> Markdown version of [/jobs/ext/2722856-threat-intelligence-engineer](https://www.wearedevelopers.com/jobs/ext/2722856-threat-intelligence-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Threat Intelligence Engineer - **Company:** Anthropic's Mission - **Location:** San Francisco, CA, United States (Remote available) - **Salary:** $320,000.0 - **Contract:** Permanent contract - **Skills:** Airflow, Audit Trail, Cyber Security, Computer Telephony Integration, Web Scraping, Data Mining, Python (Programming Language), Rich Site Summary (RSS), SQL Databases, Data Ingestion, Large Language Models, Data Pipelines - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/threat-intelligence-engineer-anthropic-3-7665059 ## About the Role * Have strong coding proficiency in Python and SQL for building detection logic, data pipelines, and automation * Have experience with data pipeline orchestration tools (Airflow, DBT, or similar) * Have familiarity with threat intelligence concepts including IOCs, YARA rules, and threat correlation techniques * Have experience integrating external APIs and building data ingestion systems * Can translate investigator needs and workflows into technical requirements * Are comfortable building v0 systems and iterating based on user feedback * Have strong communication skills for working closely with non-engineering stakeholders Strong candidates may also have: * Experience with threat intelligence sharing frameworks (e.g. MISP, STIX/TAXII) * Background in cyber threat intelligence, security operations, or abuse detection * Experience building MCP servers or similar tool integrations for AI systems * Familiarity with web scraping and data extraction at scale * Experience with behavioral analytics or anomaly detection systems * Understanding of LLM capabilities and how to leverage them for automation * A Top Secret Clearance, Minimum education: Bachelor's degree or an equivalent combination of education, training, and/or experience Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices. ## Description We are looking for a Threat Intelligence Engineer to join our Threat Intelligence team. In this role, you will build the infrastructure that powers our threat discovery capabilities-integrating external data sources, developing detection systems for automated lead generation, and creating internal tooling that scales our investigators' impact. This is a foundational engineering role on a small, high-impact team. You will take projects from proof-of-concept to production, work closely with investigators to understand their needs, and help scale what may become a multi-person collections function., * Build automated detection systems that use disparate signals to identify abusive behavior. * Take systems from idea to proof-of-concept to production-grade with appropriate monitoring, documentation, and maintenance processes * Develop and maintain YARA rule infrastructure, including tools for writing, validating, and testing rules against real data * Create integrations with external threat intelligence platforms (e.g. VirusTotal, Censys, Urlscan) via MCP servers to enable multi-source correlation during investigations * Build data pipelines that ingest intelligence from RSS feeds, CTI news sources, and partner sharing, using Claude to extract TTPs and generate targeted hunting queries * Develop behavioral analytics capabilities using DBT-based frameworks and create searchable audit logging infrastructure * Establish feedback loops with investigators to tune detection systems and reduce false positives * Scrape and normalize data from external sources to feed threat detection and enrichment workflows ## Related Videos - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [From Messy Queries to Scalable Systems - How Data Engineering actually works](https://www.wearedevelopers.com/videos/100203-from-messy-queries-to-scalable-systems-how-data-engineering-actually-works) - [Data Science on Software Data](https://www.wearedevelopers.com/videos/162-data-science-on-software-data) - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) ## Related Articles - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)