Threat Intelligence Engineer (REMOTE)

Fusion Cyber 4, LLC
United States
14 days ago
Apply on boards.greenhouse.io
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
5 years minimum
Compensation
$33,280.0
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Code Generation Data Mapping Python (Programming Language) Open Source Technology Large Language Models Mitre Att&ck Cyber Threat Analysis Information Technology

Job description

The Threat Intelligence Engineer is someone with real threat intelligence depth and the technical ability to understand threat feeds’ data model and map it correctly to STIX 2.1, who uses AI to make that work dramatically faster. Someone who can be our threat intelligence SME: writing the use cases, supporting pre-sales and customers, and giving Product the domain expertise that shapes what we build.

Come join an exciting cybersecurity product startup that has closed its Series C funding round! What You Will Do:

  • Map feeds to STIX and own the connector portfolio
  • Design and maintain mappings from commercial, open-source, and community threat intelligence sources into STIX 2.1 objects, relationships, markings, patterning, and extensions while preserving semantic fidelity.
  • Understand threat intel feed data models when API documentation is incomplete, or missing: inspect live payloads, sample data, and vendor dashboards to establish ground truth
  • Own connector lifecycle and quality-from onboarding new sources to detecting schema drift, validating mappings, and ensuring production reliability
  • Work directly with feed, sandbox, DRP, and enrichment partners on integrations and joint use cases
  • Leverage AI to accelerate engineering workflows
  • Build and improve an AI-assisted mapping workflow: infer schemas from sample payloads, propose candidate field-to-STIX mappings from documentation, and flag schema changes, while maintaining rigorous validation and human oversight
  • Be the threat intelligence SME for Product
  • Write threat intelligence use cases that drive product design, and pressure-test new capabilities against real analyst workflows.
  • Partner with Product to shape intelligence workflows, including PIRs, ATT&CK-aligned investigations, threat modeling, prioritization, collaboration, and intelligence-driven automation
  • Represent Cyware on MITRE and industry alliance committees, and bring what you learn back inside
  • Be the threat intelligence SME for the field
  • Serve as the technical threat intelligence expert for customers, prospects, and partners, translating complex intelligence concepts into practical business value
  • Enable Solution Architects, Sales Engineers, and Customer Success Managers with the threat intelligence knowledge and use cases they need to win and deliver, 47 Minutes Ago Remote or Hybrid Texas, USA 16-16 Hourly Junior 16-16 Hourly Junior Fintech * Professional Services * Sales * Financial Services Provide empathetic phone and email support to members, assist with onboarding and account setup, handle high-volume inbound calls, document interactions, and collaborate with team members to share best practices. Achieve

Customer Service

47 Minutes Ago Remote or Hybrid 18-18 Hourly Junior 18-18 Hourly Junior Fintech * Professional Services * Sales * Financial Services Provide empathetic phone and email support to members for onboarding, account setup, and ongoing inquiries. Listen, troubleshoot, document interactions, collaborate with team, and maintain high call volumes while coaching members toward financial solutions. Navan

Event Travel Manager

53 Minutes Ago Easy Apply Remote or Hybrid USA Easy Apply 68K-70K Annually Junior 68K-70K Annually Junior Fintech * Information Technology * Payments * Productivity * Software * Travel * Automation Serve as primary client liaison for Event Travel, providing end-to-end travel support, fare and booking management, program coordination from post-sale to billing, troubleshooting using agent tools, maintaining documentation and SLAs, training on travel platforms, and supporting team leads to maximize revenue and client ROI. Top Skills: AmadeusGoogle WorkspaceExcelMicrosoft PowerpointMicrosoft WordNavan TravelxenNavan/R&M SystemsNdcSabreSlack

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Requirements

  • You are driven, inquisitive, proactive, and energetic
  • You have a growth mindset and are committed to delivering results
  • You thrive in a fast-paced, collaborative environment, * US Citizenship is a requirement of this position in accordance with 8 U.S.C 1324b(a)(2)(C)
  • 5+ years in threat intelligence as an analyst, engineer, or specialist, with hands-on experience on enterprise-scale security products
  • Deep working knowledge of STIX/TAXII 2.1 objects, relationships, patterning, markings, and how to handle source data that does not fit the standard cleanly. You have implemented STIX mappings in production-not just studied the specification
  • Hands-on experience with commercial and open-source threat feeds and enrichment sources (CrowdStrike, Mandiant, Recorded Future, Flashpoint, Intel 471, MISP, etc.), and with threat intelligence platforms
  • Python: you write real code. API clients, parsers, normalizers, validators. This role builds and debugs; it does not spec and hand off
  • Practical AI fluency. You have used LLMs for real technical work: schema inference, data mapping, documentation parsing, code generation, and you know where they fail
  • Strong command of the intelligence lifecycle, MITRE ATT&CK, and the handling of IOCs, TTPs, and threat actors in conjunction with SOC, incident response, and threat hunting operations
  • Comfortable in a customer-facing, cross-functional seat: you can defend a mapping decision to an engineer and explain the value of intelligence to a CISO
  • Demonstrated ability to work successfully with colleagues across different time zones and geographies

We’re a lean team, so your impact will be felt immediately. If this all sounds like a good fit for you, why not join us?

Benefits & conditions

  • We’re not just employees. We’re people. We offer a comprehensive benefits package including time off, paid holidays, retirement plans, insurance coverage and much more.
  • We’ll invest in your career. Our company is growing quickly and we will give you the opportunity to do the same. You will have access to a number of professional development opportunities so that you can keep up with the company’s evolving needs.
  • We offer competitive compensation packages. We deeply value the talent our team brings to the table and believe that fair and equitable total compensation packages are part of our commitment to everyone who works here.
  • We value diversity of people, culture, and ideas.

About the company

Cyware delivers an innovative approach to cybersecurity that unifies threat intelligence, automation, threat response, and vulnerability management with data insights gleaned from assets, users, malware, attackers, and vulnerabilities. Cyware’s Cyber Fusion platform integrates SOAR and TIP technology, enabling collaboration across siloed security teams. Cyware is widely deployed by enterprises, government agencies, and MSSPs, and is the leading threat intelligence sharing platform for global ISACs and CERTs.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on boards.greenhouse.io
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:22 min

Reviewing and troubleshooting code generated by AI assistants

Cassidy Williams · Coffee With Developers

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

2:39 min

Harnessing data mapping tools to identify unmapped opportunities

Laura Möller Laura Möller +3 · World Congress 2024

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:47 min

Understanding the trade-offs of automated code generation

Marco Podien Marco Podien · World Congress 2025

2:14 min

Exploring internal AI product initiatives and global engineering roles

Maria Apazoglou · Coffee With Developers

Videos

See all

Related articles

See all