Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Research Engineer, Threat Intelligence

$140k - $150k

Zoomcar

About the Role You'll join STRIKE, SecurityScorecard's Threat Intelligence team, as the engineering counterpart to research. STRIKE runs several research motions in parallel, each on its own clock: rapid response to active events, longer product‑tied work, and standards‑anchored research on a quarterly cadence. The path from a finding to a shipped detection or feed gets reinvented every time. That’s the problem this role is here to solve. You'll work directly with the senior technical leader who owns STRIKE’s R&D direction, and report to the Head of Threat Research for people management. Technical direction comes from R&D leadership; you own delivery. You'll take a research artifact (a malware finding, an infrastructure cluster, a new indicator class, a behavioral pattern) and turn it into something the company can use without a second round of engineering: schemas, pipeline hooks, distribution feeds, detection rules, or platform APIs. This isn’t a pure research role, and it isn’t a pure platform role either. Researchers ideate, you ship. Key Responsibilities Research‑to‑Production Pipeline Own the path from research output to production‑ready artifact: a detection rule, a distributed feed, a scoring input, or a customer alert. Partner with adjacent teams to define clean handoff contracts, so new signals arrive downstream with the schema, value framing, and consumption pattern already defined. Threat Intelligence Platform Engineering Build and maintain STRIKE platform components across multiple services and runtimes, including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines that operate over standards‑anchored predicates. Extend these systems without breaking the data contracts already in production. Detection Content and Signal Production Turn research into shipped detection content: YARA, Sigma, STIX patterns, behavioral indicators, and the pipelines that distribute them. Build correlation pipelines that link scan data, attack surface signals, vulnerability data, and adversary tracking into customer‑facing intelligence. Data Model and Standards Adoption Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard. Define and govern schemas that hold up once they reach downstream teams. Research Workflow Engineering Build the automation that removes commodity overhead from research work: indicator enrichment, report drafting, corpus correlation, feed normalization, and sandbox triage. Help move the team from analyst‑driven, model‑assisted workflows toward model‑driven workflows with analyst review. The work that matters most here is often the unglamorous part: retrieval grounded in the team’s own corpus so outputs cite sources rather than model priors, schema‑constrained output so a generated indicator is a valid one, and eval harnesses that catch regressions before analysts do. Cost accounting, latency budgeting, prompt versioning, and output logging round out the infrastructure that makes a workflow safe to run unattended. You should have a clear sense of when a model is the wrong tool. A regex beats a model for known patterns; a SQL query beats a model for structured data. Knowing where that line sits, and respecting it, is part of the job. Cross‑Functional Delivery Coordinate with engineering, measurement, and platform product teams so research actually lands in product. You’ll often serve as the engineering voice translating between researchers, product managers, and platform engineers, and you may occasionally explain the work to customers, journalists, or executives. Qualifications Education Bachelor’s or Master’s in Computer Science, Cybersecurity, or a related technical field. Self‑taught practitioners with strong public work are welcome. Experience 5 to 8 years in a hands‑on engineering role with meaningful exposure to threat intelligence, security research, or detection engineering. Prior experience building production systems that consume or emit threat intel data is required. Technical Skills Python and TypeScript/Node at a production level Relational and cache data stores, plus at least one streaming or batch data platform Cloud infrastructure (AWS preferred), containers, and CI/CD pipelines Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT\&CK, and how they work together in practice Detection and Research Tooling Hands‑on experience with YARA, Sigma, and STIX Patterning. Comfortable reading malware analysis output, parsing adversary infrastructure data, and writing detection logic that holds up under production load. Applied Language Models You’ve shipped production systems that use language models, not just demos. That includes retrieval over a real corpus, structured output with schema validation, eval harnesses that catch regressions before users do, and a solid understanding of where models fail: recency, long‑tail facts, numerical reasoning, and adversarial input or prompt injection. You can do the cost‑per‑task math for your workloads, and you can make the case when a smaller, tightly scaffolded model beats a larger one. You approach model output with healthy skepticism by default. The bar for shipping a model‑generated indicator or detection is higher than for shipping a regex, and you understand why and design accordingly. Bridge Mindset You write code that ships, and you understand why researchers think the way they do. If you’ve only ever worked from a backlog handed down by a product manager, this probably isn’t the right fit. If you’ve taken an idea sketched out in a chat message and turned it into a deployed pipeline before the next sprint began, that’s the mode we’re looking for. Bonus Experience with policy‑as‑code or expression‑language engines (CEL, OPA, or similar) Published or co‑authored security research (campaigns, vulnerabilities, adversary tracking) Large‑scale telemetry experience (Splunk, Kinesis, NetFlow, or equivalent) Contributor or maintainer on open‑source threat intel projects (MISP, OpenCTI, Sigma, STIX, ATT\&CK) Familiarity with quantitative risk frameworks such as FAIR Familiarity with Golang at a production level Benefits Specific to each country, we offer a competitive salary, stock options, health benefits, and unlimited PTO, parental leave, tuition reimbursements, and much more! The estimated total compensation range for this position is $140,000 - $150,000 (base plus bonus). Actual compensation for the position is based on a variety of factors, including, but not limited to affordability, skills, qualifications and experience, and may vary from the range. In addition to base salary, employees may also be eligible for annual performance‑based incentive compensation awards and equity, among other company benefits. Equal Employment Opportunity SecurityScorecard is committed to Equal Employment Opportunity and embraces diversity. We believe that our team is strengthened through hiring and retaining employees with diverse backgrounds, skill sets, ideas, and perspectives. We make hiring decisions based on merit and do not discriminate based on race, color, religion, national origin, sex or gender (including pregnancy) gender identity or expression (including transgender status), sexual orientation, age, marital, veteran, disability status or any other protected category in accordance with applicable law. We also consider qualified applicants regardless of criminal histories, in accordance with applicable law. We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need assistance or accommodation due to a disability, please contact View email address on click.appcast.io. Any information you submit to SecurityScorecard as part of your application will be processed in accordance with the Company’s privacy policy and applicable law. SecurityScorecard does not accept unsolicited resumes from employment agencies. Please note that we do not provide immigration sponsorship for this position. #LI-DNI #J-18808-Ljbffr Zoomcar

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Senior Research Engineer, Threat Intelligence in Washington DC vacancy
  • $140k - $150k

    # Senior Research Engineer, Threat Intelligence## SecurityScorecardPublished 18 Jul 2026### Share this jobWashington, DC140K - 150K USD AnnualFull Time## Role Highlights### Languages usedSQLPythonTypeScriptGO### Key skillsPrompt EngineeringComputer ScienceAPIProduct ManagementCICDCloud... 
    Senior
    Intelligence

    Towards AI, Inc.

    Washington DC
    3 days ago
  • $130k - $140k

    Amentum is seeking a Counter Threat Finance Analyst SME in Washington, DC, to support the Department of Defense in creating a certification program. Responsibilities include providing intelligence analysis for law enforcement, drafting reports and action plans, and collaborating... 
    Senior
    Intelligence

    Amentum

    Washington DC
    3 days ago
  • BCMC is seeking a Cyber Threat Intelligence professional to support vulnerability management by proactively gathering and analyzing CTI, disseminating timely insights to inform operational decisions. You will identify emerging threats, vulnerabilities, and countermeasures... 
    Senior
    Intelligence

    bcmcllc

    Arlington, VA
    3 days ago
  • Johns Hopkins Applied Physics Laboratory is seeking a Missile Threat Engineer to join the A4H Applied Technologies and Threat Engineering...  ...threat models, data sets, and scenarios, interfacing with intelligence and DoD sponsors, and presenting findings to management and... 
    Senior
    Intelligence

    Johns Hopkins Applied Physics Laboratory

    Laurel, MD
    3 days ago
  • Revolutional seeks a Lead Cyber Threat Intelligence Analyst to oversee the CTI function for a federal enterprise cybersecurity program. You will identify threats across classified and unclassified streams, craft risk mitigation guidance, and deliver classified briefings... 
    Senior
    Intelligence

    Revolutional

    Suitland, MD
    1 day ago
  • Jobtailor in Washington, DC seeks a Cyber Threat Intelligence professional to monitor and report on evolving threat trends affecting national security and critical infrastructure. You will conduct OSINT investigations, synthesize findings, and prepare executive briefings... 
    Senior
    Intelligence

    Jobtailor

    Washington DC
    1 day ago
  •  ...provide guidance to customers on corrections and status inquiries. The role involves producing Threat Information Reports and all-source research to inform defense intelligence needs. Active TS-SCI clearance is required. The candidate should have 8+ years of relevant... 
    Senior
    Intelligence

    Patriot Defense Group, LLC

    Arlington, VA
    3 days ago
  • Edgewater Federal Solutions, Inc. is seeking a Cyber Threat Intelligence (CTI) Analyst to support an NIH-related government contract. The role requires US citizenship and will involve working on enterprise cyber security, threat intelligence gathering, and incident response... 
    Senior
    Intelligence
    Contract work

    Edgewater Federal Solutions, Inc.

    Bethesda, MD
    2 days ago
  • Synertex LLC in Arlington, VA seeks a Cyber Threat Intelligence Analyst SME to support a national cybersecurity organization client. You will oversee collection, assessment, and analysis of threat intel using Google Threat Intelligence and MITRE ATT&CK, delivering strategic... 
    Senior
    Intelligence

    Synertex LLC

    Arlington, VA
    4 days ago
  • $155.9k - $233.9k

     ...of a federally funded research and development center...  ...based decision support to senior leaders on space...  ...industrial base, and threat reduction to help shape...  ...planning, system of systems engineering, and threat reduction...  ...support agencies, the intelligence community, Congress,... 
    Senior
    Intelligence
    Full time
    Work at office
    Immediate start
    Remote work
    Relocation package
    Flexible hours

    The Aerospace Corporation

    Arlington, VA
    3 days ago
  • LexisNexis Risk Solutions is seeking a Senior Investigative Analyst to support a dedicated federal government customer...  ...You will conduct open-source investigations, evaluate threats, and provide real-time intelligence updates. The role requires joining a multidisciplinary... 
    Senior
    Intelligence

    LexisNexis Risk Solutions

    Washington DC
    1 day ago
  • Amentum is seeking Senior Cyber Intelligence Analysts to support our U.S. Department of Energy contract. Positions will be based in the Washington...  .... Responsibilities include delivering timely, actionable threat intelligence on hostile actors and criminals targeting the... 
    Senior
    Intelligence
    Contract work

    Amentum

    Washington DC
    1 day ago
  • cFocus Software Incorporated is seeking a Cyber Threat Intelligence & Threat Hunting Lead to oversee CTI, detection engineering, and proactive threat hunting operations supporting enterprise cyber defense missions. The Lead will drive development of intelligence-driven... 
    Senior
    Intelligence

    cFocus Software Incorporated

    Washington DC
    5 days ago
  • Everforth ECS seeks a Senior Cyber Incident Analyst to join our Arlington team, coordinating incident response and threat intelligence for government partners. You will design playbooks, guide mitigation strategies, and deliver clear reports to executives and stakeholders... 
    Senior
    Intelligence
    Local area

    ECS Limited

    Arlington, VA
    3 days ago
  • Peraton is seeking a Mobile Threat Analyst based in Arlington, VA. The role involves conducting forensic examinations of mobile devices, analyzing mobile applications for threats, and assessing cybersecurity environments to bolster U.S. missions globally. Candidates should... 
    Senior
    Intelligence
    Full time

    Peraton

    Arlington, VA
    1 day ago
  • $104k - $166k

    Peraton in Arlington, VA is seeking a Mobile Threat Analyst to conduct forensic examinations of mobile devices and analyze mobile applications for threats. The ideal candidate will have a Bachelor’s degree and relevant experience, possess cybersecurity certifications,... 
    Senior
    Intelligence

    Peraton

    Arlington, VA
    2 days ago
  • A defense contractor is seeking a Senior All-Source Analyst (Production / Janus/Hard Target) to support USCYBERCOM J2 in the National Capital...  ...7+ years with a bachelor's degree, alongside knowledge in cyber threat analysis and the ability to work independently. The position... 
    Senior
    Intelligence
    For contractors

    Kinsley Power Systems

    Alexandria, VA
    5 days ago
  •  ...in conducting in-depth analysis of cyber threats, including malware, phishing campaigns,...  ...experience in collecting and aggregating threat intelligence from various sources, such as opensource...  ...to acquire Public Trust Position Senior Cyber Threat Intelligence Analyst... 
    Senior
    Intelligence
    Full time
    Part time
    Work at office

    Avening Management and Technical Services LLC

    Washington DC
    1 day ago
  • $104k - $166k

    ResponsibilitiesPeraton's Cyber Mission sector is looking for a Sr Threat Hunter to support a SOC.Location: Chandler, AZ or Washington DC.Role and Responsibility:Conduct proactive, intelligence-driven threat hunting to identify malicious activity that evades traditional... 
    Senior
    Intelligence
    Contract work
    Shift work

    Peraton Corporation

    Washington DC
    4 days ago
  • $160k - $200k

     ...informed. About the JobWe are looking to add a talented Senior Cyber Threat Operations Engineer to become a key player in our vibrant team dedicated...  ...experience in cyber operations, a profound grasp of threat intelligence, and strong critical thinking skills to address... 
    Senior
    Intelligence
    Permanent employment
    Full time
    Work at office
    Local area
    Remote work
    Worldwide

    Umbra

    Arlington, VA
    4 days ago
  • $116.35k - $210.33k

    Leidos is seeking a Senior Supply Chain Risk Management Threat Intelligence Lead Analyst to provide advanced, high-level technical and analytical support to...  ...Information Technology, Computer Science, Computer Engineering, or a related technical discipline. (Equivalent... 
    Senior
    Intelligence
    Full time
    Work at office
    Shift work

    Leidos

    Washington DC
    2 days ago
  • $148.5k - $223.9k

     ...and you are the future of Salesforce.The Experience:As a Senior Threat Intelligence Researcher (Production), you don't just track threats—you...  ...incident response, threat hunting, threat detection, security engineering, and risk prioritization missions.Consume and curate OSINT... 
    Senior
    Intelligence
    Full time
    Remote work

    Salesforce

    Washington DC
    3 days ago
  • $148.5k - $223.9k

     ...future of Salesforce.Overview:As a Senior Threat Detection Engineer, you will take on complete ownership...  ...for delivering all necessary research and features to achieve our team’s...  ...synthesize findings into actionable intelligence.Knowledge of writing detections based... 
    Senior
    Intelligence
    Full time

    Salesforce

    Washington DC
    2 days ago
  •  ...looking to add an experienced Threat Informed Defense Senior Manager to an already...  ...execute on the technical and engineering core of a global cyber threat intelligence program serving mission-critical...  ...GCDA, or CISSP.Published threat research, detection content, or open-source... 
    Senior
    Intelligence
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Arlington, VA
    1 day ago
  • $119.32k - $202.85k

    ICF is actively recruiting for an experienced Senior Threat Detection & Response Engineer to support the research and development of new cyber analytic capabilities...  ...from multiple sources (e.g., open-source, intelligence products, etc.) 5 or more years of experience with... 
    Senior
    Intelligence
    Full time
    Contract work
    Work experience placement
    Work at office
    Remote work

    ICF

    Arlington, VA
    1 day ago
  •  ...Description Job Title:   Senior Cyber Analyst City:...  ...Core defense intelligence all-source analysis experience...  ...Excellent ability to research, analyze, document,...  ...Defense Intelligence Threat Library, Validated Online...  ...testing experience Engineering background (i.e.,... 
    Senior
    Intelligence
    Work experience placement
    Work at office
    Local area

    Noetic Strategies Inc.

    Alexandria, VA
    2 days ago
  • Salesforce is seeking a Senior Threat Intelligence Researcher (Production) to lead intelligence production across the TI suite and translate findings for a broad audience. You will author reports, brief executives, and support threat disruption across Salesforce ecosystems... 
    Senior
    Intelligence

    Salesforce.Com Inc

    Mc Lean, VA
    2 days ago
  • Salesforce is seeking a Senior Threat Intelligence Researcher (Production) to translate complex threat data into actionable intelligence for executives and teams. You will lead production across our Threat Intelligence suite and shape intelligence outputs for diverse audiences... 
    Senior
    Intelligence

    Salesforce

    Mc Lean, VA
    3 days ago
  • $132k

    A government contractor is seeking a mid- or senior-level All Source Analyst in Arlington, Virginia. This role supports the Army G-...  ...in a relevant field, with at least 10 years of experience in intelligence analysis. The role offers a salary range of $132,000 and includes... 
    Senior
    Intelligence
    For contractors

    Ballygar AI

    Arlington, VA
    5 days ago
  • $90k - $120k

     ...HII works within our nation’s intelligence and cyber operations...  ...cyberspace and anticipate emerging threats. Our capabilities in...  ...network architecture, reverse engineering, software and hardware development...  ...We are seeking talented Mid/Senior Data Engineers (Software... 
    Senior
    Intelligence
    Full time
    Work at office
    Local area
    Remote work
    Work from home
    Worldwide
    Home office

    HII Mission Technologies Division

    Arlington, VA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Research Engineer, Threat Intelligence. Be the first to apply!