScorecard's careers page and normalized into a canonical job model.