> Markdown version of [/jobs/ext/1583051-threat-intelligence-engineer](https://www.wearedevelopers.com/jobs/ext/1583051-threat-intelligence-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Threat Intelligence Engineer - **Company:** GitLab - **Location:** Madrid, Spain (Remote available) - **Salary:** €140,000.0 - €200,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Build Automation, Cyber Security, Linux, Python (Programming Language), Open Source Technology, Open Source Intelligence, Red Team (Cyber Security), Reverse Engineering, Data Logging, Malware, Cyber Threat Analysis, Purple Team (Cyber Security) - **Published:** July 18, 2026 - **Apply:** https://www.jobleads.com/es/job/e496bbcc5ba0dd4012594a3b2451acc4d ## About the Role * Proven track record of delivering actionable intelligence that has had a meaningful impact on the security of an organization. * Experience working with a Threat Intelligence Platform (TIP) and managing ingested and exported threat feeds. * Experience researching adversaries using OSINT and structured analytical techniques. * Ability to automate tasks by writing basic scripts or programs, preferably with Python. * Excellent professional communication skills, both written and verbal, with the ability to articulate complex topics clearly and concisely. * Optional: experience reverse-engineering malware, particularly macOS and Linux malware, and malware delivered via code repositories. * Optional: public examples of blogs or open-source work related to threat intelligence. ## Description We are looking for a seasoned Threat Intelligence Engineer to join us as a dedicated Senior Security Engineer, TI. This role is part of a program with an existing foundation of reporting templates, tools, feeds, and industry connections built by the Security Operations team. Your mission will be to provide actionable intelligence that empowers GitLab to make informed, proactive decisions about security, and to get in front of threats before they materialize. You will work in partnership with Security Operations engineers and across security, infrastructure, and product teams to keep our customers, platform, and organization secure., * Monitor the threat landscape, identify and analyze the risks most relevant to GitLab, and raise awareness through ad-hoc Flash Reports. * Administer our Threat Intelligence Platform and continue building out our open-source, proprietary, and internal intelligence collection pipeline. * Support incident response through malware analysis and threat-actor tracking to stay one step ahead of top threats. * Collaborate on Purple Team Flash Operations, turning emerging threats into exercises that validate and improve our defensive capabilities. * Build meaningful relationships with industry peers, share intelligence, and collaborate on emerging threats. * Write code, leverage AI, and build automation to improve process efficiencies on the team., This role is the sole dedicated member of a team within the Security Operations department. You will report to a Security Manager based in Australia who also runs the SIRT APAC Team. Security Operations includes SIRT, Trust and Safety, Signal Engineering, Red Team, and Security Logging. ## Related Videos - [Security Blindspots and How to Learn About Them - Anna Oliveira](https://www.wearedevelopers.com/videos/1754-security-blindspots-and-how-to-learn-about-them-anna-oliveira) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)