> Markdown version of [/jobs/ext/2359971-full-stack-software-engineer-threat-intelligence-services](https://www.wearedevelopers.com/jobs/ext/2359971-full-stack-software-engineer-threat-intelligence-services). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Full Stack Software Engineer, Threat Intelligence Services - **Company:** Proofpoint - **Location:** United States - **Experience:** Expert - **Salary:** $166,500.0 - $244,200.0 - **Contract:** Permanent contract - **Skills:** Contentful, JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Amazon Elastic Compute Cloud, Application Frameworks, Cloud Computing, Cyber Security, Databases, Continuous Integration, Data Integration, Relational Databases, Domain Name System (DNS), Elasticsearch, Identity and Access Management, Python (Programming Language), PostgreSQL, Node.Js, Aws Command Line Interface (CLI), Software Engineering, SQL Databases, Web Applications, Data Processing, ReactJS, Delivery Pipeline, Large Language Models, Cyber Threat Analysis, Amazon Virtual Private Cloud (VPC), Backend, Git, Fastapi, Build Management, Containerization, Front End Software Development, Route53, Functional Programming, Cloudwatch, Api Gateway, Restful APIs, Terraform, Docker - **Published:** August 16, 2026 - **Apply:** https://www.dice.com/job-detail/267e5310-a1d0-41c2-9e4d-3a661525cbfc ## About the Role * Languages: Python, JavaScript (React/JSX) * Cloud: AWS - Lambda, API Gateway, IAM, Secrets Manager, CloudWatch, ALB/VPC * IaC: Terraform / Terramake * CMS: dotCMS * API/Auth: REST APIs, custom authorizers, JWT / API keys * Domain: Threat intelligence / IOC feeds (STIX, MISP, CSV) * Tooling: Git, CI/CD, AWS CLI What you bring to the team (required) * 2-5 years of professional software engineering experience and are comfortable delivering and operating production systems with minimal supervision. We are open to candidates around the 2-year mark, but this is not an entry-level role. * Hands-on AWS administration: EC2, Lambda, storage, networking, monitoring, and troubleshooting. * API development and integration experience; AWS API Gateway preferred. * Front-end development with React and Node.js, ideally including Fuse (or a comparable React application framework). * Proficiency in Python. * SQL and relational database experience, preferably PostgreSQL. * Ability to learn new systems and domains quickly and work independently across the full stack infrastructure, backend, and front-end. Nice to have * Micro front-end development and deployment. * ElasticSearch. * Experience with headless CMSs (e.g., dotCMS, Payload, Strapi, or Contentful). * MCP (Model Context Protocol) server development. * Containerization (Docker), CI/CD, and infrastructure-as-code. * Familiarity with cybersecurity or threat-intelligence concepts as you'll work shoulder-to-shoulder with analysts, so curiosity about the domain goes a long way (you don't need to be an analyst yourself). ## Description The Threat Intelligence Services (TIS) team turns Proofpoint's threat data and telemetry into intelligence products for customers through reporting, analytics, detection content, and live briefings. Behind that work is a fast-growing suite of internal web applications, data integrations, automation, cloud infrastructure, and a customer-facing CMS. We are hiring a software engineer to build and operate that platform. You will own tools end to end: standing up and running the team's AWS environment, building the APIs and integrations that connect internal threat-intel systems, third-party feeds, and AI/LLM services, and shipping the web front-ends and automation the analyst team relies on daily to produce and deliver intelligence at scale. This is a builder role for a full-stack, infrastructure-comfortable engineer who can take an idea from an analyst to a deployed, dependable tool with minimal supervision. This is the engineering counterpart to our customer-facing Threat Intelligence Analyst role: you make the analysts faster and their output sharper by replacing manual, repetitive workflows with reliable software and ensure that customers can reliably access content and APIs. Your day-to-day * Administer and troubleshoot the team's AWS environment, including but not limited to EC2, Lambda, storage, networking (VPC, DNS/Route 53, transit gateway, security groups), monitoring, and deployment pipelines. * Design and build APIs and integrations (AWS API Gateway) that wire internal threat-intel platforms, third-party threat feeds, and LLM services into the tooling suite. * Develop and deploy the web front-ends analysts use to generate and deliver intelligence (React / Node.js; Fuse), including dashboards, report/deck generators, and detection tooling. * Maintain and develop enhancements to the headless CMS-based customer threat intel portal, its underlying database (PostgreSQL and Elastic Search) infrastructure, and micro-frontend (Fuse/React) * Write Python services (FastAPI) for data processing, report and detection-rule generation, and workflow automation. * Model and query data across PostgreSQL and Elastic Search and support headless-CMS-backed content workflows. * Partner directly with analysts to identify manual, repetitive intelligence tasks and turn them into automated, maintainable products. * Keep the platform secure, observable, and well-documented. You own reliability, troubleshooting, QA, and security for what you ship. ## Related Videos - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Inside Bitpanda's Tech Stack: Scaling a European Fintech Leader - Markus Dorner](https://www.wearedevelopers.com/videos/1979-inside-bitpanda-s-tech-stack-scaling-a-european-fintech-leader-markus-dorner) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)