Senior Threat Engineer
About the Company
Our client is a diversified financial services organization providing financial advice, investments, insurance, and related financial solutions to clients across the United States. Operating within a highly regulated environment, they continue to invest in technology and cybersecurity capabilities to protect clients, employees, data, and the enterprise as the threat landscape becomes increasingly sophisticated. As part of this investment, they are expanding their Cyber Defense organization and developing a more integrated Threat, Detect & Defense capability designed to improve how threat intelligence, vulnerability information, security telemetry, and detection engineering work together.
About the Role
We are seeking an experienced Senior Threat Engineer to help build and mature its Threat, Detect & Defense capabilities. This is a hands-on engineering role for an experienced cybersecurity professional who has previously built, integrated, or significantly matured enterprise threat intelligence and threat detection capabilities. The Senior Threat Engineer will transform external and internal threat intelligence into actionable defensive capabilities by developing threat feeds, integrating intelligence into security platforms, analyzing adversary tactics, techniques, and procedures (TTPs), and helping determine where emerging threats intersect with their assets and existing security controls. This individual should be capable of operating independently with minimal direction.
Responsibilities
- Threat Intelligence Engineering: Design, build, and mature the technical capabilities required to ingest, normalize, enrich, and operationalize threat intelligence from internal, commercial, and open-source sources.
- Threat Feed Integration: Develop and maintain integrations between threat intelligence feeds and security platforms, including SIEM/SOAR and other detection and response technologies.
- Detection Engineering: Translate threat intelligence, indicators of compromise, adversary behaviors, and TTPs into actionable detections that enable Cyber Defense teams to identify malicious activity more quickly.
- Threat Correlation: Correlate threat intelligence against assets, vulnerabilities, security telemetry, and the enterprise environment to determine potential exposure and prioritize defensive actions.
- Threat Modeling: Partner with Cyber Defense and engineering teams to assess emerging threats, identify gaps in existing security controls, and support threat-modeling activities.
- Security Automation: Develop automation that improves the speed at which threat intelligence can be analyzed, enriched, correlated, and incorporated into security operations and detection workflows.
- Platform Integration: Extend threat intelligence beyond traditional security platforms when appropriate, integrating actionable intelligence into engineering and observability platforms to improve enterprise-wide awareness and response.
- Threat Research: Monitor emerging threat actors, attack techniques, vulnerabilities, and campaigns and translate relevant intelligence into practical recommendations.
- Cross-Functional Collaboration: Partner closely with SIEM/SOAR engineers, vulnerability engineering, Cyber Defense, Incident Response, Application Security, Cloud Security, and other technology teams to operationalize threat intelligence.
- Program Development: Help establish scalable processes, engineering patterns, and technical standards for the developing Threat, Detect & Defense function.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related technical field, or equivalent professional experience.
- 5+ years of experience in cybersecurity, threat intelligence, threat engineering, detection engineering, security operations, or a related discipline.
- Demonstrated experience building or significantly maturing threat intelligence or threat engineering capabilities within an enterprise environment.
- Hands-on experience working with threat intelligence feeds and integrating threat data into security platforms.
- Strong knowledge of cyber threat actors, indicators of compromise, and attacker tactics, techniques, and procedures.
- Experience translating threat intelligence into actionable security detections, hunting hypotheses, or defensive controls.
- Experience working with SIEM and/or SOAR technologies and integrating security data across platforms.
- Strong understanding of MITRE ATT&CK and its application to threat intelligence, detection, and threat modeling.
- Experience working with APIs, scripting, or automation to integrate and operationalize security data.
- Ability to independently assess complex security problems, recommend solutions, and drive implementation with limited oversight.
- Strong written and verbal communication skills with the ability to translate technical threat information into actionable recommendations.
Preferred Qualifications
- Experience working with commercial and open-source threat intelligence platforms and OSINT sources.
- Experience with threat hunting and detection engineering.
- Experience correlating threat intelligence with vulnerability and asset-management data.
- Experience developing or maintaining automated threat intelligence pipelines.
- Familiarity with cloud environments and cloud-native security telemetry.
- Experience integrating security intelligence with engineering, development, or observability platforms.
- Scripting experience with Python or similar languages.
- Experience working within financial services, healthcare, insurance, or another highly regulated industry.
- Experience partnering with vulnerability management, incident response, red team, or application security functions.
- Familiarity with emerging uses of AI and automation within threat intelligence and detection engineering.