Source Job

US

  • Monitor and analyze sophisticated cyber threats targeting Anduril's products, infrastructure, and personnel.
  • Research and anticipate emerging technical trends in the threat landscape, collaborating with detection and response teams.
  • Enhance tooling for threat actor tracking and intelligence data integration, engaging with external partners.

Python Rust Golang Swift YARA

20 jobs similar to Staff Threat & Attack Research Engineer

Jobs ranked by similarity.

$170,000–$240,000/yr
US Unlimited PTO

  • Design, build, and maintain static and dynamic file analysis pipelines processing artifacts at scale.
  • Operate and extend threat indicator enrichment systems for real-time file metadata extraction.
  • Build and maintain threat graph intelligence systems modeling relationships between indicators and actors.

Censys provides real-time Internet intelligence and threat insights to global governments and over 50% of the Fortune 500. They are a growing, research-driven company focused on building comprehensive maps of the internet with a collaborative culture.

Europe

  • Monitor threats and investigate suspicious activities using logs and detection systems.
  • Analyze attack patterns and build detailed threat scenarios from collected data.
  • Improve detection and blocking mechanisms for automated attacks and malicious behaviors.

Sigma Software is a technology company that provides advanced cybersecurity solutions and application protection services. The remote team is collaborative, experienced, and operates within European time zones.

India

  • Monitor security alerts and events to identify potential threats and vulnerabilities.
  • Detect and analyze security incidents using multiple security tools like SIEM, EDR, and IDS/IPS.
  • Respond to security incidents promptly following established procedures and perform phishing analysis.

Zscaler accelerates digital transformation so customers can be more agile, efficient, resilient, and secure with its Zero Trust Exchange platform. The company employs thousands globally and fosters a culture of ownership, collaboration, and continuous feedback.

US 3w PTO 17w maternity 17w paternity

  • Hunt through first-party data and telemetry to identify and expose new malicious cyber activity and campaigns.
  • Cluster, track, attribute, and disrupt malicious cyber threats with advanced tradecraft.
  • Develop and integrate new intelligence sources, tools, and systems to produce a comprehensive threat picture.

GreyNoise Intelligence is a mission driven security startup focused on helping organizations understand and mitigate risks from Internet scanning and exploitation. It is a high-growth Series-A startup with a remote-first culture emphasizing transparency, honesty, and continuous learning.

US Unlimited PTO

  • Own the research-to-production pipeline, turning research artifacts into production-ready detection rules, feeds, or platform APIs.
  • Build and maintain threat intelligence platform components across multiple services, including distribution servers, sandbox orchestration, and rules engines.
  • Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard, defining schemas that hold up downstream.

SecurityScorecard is the global leader in cybersecurity ratings, continuously rating over 12 million companies across 64 countries. Headquartered in New York City, the company has been recognized as a Best Workplace by Inc Magazine and a Best Place to Work in NYC, with a culture that values innovation and employee engagement.

$108,000–$140,000/yr
US

  • Design, implement, and maintain internal tooling for acquiring and parsing recaptured underground data.
  • Build and deploy cloud infrastructure using Infrastructure as Code technologies.
  • Collaborate with the research team to support targeting and collection of new data sources.

SpyCloud transforms recaptured darknet data to disrupt cybercrime. They have over 250 cybersecurity experts and foster a collaborative, innovative culture.

$135,000–$145,000/yr

  • Perform all-source intelligence analysis and fusion to assess threats to critical infrastructure.
  • Provide analytical support to insider risk investigations and supply chain due diligence.
  • Author intelligence reports and briefings aligned with industry best practices.

Agile Defense provides advanced technology solutions for national security missions, focusing on cybersecurity and intelligence. They emphasize a culture of the '6Hs'—Happy, Helpful, Honest, Humble, Hungry, and Hustle—and value their employees as family, fostering collaboration and innovation.

Australia

  • Design and optimize threat detection capabilities using SIEM, SOAR, EDR, and NDR technologies.
  • Develop automation playbooks and cybersecurity data solutions to improve detection accuracy.
  • Collaborate with customer teams to close detection gaps and adapt defenses to emerging threats.

Our partner is a cybersecurity firm focused on building threat detection capabilities for enterprise environments. They foster a collaborative, engineering-led culture with significant autonomy for engineers.

US

  • Perform investigations of security incidents using digital forensics and data analytics.
  • Apply coding, data analytics, and investigative skills to hunt, detect, and respond to threats.
  • Build automation and detection models to identify anomalous activity and support response efforts at scale.

Maleda Tech is a technology staffing and consulting firm that provides security engineering services. They are hiring for a contract role supporting a major technology organization.

US

  • Lead MLB's threat intelligence and incident response programs across the league office, 30 Clubs, and affiliates.
  • Manage vulnerability intelligence, digital risk monitoring, incident coordination, and forensic investigations.
  • Own security awareness programming and use automation to shorten research, triage, and reporting cycles.

Major League Baseball (MLB) is the most historic professional sports league in the United States and Canada. With a league office, 30 Clubs, and affiliates, MLB fosters a culture of growth, teamwork, and professionalism, empowering employees to take initiative and put the team first.

3w PTO

  • Lead design and implementation of data science solutions for cybersecurity operations.
  • Develop data models, machine learning algorithms, and automation to enhance threat detection and analytics.
  • Collaborate with SOC, threat hunters, and engineers to transform telemetry into actionable defense.

True Zero Technologies is a veteran-owned small business that empowers people and technology to drive quality outcomes. Named a Best Place to Work in 2023 and 2025, it fosters a collaborative, innovative culture with sustained growth on the Inc. 5000 list.

$152,000–$152,000/yr
US

  • Create ICS-focused threat detections and asset identification analytics based on threat intelligence.
  • Mentor detection engineers and contribute to detection development initiatives.
  • Analyze cyber threat intelligence and network data to identify and respond to OT threats.

Dragos is the global leader in operational technology (OT) cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure. The company is a remote-first, mission-driven team across multiple continents built on authenticity, transparency, and trust.

  • Proactively search for signs of malicious activities within network and systems.
  • Swiftly assess and prioritize security incidents to minimize potential impact.
  • Participate in incident response, analyze phishing, create user education, and dissect malware.

They are a tech pioneer offering adult entertainment and games on safe, popular platforms. With an international team of dynamic innovators, they focus on safe user experiences and community empowerment, with offices in Montreal, Austin, and Nicosia.

$87,400–$131,000/yr
US 4w PTO

  • Support ransomware and cyber extortion engagements by managing threat actor communications and maintaining accurate case documentation.
  • Conduct research on threat actor groups, campaigns, and malware to provide actionable intelligence for active cases.
  • Coordinate with internal teams and external partners to ensure timely and accurate communication throughout engagements.

The company specializes in ransomware and cyber extortion incident response, supporting active engagements. They foster a collaborative remote culture with opportunities for professional growth and development.

US

  • Design and implement scalable detection logic to identify insider threats and data exfiltration across corporate and production environments.
  • Conduct proactive threat hunting and incident response, collaborating with HR, Legal, and engineering teams during complex investigations.
  • Develop automation and detection models using Python and SQL to strengthen security response capabilities and reduce risk exposure.

The company is a technology organization specializing in security and threat detection. They operate in a fast-paced, collaborative environment with a focus on insider threat prevention and response.

$85,000–$110,000/yr
US

  • Implement assigned security controls across Kubernetes, Linux, database, and model-serving environments.
  • Build monitoring, vulnerability scanning, and automation to keep security controls current.
  • Contribute to AI tooling, documentation, and evidence collection for federal reviews.

Axle is a bioscience and IT company offering advancements in translational research, biomedical informatics, and data science applications to research organizations. Their team includes biomedical science, software engineering, and program management experts who support top research centers, including NIH.

Australia 12w maternity 12w paternity

  • Triage and investigate intrusions, analyze logs and forensic artifacts to determine root causes.
  • Perform dynamic malware analysis and refine detection capabilities to address emerging threats.
  • Collaborate with product and engineering teams to evolve human-led agentic workflows.

Huntress is a cybersecurity company founded in 2015 by former NSA cyber operators, making enterprise-grade security accessible to businesses of all sizes. They secure over 5 million endpoints and 14 million identities worldwide with a remote-first team and a 24/7 human-led Security Operations Center.

US

  • Build and scale a world-class insider threat program, including detection logic and automation.
  • Collaborate with cross-functional teams including HR, Legal, and Engineering to investigate and mitigate insider risks.
  • Participate in on-call rotation and proactively hunt for threats across corporate and production environments.

Maleda Tech is a technology consulting firm specializing in security and threat detection. They operate as a fast-paced team supporting major organizations, with a focus on building and scaling insider threat programs.

$144,300–$216,500/yr
US

  • Proactively hunt for advanced threats and dissect complex fraud vectors using hypothesis-driven threat hunting operations.
  • Apply and enrich the FT3 taxonomy to standardize threat intelligence across kill chain phases and API endpoints.
  • Collaborate cross-functionally to integrate threat intelligence, build agentic simulation workflows, and eliminate product vulnerabilities.

Stripe is a financial infrastructure platform for businesses, enabling millions of companies to accept payments and grow revenue. They are a large, global company with a mission to increase the GDP of the internet and a culture of innovation and collaboration.

$140,000–$180,000/yr
US

  • Apply deep expertise in cyber threat intelligence, analyzing advanced threat actors and attack methodologies.
  • Lead strategic threat intelligence initiatives, developing methodologies and providing thought leadership.
  • Convey complex intelligence findings through reports and briefings to diverse technical and executive audiences.

NBCUniversal is a leading media and entertainment company, creating and distributing content across film, television, streaming, and theme parks. As a subsidiary of Comcast Corporation, it employs a large global workforce and fosters an inclusive culture with a commitment to community engagement.