Detection & Response Security Engineer, Threat Intelligence

Meta
London, UK
4 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

PHP (Programming Language) Artificial Intelligence Big Data Query Languages Data Intelligence Python (Programming Language) Network Forensics Red Team (Cyber Security) SQL Databases Software Vulnerability Management Snort (Software) Scripting
+5 more
Mitre Att&ck Malware Cyber Threat Analysis Cybercrime Production Code

Job description

Meta Security is looking for a threat intelligence investigator with extensive experience in investigating cyber threats with an intelligence-driven approach. You will be proactively responding to a broad set of security threats, as well as tracking actor groups with an interest or capability to target Meta and its employees. You will also be identifying the gaps in current detections and preventions by long-term intelligence tracking and research, and working with cross-functional stakeholders to improve Meta’s security posture., Detection & Response Security Engineer, Threat Intelligence Responsibilities:

  1. Track threat clusters posing threats to Meta’s infrastructure and employees, and identify, develop and implement countermeasures on our corporate network
  2. Investigate, mitigate, and forecast emerging technical trends and communicate effectively with actionable suggestions to different types of audiences
  3. Work closely with incident responders to provide useful and timely intelligence to enrich ongoing investigations
  4. Improve the tooling of threat cluster tracking and intelligence data integration to existing systems
  5. Engage constructively in cross-functional projects to improve the security posture of Meta’s infrastructure, such as red team operations, surface detection coverage expansion and vulnerability management discussions

Requirements

  1. 3+ years threat intelligence experience
  2. Familiarity with campaign tracking techniques and ability to convert the tracking results to long term countermeasures
  3. Familiarity with threat modeling framework, such as Diamond Model and/or MITRE ATT&CK framework
  4. Experience intelligence-driven hunting to spot suspicious activities in the network and identify potential risks
  5. Proven track record of managing and executing on short term and long term projects
  6. Ability to work with a team spanning multiple locations/time zones
  7. Ability to prioritize and execute tasks with minimal direction or oversight
  8. Ability to think critically and qualify assessments with solid communications skills
  9. Coding or scripting experience in one or more scripting languages such as Python or PHP, 15. Familiarity with malware analysis or network traffic analysis
  10. Experience authoring production code for threat intelligence tooling
  11. Experience conducting large scale data analysis
  12. Experience in one or more query languages such as SQL
  13. Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
  14. Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
  15. Experience working across the broader security community
  16. Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
  17. Production of file-based or network-based rules and signatures for detection and tracking of complex threats, such as YARA or Snort
  18. Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
  19. Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
  20. Experience closely collaborating with incident responders on incident investigations
  21. Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
  22. Familiarity with nation-state, sophisticated criminal, or supply chain threats

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

3:28 min

Defining big data and machine learning fundamentals

Ayon Roy · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:45 min

Addressing active AI incident remediation and broad ecosystem support

Matthew Brady Matthew Brady · World Congress 2026 Europe

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

1:31 min

Dual usage of machine learning in cybersecurity

Wolfgang Ettlinger +1 · World Congress 2023

Videos

See all

Related articles

See all