> Markdown version of [/jobs/ext/1451441-security-engineer-cyber-threat-intelligence](https://www.wearedevelopers.com/jobs/ext/1451441-security-engineer-cyber-threat-intelligence). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, Cyber Threat Intelligence - **Company:** Saronic Technologies - **Location:** Austin, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Build Automation, Computer Telephony Integration, Domain Name System (DNS), Data Intelligence, Intrusion Detection and Prevention, Log Analysis, Open Source Intelligence, Raw Data, Security Information and Event Management, Software Engineering, Large Language Models, Mitre Att&ck, Malware, Cyber Threat Analysis, Cybercrime, Free and Open-Source Software, Data Pipelines - **Published:** July 26, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ed3ad17016527ca1 ## About the Role * 4+ years in cyber threat intelligence, threat hunting, detection engineering, or intrusion analysis, or an equivalent combination of experience and demonstrated ability, with demonstrable tracking of sophisticated or state-sponsored adversaries that drove detection, hunting, or response * Fluency with the intelligence lifecycle, Priority Intelligence Requirements and collection management, and structured analytic techniques, and the ability to produce finished intelligence with calibrated confidence * Strong software engineering to build automation, connectors, and data pipelines end to end * Working command of MITRE ATT&CK, the Diamond Model, and the Cyber Kill Chain, plus STIX/TAXII for modeling and sharing intelligence * Hands-on infrastructure and log analysis (passive DNS, certificate pivoting, WHOIS/ASN) and detection authoring (Sigma, YARA, or SIEM-native) * Ability to obtain and maintain a U.S. security clearance, * Nation-state/APT tracking relevant to the defense industrial base, maritime, or manufacturing industries * Standing up or operating an in-house or graph-based CTI platform, MISP, or a TAXII/STIX pipeline * Malware analysis and adversary attribution (provisional clustering; tactical, operational, and strategic attribution) * Cyber-deception design and operations (honeytokens, canaries, decoys), * If your experience doesn't line up with every preferred qualification, we still encourage you to apply; we hire for demonstrated ability and outcomes. ## Description * Priority Intelligence Requirements & Collection: Help own and evolve our Priority Intelligence Requirements and collection-management framework, translating leadership decisions and our maritime-autonomy and defense-industrial-base threat model into tasked collection, hunts, and finished intelligence. * Adversary Tracking: Track the priority adversaries, including nation-state, APT, and advanced criminal actors most likely to target defense, maritime, and the broader industrial base, along with their tooling, infrastructure, and tradecraft, and maintain adversary and campaign profiles. * Turn Intelligence into Action: Operationalize indicators and TTPs into detections, hunts, and prioritized remediation, and build the pipelines and connectors that ingest, enrich, and correlate intel from commercial feeds and OSINT. Turn raw data into verified intelligence products that meaningfully influence decision-making at all levels of the organization. * Fuse Internal & External: Fuse external intelligence with internal telemetry in our graph-based intelligence data store, running attack-path and identity-to-asset correlation to prioritize by real exposure rather than CVSS alone. * Finished Intelligence: Produce concise, actionable intelligence and briefings for security leadership and cross-functional partners, applying analytic tradecraft, estimative language, calibrated confidence, and structured analytic techniques, and modeling with STIX and MITRE ATT&CK. * Hunting & Detection: Develop and run intelligence-driven threat hunts across endpoint, cloud, identity, email, and network telemetry, and author durable detections (Sigma, YARA) with detection engineering and incident response. * Infrastructure & Malware Analysis: Perform infrastructure pivoting (passive DNS, certificate pivoting, WHOIS/ASN) and malware triage to extract indicators, TTPs, and attribution signals. * Digital Risk & Identity Protection: Run deep and dark-web, breach-credential, and identity-exposure monitoring, including account-takeover, executive and VIP protection, and brand-impersonation, and coordinate takedowns with Legal, Comms, and IT. * Deception & Automation: Help design and operate cyber-deception sensors (honeytokens, canaries, decoys) for high-fidelity, low-noise alerts, and build case-automation and in-case AI-agent workflows for enrichment and triage., * Digital risk protection and dark-web tradecraft: breach-credential, executive-protection, and brand-impersonation monitoring and takedowns * Applying LLMs and AI tooling to accelerate collection, enrichment, and analysis, including agentic case automation * DoD/DIB context (CMMC/NIST 800-171, GovCloud, ITAR) and military intelligence doctrine * OT/ICS or maritime security knowledge * Public CTI research, talks, or open-source contributions, * Prolonged periods of sitting at a desk and working on a computer * Occasional standing and walking within the office * Manual dexterity to operate a computer keyboard, mouse, and other office equipment * Visual acuity to read screens, documents, and reports * Occasional reaching, bending, or stooping to access file drawers, cabinets, or office supplies * Lifting and carrying items up to 20 pounds occasionally (e.g., office supplies, packages) ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Data Governance in the Era of AI](https://www.wearedevelopers.com/videos/1622-data-governance-in-the-era-of-ai) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Bringing Clarity to Event Streams: Enabling Analytics and AI Through Rich Metadata](https://www.wearedevelopers.com/videos/1616-bringing-clarity-to-event-streams-enabling-analytics-and-ai-through-rich-metadata) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)