Own the research-to-production pipeline, turning research artifacts into production-ready detection rules, feeds, or platform APIs.
Build and maintain threat intelligence platform components across multiple services, including distribution servers, sandbox orchestration, and rules engines.
Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard, defining schemas that hold up downstream.
SecurityScorecard is the global leader in cybersecurity ratings, continuously rating over 12 million companies across 64 countries. Headquartered in New York City, the company has been recognized as a Best Workplace by Inc Magazine and a Best Place to Work in NYC, with a culture that values innovation and employee engagement.
Build and maintain Synapse collection pipelines through Storm queries, automation, and data models.
Diagnose and resolve complex defects in Synapse tooling and collection systems independently.
Support threat hunting and adversary tracking using telemetry and malware analysis techniques.
Dragos is a global leader in OT cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure. The company is a remote-first mission-driven team built on authenticity, transparency, and trust.
Design, build, and maintain cybersecurity data pipelines using Cribl, managing data flows from source systems into SIEM and data lake platforms.
Develop and integrate connectors for security data ingestion, configure parsing, routing, and transformation, and support SIEM architecture and operations.
Troubleshoot complex pipeline issues, create documentation, and collaborate with cross-functional teams to ensure data accuracy, security, and performance.
Cribl is a cybersecurity and data engineering company that helps organizations manage and optimize security data pipelines for SIEM and data lake environments. As a growing company with a small team, they emphasize independent problem-solving, collaboration, and a culture that values technical excellence and clear communication.
Hunt through first-party data and telemetry to identify and expose new malicious cyber activity and campaigns.
Cluster, track, attribute, and disrupt malicious cyber threats with advanced tradecraft.
Develop and integrate new intelligence sources, tools, and systems to produce a comprehensive threat picture.
GreyNoise Intelligence is a mission driven security startup focused on helping organizations understand and mitigate risks from Internet scanning and exploitation. It is a high-growth Series-A startup with a remote-first culture emphasizing transparency, honesty, and continuous learning.
Conduct hands-on detection engineering for custom alerting, integrating threat intelligence and building agentic tooling.
Work with structured and unstructured telemetry to produce meaningful security signals across cloud, endpoints, and marketplace.
Collaborate with cross-functional teams and mentor engineers to improve detection capabilities and maintain standards.
DoorDash is a technology and logistics company that enables door-to-door delivery, empowering local economies. We grow rapidly and constantly change, with a diverse and inclusive team committed to supporting employees' happiness and well-being.
Create ICS-focused threat detections and asset identification analytics based on threat intelligence.
Mentor detection engineers and contribute to detection development initiatives.
Analyze cyber threat intelligence and network data to identify and respond to OT threats.
Dragos is the global leader in operational technology (OT) cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure. The company is a remote-first, mission-driven team across multiple continents built on authenticity, transparency, and trust.
Deliver on business-critical outcomes by owning backend and data services end-to-end, from design to production operation.
Design, build, and operate scalable data pipelines and streaming ingestion for high-volume security telemetry.
Contribute to data modeling and warehouse/lakehouse architecture decisions that serve detection, analytics, and product features.
Blackpoint Cyber is the leading provider of world-class cybersecurity threat hunting, detection and remediation technology. Founded by former National Security Agency (NSA) cyber operations experts, the company is in hyper-growth mode, fueled by a recent $190m series C round.
Design and implement data integrations with SIEM platforms such as Sentinel and Splunk.
Model complex data sources into performant analytics.
Collaborate with product engineering teams to deliver data solutions that enhance customer-facing products.
Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The company is a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust.
Design, build, and maintain highly reliable backend services and distributed systems for RapidFort's security platform.
Build systems for processing and analyzing large volumes of security, vulnerability, container, and runtime data.
Solve complex problems involving concurrency, performance, scalability, and distributed processing across Linux, Kubernetes, and cloud environments.
RapidFort is a cybersecurity company focused on securing and optimizing modern software supply chains and cloud-native environments. The company works with enterprise and U.S. public-sector customers in security-sensitive environments, fostering a culture of technical ownership and collaboration.
Build and maintain reusable use cases and reference architectures on the Cyware platform for threat intelligence, automation, and agentic SOC workflows.
Act as the primary voice of the market to Product, translating customer pain points into product requirements and roadmap input.
Enable Sales Engineering and Customer Success teams with reusable technical assets and best practices.
Cyware delivers an innovative approach to cybersecurity that unifies threat intelligence, automation, threat response, and vulnerability management. It is a cybersecurity startup that has closed its Series C funding round and fosters an exciting and challenging start-up culture.
Synthesize data from a wide range of internal and external sources to develop a comprehensive picture of threats affecting cloud, AI, and developers.
Analyze and track state-backed and financially motivated attackers targeting cloud ecosystems.
Communicate novel findings and in-depth analyses of cyber threat activity to multiple audiences and in multiple formats.
Wiz enables teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. It is one of the fastest-growing startups, trusted by over 65% of the Fortune 100, with a culture that values world-class talent.
Monitor threats and investigate suspicious activities using logs and detection systems.
Analyze attack patterns and build detailed threat scenarios from collected data.
Improve detection and blocking mechanisms for automated attacks and malicious behaviors.
Sigma Software is a technology company that provides advanced cybersecurity solutions and application protection services. The remote team is collaborative, experienced, and operates within European time zones.
Develop processes, tooling and automation to scale incident management response and mitigate risks.
Collaborate with security, engineering, product, support, and business operations to identify detection use cases.
Maintain security logging platform and stay updated on threats to improve detection mechanisms.
ClickHouse is a leading real-time analytics, data warehousing, observability, and AI workloads company with over 4,000 customers and rapid growth, validated by a $400M Series D funding round. The company values innovation and collaboration, offering a remote-friendly culture with a global team.
Lead MLB's threat intelligence and incident response programs across the league office, 30 Clubs, and affiliates.
Manage vulnerability intelligence, digital risk monitoring, incident coordination, and forensic investigations.
Own security awareness programming and use automation to shorten research, triage, and reporting cycles.
Major League Baseball (MLB) is the most historic professional sports league in the United States and Canada. With a league office, 30 Clubs, and affiliates, MLB fosters a culture of growth, teamwork, and professionalism, empowering employees to take initiative and put the team first.
Conduct comprehensive OSINT and Deep & Dark Web analysis to develop intelligence on national security threats.
Perform proactive covert engagement with threat actors using managed-attribution tradecraft.
Apply an offensive-security perspective to assess how adversaries could operationalize exposed data.
Flashpoint is a pioneering threat intelligence company providing data and insights to commercial and government clients. The company prioritizes a diverse and inclusive culture with employee wellness and growth opportunities.
Build and scale a world-class insider threat program, including detection logic and automation.
Collaborate with cross-functional teams including HR, Legal, and Engineering to investigate and mitigate insider risks.
Participate in on-call rotation and proactively hunt for threats across corporate and production environments.
Maleda Tech is a technology consulting firm specializing in security and threat detection. They operate as a fast-paced team supporting major organizations, with a focus on building and scaling insider threat programs.
Design and build dedicated normalizers per EDR vendor with rigorous testing for API evolution.
Develop core product features in ETL and GraphQL to support data processing and retrieval.
Build and maintain backend APIs and ETL pipelines for data interactions and analytics.
Horizon3 is a fast-growing cybersecurity company that provides the NodeZero platform for autonomous pentesting and attack vector verification. The company is a fusion of former U.S. Special Operations cyber operators and startup engineers, committed to a culture of respect, collaboration, ownership, and results.
Design, build, and operate high-signal detections across endpoint, identity, cloud, and SaaS environments.
Implement and tune detection content across SIEM/XDR/EDR and cloud telemetry using detections-as-code with CI/CD and version control.
Proactively hunt for threats, operationalize threat intelligence, and contribute to incident response and automation efforts.
LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. They aspire to create a culture built on trust, care, inclusion, and fun where everyone can succeed.
Design, build, and maintain agent infrastructure and platforms, including the TRACE Graph, embeddings, and semantic search.
Collaborate with detection engineers and threat hunters to encode domain expertise into agents.
Build automated evaluations and benchmarks for non-deterministic agentic systems.
Nebulock is an agentic threat hunting platform that autonomously surfaces behaviors, not just IOCs, from various data sources. As a startup, we emphasize collaboration, low ego, and a relentless focus on delivering customer value.