> Markdown version of [/jobs/ext/2634497-capabilities-developer](https://www.wearedevelopers.com/jobs/ext/2634497-capabilities-developer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Capabilities Developer - **Company:** Dragos, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $152,000.0 - **Contract:** Temporary contract - **Skills:** Cyber Security, Intrusion Detection and Prevention, Data Streaming, Data Processing, Malware, Cybercrime - **Published:** August 6, 2026 - **Apply:** https://job-boards.greenhouse.io/dragos/jobs/5371393008 ## About the Role * 3-5 years of combined experience in cyber threat intelligence, detection engineering, security operations, incident response, or a related cybersecurity discipline. * Working proficiency with Synapse/Storm query language for analytical queries, data manipulation, and collection workflows. * Experience troubleshooting and resolving moderately complex to complex defects in analytical tooling or scripts. * Understanding of Synapse's hypergraph data model, forms, properties, and tag structures. * Familiarity with telemetry and malware analysis tools in support of threat hunting or adversary tracking. * Comfortable writing design documentation and collaborating cross-functionally with hunt, intelligence, product, and engineering teams. * Ability to identify automation opportunities and data-visibility gaps and recommend practical solutions. * Experience contributing to recurring intelligence outputs (e.g., quarterly or annual reporting) is a plus. ## Description Dragos' Capabilities Development team builds the technical foundation behind our OT threat intelligence-not just consuming data, but building the Synapse tooling, collection pipelines, and data models that turn raw threat information into an intelligence fabric for hunters, analysts, and customers. As a Senior Capabilities Developer, you'll build and maintain Synapse collection efforts that feed this fabric, writing Storm queries and automation, shaping tag hierarchies and data models, and scaling collection pipelines across threat groups and temporary activity threats (TATs). You'll partner with the Principal Capabilities Developer and cross-functional teams to resolve complex defects, close data-visibility gaps, and support recurring intelligence outputs, with the opportunity to shape how Dragos operationalizes threat intelligence at scale., * Build and maintain Synapse collection pipelines through Storm queries, automation, data models, and tag hierarchies that support accurate, on-schedule threat data flow. * Diagnose and resolve complex defects in Synapse tooling and collection systems independently, escalating architectural questions as needed. * Support threat hunting and adversary tracking using telemetry and malware analysis techniques across multiple threat groups and infrastructure assessments. * Contribute analysis to recurring intelligence deliverables (WorldView, Year in Review, Intelligence Services products) with validated, properly modeled underlying data. * Ensure data quality and close visibility gaps through validation, automation identification, and methodological improvement. * Document designs, improve processes, contribute to team coding standards and testing frameworks, and share knowledge across the team. * Collaborate across hunt, research, intelligence, product, and engineering functions; support incident response and intel-sharing relationships. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 166: Sycophancy, Zip bombs and AI Native Development](https://www.wearedevelopers.com/magazine/585-dev-digest-166-sycophancy-zip-bombs-and-ai-native-development) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)