Full Stack Software Engineer, Threat Intelligence Services

Proofpoint
United States
19 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$166,500.0 - $244,200.0
Working hours
Regular working hours
Job source

Tech stack

Contentful JavaScript (Programming Language) Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Amazon Elastic Compute Cloud Application Frameworks Cloud Computing Cyber Security Databases Continuous Integration Data Integration
+30 more
Relational Databases Domain Name System (DNS) Elasticsearch Identity and Access Management Python (Programming Language) PostgreSQL Node.Js Aws Command Line Interface (CLI) Software Engineering SQL Databases Web Applications Data Processing ReactJS Delivery Pipeline Large Language Models Cyber Threat Analysis Amazon Virtual Private Cloud (VPC) Backend Git Fastapi Build Management Containerization Front End Software Development Route53 Functional Programming Cloudwatch Api Gateway Restful APIs Terraform Docker

Job description

The Threat Intelligence Services (TIS) team turns Proofpoint’s threat data and telemetry into intelligence products for customers through reporting, analytics, detection content, and live briefings. Behind that work is a fast-growing suite of internal web applications, data integrations, automation, cloud infrastructure, and a customer-facing CMS. We are hiring a software engineer to build and operate that platform.

You will own tools end to end: standing up and running the team’s AWS environment, building the APIs and integrations that connect internal threat-intel systems, third-party feeds, and AI/LLM services, and shipping the web front-ends and automation the analyst team relies on daily to produce and deliver intelligence at scale. This is a builder role for a full-stack, infrastructure-comfortable engineer who can take an idea from an analyst to a deployed, dependable tool with minimal supervision.

This is the engineering counterpart to our customer-facing Threat Intelligence Analyst role: you make the analysts faster and their output sharper by replacing manual, repetitive workflows with reliable software and ensure that customers can reliably access content and APIs.

Your day-to-day

  • Administer and troubleshoot the team’s AWS environment, including but not limited to EC2, Lambda, storage, networking (VPC, DNS/Route 53, transit gateway, security groups), monitoring, and deployment pipelines.

  • Design and build APIs and integrations (AWS API Gateway) that wire internal threat-intel platforms, third-party threat feeds, and LLM services into the tooling suite.

  • Develop and deploy the web front-ends analysts use to generate and deliver intelligence (React / Node.js; Fuse), including dashboards, report/deck generators, and detection tooling.

  • Maintain and develop enhancements to the headless CMS-based customer threat intel portal, its underlying database (PostgreSQL and Elastic Search) infrastructure, and micro-frontend (Fuse/React)

  • Write Python services (FastAPI) for data processing, report and detection-rule generation, and workflow automation.

  • Model and query data across PostgreSQL and Elastic Search and support headless-CMS-backed content workflows.

  • Partner directly with analysts to identify manual, repetitive intelligence tasks and turn them into automated, maintainable products.

  • Keep the platform secure, observable, and well-documented. You own reliability, troubleshooting, QA, and security for what you ship.

Requirements

  • Languages: Python, JavaScript (React/JSX)

  • Cloud: AWS - Lambda, API Gateway, IAM, Secrets Manager, CloudWatch, ALB/VPC

  • IaC: Terraform / Terramake

  • CMS: dotCMS

  • API/Auth: REST APIs, custom authorizers, JWT / API keys

  • Domain: Threat intelligence / IOC feeds (STIX, MISP, CSV)

  • Tooling: Git, CI/CD, AWS CLI

What you bring to the team (required)

  • 2-5 years of professional software engineering experience and are comfortable delivering and operating production systems with minimal supervision. We are open to candidates around the 2-year mark, but this is not an entry-level role.

  • Hands-on AWS administration: EC2, Lambda, storage, networking, monitoring, and troubleshooting.

  • API development and integration experience; AWS API Gateway preferred.

  • Front-end development with React and Node.js, ideally including Fuse (or a comparable React application framework).

  • Proficiency in Python.

  • SQL and relational database experience, preferably PostgreSQL.

  • Ability to learn new systems and domains quickly and work independently across the full stack infrastructure, backend, and front-end.

Nice to have

  • Micro front-end development and deployment.

  • ElasticSearch.

  • Experience with headless CMSs (e.g., dotCMS, Payload, Strapi, or Contentful).

  • MCP (Model Context Protocol) server development.

  • Containerization (Docker), CI/CD, and infrastructure-as-code.

  • Familiarity with cybersecurity or threat-intelligence concepts as you’ll work shoulder-to-shoulder with analysts, so curiosity about the domain goes a long way (you don’t need to be an analyst yourself).

Benefits & conditions

At Proofpoint, we believe that an exceptional career experience includes a comprehensive compensation and benefits package. Here are just a few reasons you’ll love working with us:

  • Competitive compensation
  • Comprehensive benefits
  • Career success on your terms
  • Flexible work environment
  • Annual wellness and community outreach days
  • Always on recognition for your contributions
  • Global collaboration and networking opportunities

Our Culture:

Our culture is rooted in values that inspire belonging, empower purpose and drive success-every day, for everyone., Consistent with Proofpoint values and applicable law, we provide the following information to promote pay transparency and equity. Our compensation reflects the cost of labor across several U.S. geographic markets, and we pay differently based on those defined markets as set out below. Pay within these ranges varies and depends on job-related knowledge, skills, and experience. The actual offer will be based on the individual candidate. The range provided may represent a candidate range and may not reflect the full range for an individual tenured employee. This role may be eligible for variable compensation and/or equity. We offer a competitive benefits package, including flexible time off, a comprehensive well-being program with two paid Wellbeing Days and two paid Volunteer Days per year, plus a three-week Work from Anywhere option.

Base Pay Ranges:

SF Bay Area, New York City Metro Area: Base Pay Range: 166,500.00 - 244,200.00 USD

California (excludes SF Bay Area), Colorado, Connecticut, Illinois, Washington DC Metro, Maryland, Massachusetts, New Jersey, Texas, Washington, Virginia, and Alaska: Base Pay Range: 136,200.00 - 199,760.00 USD

About the company

Proofpoint is a global leader in human- and agent-centric cybersecurity. We protect how people, data, and AI agents connect across email, cloud, and collaboration tools. Over 80 of the Fortune 100, 10,000 large enterprises, and millions of smaller organizations trust Proofpoint to stop threats, prevent data loss, and build resilience across their people and AI workflows. Our mission is simple: safeguard the digital world and empower people to work securely and confidently. Join us in our pursuit to defend data and protect people.

How We Work:

At Proofpoint you’ll be part of a global team that breaks barriers to redefine cybersecurity guided by our BRAVE core values

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

Videos

See all

Related articles

See all