> Markdown version of [/jobs/ext/2722763-threat-detection-intelligence-engineer](https://www.wearedevelopers.com/jobs/ext/2722763-threat-detection-intelligence-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Threat Detection & Intelligence Engineer - **Company:** Miro - **Location:** Austin, TX, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Application Layers, Big Data, Software as a Service, Cloud Computing Security, Cloud Engineering, Digital Forensics, Intrusion Detection and Prevention, Python (Programming Language), SQL Databases, Data Logging, Cyber Threat Analysis, Terraform - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-threat-detection-engineer-intelligence-miro-7007676 ## About the Role * Think in attacker TTPs, not just alerts or dashboards * Enjoy investigating ambiguous signals and turning them into clear conclusions * Have experience in threat intelligence, threat hunting, or security investigations * Care about why something is happening, not just what fired * Want to build detection programs that evolve with the threat landscape * Are comfortable explaining technical risk in business terms This role is not a fit if you're mainly focused on compliance, policy writing, or managing vendors. What We're Looking For * 5-7 years in security, with 2+ years in threat detection, threat intelligence, or investigations * Experience in cloud-native SaaS environments (AWS strongly preferred) * Strong investigation skills and ability to analyze attacker behavior * Experience using threat intelligence to inform detection and response * Proficiency in Python and comfort automating security workflows * Experience querying large datasets (SQL or similar) * Familiarity with cloud security telemetry, logging, and detection platforms * Solid understanding of incident response and digital forensics * Experience with Infrastructure as Code (Terraform or similar) ## Description The Cloud Security & Detection & Response (CSDR) team protects Miro by staying ahead of credible threats. We focus on: * Translating external threat intelligence into actionable detections * Building custom, high-fidelity detections for cloud and SaaS environments * Leading complex investigations and incident response * Partnering with engineering to drive security by design We care about context, signal quality, and attacker intent not alert volume. What You'll Do * Track emerging threats, attacker techniques, and campaigns relevant to cloud and SaaS * Turn threat intelligence into practical detection strategies and attack hypotheses * Design and maintain context-aware detections across cloud, identity, and application layers * Lead deep investigations, from first signal to root cause and remediation * Act as a technical lead during security incidents, guiding response and decision-making * Analyze detection and investigation trends to improve preventative controls * Partner with engineering teams to raise security maturity across the organization, * You'll help define how threat intelligence is used, not just consume it * You'll work on real attacker behavior, not checkbox security * You'll have room to build, experiment, and improve detection capabilities * You'll partner closely with engineers who value security as an engineering problem ## Related Videos - [Alibaba Big Data and Machine Learning Technology](https://www.wearedevelopers.com/videos/37-alibaba-big-data-and-machine-learning-technology) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity](https://www.wearedevelopers.com/magazine/709-dev-digest-210-ai-agents-are-go-is-mcp-dead-llms-crack-anonymity) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production)