> Markdown version of [/jobs/ext/2209762-staff-security-engineer-threat-intelligence](https://www.wearedevelopers.com/jobs/ext/2209762-staff-security-engineer-threat-intelligence). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Security Engineer, Threat Intelligence - **Company:** Nscale - **Location:** Oña, Spain - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing, Intelligence Analysis, Data Intelligence, Intrusion Detection and Prevention, Machine Learning, Security Information and Event Management, Systems Integration, AI Infrastructure, Enterprise Software Applications, Cloud Platform System, Mitre Att&ck, Malware, Cyber Threat Analysis, Cybercrime, Security Orchestration, Automation & Response - **Published:** August 24, 2026 - **Apply:** https://www.buscojobs.com.es/staff-security-engineer-threat-intelligence-en-ona-ID-368549075 ## About the Role About You8+ years of experience in threat intelligence, security engineering, or detection engineering Strong understanding of threat actors, tactics, techniques, and procedures (TTPs) Experience translating intelligence into detections, rules, or security controls Familiarity with SIEM platforms and detection pipelines Experience with threat intelligence platforms (TIPs) and data formats such as STIX/TAXII Understanding of cloud environments and modern infrastructure Experience leveraging automation or AI/ML techniques for intelligence analysis or enrichment Ability to operate at a Staff level, driving strategy, influencing detection programs, and owning systems Clear communication skills with the ability to share insights and risks with technical teams and leadership Nice to have: experience in AI infrastructure, threat hunting, incident response, SOAR integrations, malware analysis, or advanced threat actor tracking ## Description Staff Security Engineer, Threat IntelligenceAMERAbout NscaleNscale is the GPU cloud engineered for AI.We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers.Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development.Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency.As an Nscaler, you'll build trust through openness and transparency, where everyone is inspired to do their best work.If you join our team, you'll be contributing to building the technology that powers the future.About the RoleWe're hiring a Staff Security Engineer, Threat Intelligence to build and scale Nscale's threat intelligence capability and turn adversary insight into actionable security outcomes.This is a high-impact, engineering-driven role focused on connecting external threat intelligence with internal telemetry so that what Nscale knows about attackers directly improves how the company detects and responds.The role works closely with Detection & Response and supports security efforts across infrastructure, cloud, and enterprise systems.You'll help strengthen Nscale's security posture by tracking relevant threat actors, campaigns, and emerging techniques, then translating that intelligence into practical detections, defenses, and response improvements.This role matters because it ensures intelligence is not just collected, but operationalized in the systems and workflows that protect the business.This role will be part of the global CISO organization.What you'll be doingTrack relevant threat actors, campaigns, and emerging attack techniques tied to Nscale's environmentAnalyze adversary tactics, techniques, and procedures to identify meaningful security implicationsProduce actionable threat intelligence tailored to infrastructure, cloud, and enterprise systemsEvaluate external intelligence sources, feeds, and tooling for relevance and qualityDetection Engineering & CoverageTranslate intelligence into detection logic, SIEM rules, and security controlsPartner with Detection & Response to improve coverage against known adversary behaviorsMaintain mappings to frameworks such as MITRE ATT&CK and identify coverage gapsImprove defensive visibility by aligning detections to current and emerging threatsSystems Integration & AutomationIntegrate threat intelligence into SIEM pipelines, enrichment systems, and automation workflowsLeverage AI and automation to process large volumes of threat data and surface patternsSupport the use of intelligence data within operational security systems and workflowsSupport incident response and threat hunting with contextual intelligence and hypothesis generationCommunicate insights, risks, and adversary activity clearly to technical teams and leadershipEnable more effective response playbooks by embedding intelligence into response workflowsKPIsThreat intelligence integrated into SIEM pipelines and automation workflowsDetection coverage against known adversary behaviorsCoverage gap tracking through MITRE ATT&CK mappingsActionable intelligence produced for infrastructure, cloud, and enterprise systemsAbout You8+ years of experience in threat intelligence, security engineering, or detection engineeringStrong understanding of threat actors, tactics, techniques, and procedures (TTPs)Experience translating intelligence into detections, rules, or security controlsFamiliarity with SIEM platforms and detection pipelinesExperience with threat intelligence platforms (TIPs) and data formats such as STIX/TAXIIUnderstanding of cloud environments and modern infrastructureExperience leveraging automation or AI/ML techniques for intelligence analysis or enrichmentAbility to operate at a Staff level, driving strategy, influencing detection programs, and owning systemsClear communication skills with the ability to share insights and risks with technical teams and leadershipNice to have: experience in AI infrastructure, threat hunting, incident response, SOAR integrations, malware analysis, or advanced threat actor trackingWhat we can offer youAt Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact.We're building something extraordinary, and we want you at the core.Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)