Threat Intelligence Engineer

GitLab
Madrid, Spain
24 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
€140,000.0 - €200,000.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Build Automation Cyber Security Linux Python (Programming Language) Open Source Technology Open Source Intelligence Red Team (Cyber Security) Reverse Engineering Data Logging Malware Cyber Threat Analysis
+1 more
Purple Team (Cyber Security)

Job description

We are looking for a seasoned Threat Intelligence Engineer to join us as a dedicated Senior Security Engineer, TI. This role is part of a program with an existing foundation of reporting templates, tools, feeds, and industry connections built by the Security Operations team.

Your mission will be to provide actionable intelligence that empowers GitLab to make informed, proactive decisions about security, and to get in front of threats before they materialize.

You will work in partnership with Security Operations engineers and across security, infrastructure, and product teams to keep our customers, platform, and organization secure., * Monitor the threat landscape, identify and analyze the risks most relevant to GitLab, and raise awareness through ad-hoc Flash Reports.

  • Administer our Threat Intelligence Platform and continue building out our open-source, proprietary, and internal intelligence collection pipeline.
  • Support incident response through malware analysis and threat-actor tracking to stay one step ahead of top threats.
  • Collaborate on Purple Team Flash Operations, turning emerging threats into exercises that validate and improve our defensive capabilities.
  • Build meaningful relationships with industry peers, share intelligence, and collaborate on emerging threats.
  • Write code, leverage AI, and build automation to improve process efficiencies on the team., This role is the sole dedicated member of a team within the Security Operations department. You will report to a Security Manager based in Australia who also runs the SIRT APAC Team. Security Operations includes SIRT, Trust and Safety, Signal Engineering, Red Team, and Security Logging.

Requirements

  • Proven track record of delivering actionable intelligence that has had a meaningful impact on the security of an organization.
  • Experience working with a Threat Intelligence Platform (TIP) and managing ingested and exported threat feeds.
  • Experience researching adversaries using OSINT and structured analytical techniques.
  • Ability to automate tasks by writing basic scripts or programs, preferably with Python.
  • Excellent professional communication skills, both written and verbal, with the ability to articulate complex topics clearly and concisely.
  • Optional: experience reverse-engineering malware, particularly macOS and Linux malware, and malware delivered via code repositories.
  • Optional: public examples of blogs or open-source work related to threat intelligence.

Benefits & conditions

  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation / Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave, Base salary range for United States residents is $140,000 to $200,000 USD. The role is fully remote with eligibility for specific locations subject to internal policy.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jobleads.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · WWC Europe 2026

2:35 min

Exploring diverse resources for continuous security learning

Stefania Chaplin · WWC 2022

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade · LIVE

Videos

See all

Related articles

See all