Own the research-to-production pipeline, turning research artifacts into production-ready detection rules, feeds, or platform APIs.
Build and maintain threat intelligence platform components across multiple services, including distribution servers, sandbox orchestration, and rules engines.
Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard, defining schemas that hold up downstream.
Build and maintain Synapse collection pipelines through Storm queries, automation, and data models.
Diagnose and resolve complex defects in Synapse tooling and collection systems independently.
Support threat hunting and adversary tracking using telemetry and malware analysis techniques.
Dragos is a global leader in OT cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure. The company is a remote-first mission-driven team built on authenticity, transparency, and trust.
Lead a team of threat intelligence analysts, fraud researchers, and detection engineers to proactively identify and mitigate threats.
Set the research agenda across threat actor tracking, fraud investigations, and merchant ecosystem defense.
Collaborate with key partners like Risk, Trust & Safety, and Security Engineering to translate research into platform protections.
Stripe is a financial infrastructure platform for businesses that enables millions of companies to accept payments and grow revenue. With a mission to increase the GDP of the internet, Stripe fosters a culture of passion, grit, and integrity, and employs a large, global team.
Translate complex threat research, telemetry insights, and security findings into compelling narratives for security leaders and media.
Lead cross-functional launch orchestration of threat research reports and intelligence programs.
Build relationships with information sharing organizations and develop sales enablement tools.
Zscaler accelerates digital transformation to ensure customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise with the world's largest security data lake, Zscaler is a publicly traded company with a culture of innovation, collaboration, and customer obsession.
Build and maintain SIEM for log collection and detection rules across corporate and production environments.
Design and deploy canary tokens and early warning mechanisms to detect threats before they reach critical assets.
Investigate security incidents end-to-end, including malware analysis, exfiltration assessment, and timeline reconstruction.
Quora operates two platforms: a global knowledge sharing platform with over 300M monthly unique visitors, and Poe, a platform for chatting and building with AI language models. The company is privately held, remote-first, and fosters a culture of transparency, collaboration, and experimentation.
Hunt through first-party data and telemetry to identify and expose new malicious cyber activity and campaigns.
Cluster, track, attribute, and disrupt malicious cyber threats with advanced tradecraft.
Develop and integrate new intelligence sources, tools, and systems to produce a comprehensive threat picture.
GreyNoise Intelligence is a mission driven security startup focused on helping organizations understand and mitigate risks from Internet scanning and exploitation. It is a high-growth Series-A startup with a remote-first culture emphasizing transparency, honesty, and continuous learning.
Lead and mentor the Detection Engineering & Automation team, driving delivery and professional growth.
Own the full detection lifecycle, from use-case design to implementation, optimization, and retirement.
Develop SIEM/EDR rules, detection-as-code pipelines, and SOAR automation playbooks to reduce alert fatigue.
This role is listed on behalf of a partner company, which manages all applications and next steps. The company is a remote-first organization focused on building advanced cyber defense capabilities, with a collaborative culture and a proactive security program.
Lead MLB's threat intelligence and incident response programs across the league office, 30 Clubs, and affiliates.
Manage vulnerability intelligence, digital risk monitoring, incident coordination, and forensic investigations.
Own security awareness programming and use automation to shorten research, triage, and reporting cycles.
Major League Baseball (MLB) is the most historic professional sports league in the United States and Canada. With a league office, 30 Clubs, and affiliates, MLB fosters a culture of growth, teamwork, and professionalism, empowering employees to take initiative and put the team first.
Conduct hands-on detection engineering for custom alerting, integrating threat intelligence and building agentic tooling.
Work with structured and unstructured telemetry to produce meaningful security signals across cloud, endpoints, and marketplace.
Collaborate with cross-functional teams and mentor engineers to improve detection capabilities and maintain standards.
DoorDash is a technology and logistics company that enables door-to-door delivery, empowering local economies. We grow rapidly and constantly change, with a diverse and inclusive team committed to supporting employees' happiness and well-being.
You'll lead the VIPR & VMDR function, integrating vulnerability intelligence, detection, and response for customers across APJ/APAC.
You'll operate and tune vulnerability detection tools like Tenable, Qualys, and Rapid7, and automate pipelines using Python and REST APIs.
You'll build risk dashboards and executive briefings, and collaborate with Customer Success and Security Engineering to improve remediation metrics.
ServiceNow is the AI control tower for business reinvention, bringing together AI, data, and workflows to help 85% of the Fortune 500 work smarter. The company fosters an AI-native culture where technology and talent are unstoppable together.
Analyze data to identify confirmed relationships and document threat actor tactics.
Initiate communication with international government agencies and foster cross-departmental engagement.
Respond promptly to user needs and stay abreast of industry trends.
Kodex revolutionizes how organizations handle sensitive subpoenas and data requests from law enforcement and government agencies. Founded by a former FBI agent and backed by leading investors, the company has become the industry standard for secure data exchange with a platform supporting over 15,000 government agencies in 190 countries.
Apply deep expertise in cyber threat intelligence, analyzing advanced threat actors and attack methodologies.
Lead strategic threat intelligence initiatives, developing methodologies and providing thought leadership.
Convey complex intelligence findings through reports and briefings to diverse technical and executive audiences.
NBCUniversal is a leading media and entertainment company, creating and distributing content across film, television, streaming, and theme parks. As a subsidiary of Comcast Corporation, it employs a large global workforce and fosters an inclusive culture with a commitment to community engagement.
Build and maintain reusable use cases and reference architectures on the Cyware platform for threat intelligence, automation, and agentic SOC workflows.
Act as the primary voice of the market to Product, translating customer pain points into product requirements and roadmap input.
Enable Sales Engineering and Customer Success teams with reusable technical assets and best practices.
Cyware delivers an innovative approach to cybersecurity that unifies threat intelligence, automation, threat response, and vulnerability management. It is a cybersecurity startup that has closed its Series C funding round and fosters an exciting and challenging start-up culture.
Develop threat intelligence content including advisories, briefs, reports, blogs, and executive summaries.
Translate IOCs, TTPs, and attack trends into narratives for practitioners and executives.
Track the threat landscape, pitch stories, and manage webinars and publication calendars.
SecurityScorecard is the global leader in cybersecurity ratings, with over 12 million companies continuously rated and operating in 64 countries. Founded in 2013 and funded by world-class investors, its culture has been recognized as a Best Workplace and one of the world's most innovative companies.
Analyze and respond to advanced threats ranging from commodity phishing to zero-day exploits.
Monitor and triage alerts from network security monitoring, EDR platforms, and other log sources.
Create detailed incident reports and collaborate with threat intelligence and incident response teams.
Volexity is a cybersecurity company specializing in threat intelligence and incident response. They have a growing, industry-leading security operations team and value diversity and equal opportunity.
Own and lead building out the Insider Trust Team’s infrastructure to engineer and automate end-to-end detection and investigation workflows.
Develop, measure, and tune detection rules in Sigma to ensure effective and sustainable operations.
Drive projects with a focus on Insider Risks, ranging from access abuse and intellectual property theft, to novel risks emerging within the blockchain/Web3 space.
We are the team behind Chainlink, the industry-standard oracle platform bringing capital markets onchain and powering the majority of DeFi. We have enabled tens of trillions in transaction value and secure the vast majority of DeFi, with a culture of security and innovation.
Continuously research emerging threats, malware, and vulnerability exploitation campaigns and translate findings into authoritative content.
Produce high-impact technical content including research papers, security reports, whitepapers, blogs, and conference presentations.
Partner with Product and Engineering to translate new product capabilities into clear, compelling technical narratives.
Picus Security is a leading exposure validation company that proves what attackers can exploit and what your defenses stop. Trusted by Fortune 500 enterprises and named a Gartner Peer Insights Customers' Choice, Picus offers a fast-growing, remote-first culture with unlimited opportunity.
You will hunt for and analyze adversary capabilities targeting ICS/OT networks.
You will develop tools and scripts for capability analysis and inform detection strategies.
Your work directly enhances Dragos' ability to defend against advanced threats.
Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The company is a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust.
Lead and develop a team of security engineers to defend infrastructure, SaaS, and endpoints against real-world adversaries.
Own detection and response, including incident command, tuning CrowdStrike, and conducting cybersecurity risk assessments.
Drive AI security strategy and partner with cross-functional teams to build robust detection controls.
Forward Financing is a financial technology company that unlocks capital to fuel small businesses across America. Since 2012, they have provided over $4.8 billion in funding to more than 92,000 small businesses and are recognized as a Best Place to Work with a culture focused on empowerment and collaboration.
Leads product security work across Black Duck's portfolio, including architecture reviews, threat models, vulnerability triage, and customer-facing security inquiries.
Maintains detection content in CrowdStrike NG-SIEM and Sumo Logic, contributes to SOAR automations, and coordinates vulnerability fixes with engineering teams.
Acts as an informal technical resource for less experienced team members, explains complex security topics to diverse stakeholders, and documents runbooks and SOPs.
Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. A recognized pioneer in application security with industry-leading tools and services, they partner with teams to maximize security and quality in DevSecOps.
Conduct comprehensive OSINT and Deep & Dark Web analysis to develop intelligence on national security threats.
Perform proactive covert engagement with threat actors using managed-attribution tradecraft.
Apply an offensive-security perspective to assess how adversaries could operationalize exposed data.
Flashpoint is a pioneering threat intelligence company providing data and insights to commercial and government clients. The company prioritizes a diverse and inclusive culture with employee wellness and growth opportunities.