wagey.ggwagey.gg
31,365  jobs31,365  jobs
Browse Tech JobsCompaniesFeaturesPricingFAQs
Log InGet Started Free
Jobs(31,365)/Security Engineer Role(386)/Cyware (2) - Threat Intelligence Engineer
Pro members applied to this job 36 hours before you saw itGet Pro ›
Cyware

Cyware - Threat Intelligence Engineer

Remote - United States3d ago
RemoteSeniorNAInsuranceArtificial IntelligenceSecurity EngineerCISODocumentationProspectingPythonCustomer Success

Requirements

• US Citizenship is a requirement of this position in accordance with 8 U.S.C 1324b(a)(2)(C) • 5+ years in threat intelligence as an analyst, engineer, or specialist, with hands-on experience on enterprise-scale security products • Deep working knowledge of STIX/TAXII 2.1 objects, relationships, patterning, markings, and how to handle source data that does not fit the standard cleanly. You have implemented STIX mappings in production—not just studied the specification • Hands-on experience with commercial and open-source threat feeds and enrichment sources (CrowdStrike, Mandiant, Recorded Future, Flashpoint, Intel 471, MISP, etc.), and with threat intelligence platforms • Python: you write real code. API clients, parsers, normalizers, validators. This role builds and debugs; it does not spec and hand off • Practical AI fluency. You have used LLMs for real technical work: schema inference, data mapping, documentation parsing, code generation, and you know where they fail • Strong command of the intelligence lifecycle, MITRE ATT&CK, and the handling of IOCs, TTPs, and threat actors in conjunction with SOC, incident response, and threat hunting operations • Comfortable in a customer-facing, cross-functional seat: you can defend a mapping decision to an engineer and explain the value of intelligence to a CISO • Demonstrated ability to work successfully with colleagues across different time zones and geographies • We're a lean team, so your impact will be felt immediately. If this all sounds like a good fit for you, why not join us? • You’ll love working at Cyware because • We foster an exciting and challenging start-up culture. • We’re not just employees. We’re people. We offer a comprehensive benefits package including time off, paid holidays, retirement plans, insurance coverage and much more. • We’re not just employees. We’re people. • We’ll invest in your career. Our company is growing quickly and we will give you the opportunity to do the same. You will have access to a number of professional development opportunities so that you can keep up with the company’s evolving needs. • We’ll invest in your career. • We offer competitive compensation packages. We deeply value the talent our team brings to the table and believe that fair and equitable total compensation packages are part of our commitment to everyone who works here. • We offer competitive compensation packages. • We value diversity of people, culture, and ideas. • EEO Statement:

Responsibilities

• Map feeds to STIX and own the connector portfolio • Design and maintain mappings from commercial, open-source, and community threat intelligence sources into STIX 2.1 objects, relationships, markings, patterning, and extensions while preserving semantic fidelity. • Understand threat intel feed data models when API documentation is incomplete, or missing: inspect live payloads, sample data, and vendor dashboards to establish ground truth • Own connector lifecycle and quality—from onboarding new sources to detecting schema drift, validating mappings, and ensuring production reliability • Work directly with feed, sandbox, DRP, and enrichment partners on integrations and joint use cases • Leverage AI to accelerate engineering workflows • Build and improve an AI-assisted mapping workflow: infer schemas from sample payloads, propose candidate field-to-STIX mappings from documentation, and flag schema changes, while maintaining rigorous validation and human oversight • Be the threat intelligence SME for Product • Write threat intelligence use cases that drive product design, and pressure-test new capabilities against real analyst workflows. • Partner with Product to shape intelligence workflows, including PIRs, ATT&CK-aligned investigations, threat modeling, prioritization, collaboration, and intelligence-driven automation • Represent Cyware on MITRE and industry alliance committees, and bring what you learn back inside • Be the threat intelligence SME for the field • Serve as the technical threat intelligence expert for customers, prospects, and partners, translating complex intelligence concepts into practical business value • Enable Solution Architects, Sales Engineers, and Customer Success Managers with the threat intelligence knowledge and use cases they need to win and deliver

Benefits

• The Threat Intelligence Engineer is someone with real threat intelligence depth and the technical ability to understand threat feeds’ data model and map it correctly to STIX 2.1, who uses AI to make that work dramatically faster. Someone who can be our threat intelligence SME: writing the use cases, supporting pre-sales and customers, and giving Product the domain expertise that shapes what we build. • Come join an exciting cybersecurity product startup that has closed its Series C funding round!

Apply in one click

Upload My Resume

Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT

Apply in One Click
Apply in One Click

Similar roles

Temporal TechnologiesTemporal Technologies - Senior Security Engineer, GRC1mo ago
·Remote - United States and Canada - Remote Opportunity·$180k - $225k/year + Equity
RemoteNASeniorFintechCybersecuritySecurity EngineerCISOBashPythonProspectingRecords ManagementGo
RedditReddit - Senior Security Engineer, AI Security1mo ago
·Remote - USA·$191k - $191k/year + Equity
RemoteNASeniorInsuranceArtificial IntelligenceSecurity EngineerGoPythonJavaScriptTypeScriptEmployee Relations
ActiveCampaignActiveCampaign - Senior Security Engineer3w ago
·United States·$126k - $154k/year + Equity
In OfficeNASeniorCloud ComputingLogisticsSecurity EngineerPythonTerraformAWSDocumentationKubernetes
etchedetched - Security Engineer (Remote)1mo ago
·United States - Hybrid·$24k - $24k/year
In OfficeNASeniorCloud ComputingSemiconductorsSecurity EngineerGoBashRustPythonDocumentation
TwilioTwilio - Senior Security Engineer, Incident Response1w ago
·Remote - CT (Central)·$142k - $177k/year + Equity
RemoteNASeniorCloud ComputingArtificial IntelligenceSecurity EngineerAWSGCPDocumentation
GauntletGauntlet - Senior Security Engineer1w ago
·Remote - USA·$180k - $180k/year + Equity
RemoteNASeniorCryptocurrencyArtificial IntelligenceSecurity EngineerPythonTypeScriptJavaScriptClaudeDue Diligence
butterflymxbutterflymx - Sr. Security Engineer3w ago
·Remote - US Remote·$170k - $200k/year
RemoteNASeniorCloud ComputingArtificial IntelligenceSecurity EngineerGoRubyPythonJavaScriptTraining Development
Pair TeamPair Team - Senior Security Engineer1mo ago
·Remote - USA·$208k - $208k/year + Equity
RemoteNASeniorLife InsuranceInsuranceSecurity EngineerRubyTypeScriptPythonData GovernanceAWS
OpenAIOpenAI - Security Engineer, Insider Threat Detection & Response3mo ago
·San Francisco, California, United States·$230k - $385k/year
In OfficeNASeniorCloud ComputingArtificial IntelligenceSecurity EngineerBashPythonIntellectual PropertyLinuxKubernetes

Browse more by category

Show 386 moreSecurity EngineerShow 54 moreCISOShow 5,250 moreDocumentationShow 2,363 moreProspectingShow 5,057 morePythonShow 2,182 moreCustomer Success
Privacy·Terms··Contact·FAQ·Wagey on X