Remote Cyber security Jobs · Threat Intelligence

Job listings

US Unlimited PTO 12w maternity 12w paternity

  • Drive and conduct security testing and penetration tests across applications, infrastructure, and networks to identify exploitable vulnerabilities.
  • Manage and implement security testing tools and frameworks to simulate real-world attacks and validate security controls.
  • Design and implement AI-enabled workflows to scale security testing and threat related operations.

Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing. They are a Series C company backed by a16z, managing over $110 billion in loans, with a culture that values security and innovation.

$152,000–$152,000/yr

  • Create ICS-focused threat detections and asset identification analytics based on threat intelligence.
  • Mentor detection engineers and contribute to detection development initiatives.
  • Analyze cyber threat intelligence and network data to identify and respond to OT threats.

Dragos is the global leader in operational technology (OT) cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure. The company is a remote-first, mission-driven team across multiple continents built on authenticity, transparency, and trust.

  • Triage and evaluate threat information from multiple simulated sources to determine relevance and credibility.
  • Analyze simulated threat actors and their TTPs to assess potential organizational risk.
  • Produce actionable intelligence assessments and brief decision-makers on technical findings.

They provide simulation-based cyber threat intelligence training and analysis. They are a partner company that hires remote analysts for professional development.

  • Monitor threats and investigate suspicious activities using logs and detection systems.
  • Analyze attack patterns and build detailed threat scenarios from collected data.
  • Improve detection and blocking mechanisms for automated attacks and malicious behaviors.

Sigma Software is a technology company that provides advanced cybersecurity solutions and application protection services. The remote team is collaborative, experienced, and operates within European time zones.

$87,400–$131,000/yr
US 4w PTO

  • Support ransomware and cyber extortion engagements by managing threat actor communications and maintaining accurate case documentation.
  • Conduct research on threat actor groups, campaigns, and malware to provide actionable intelligence for active cases.
  • Coordinate with internal teams and external partners to ensure timely and accurate communication throughout engagements.

The company specializes in ransomware and cyber extortion incident response, supporting active engagements. They foster a collaborative remote culture with opportunities for professional growth and development.

$87,400–$131,000/yr
US 4w PTO

  • Support ransomware and cyber extortion engagements by managing threat actor communications and maintaining clear negotiation records.
  • Perform light threat intelligence research on threat actor trends, tactics, techniques, and tooling to support engagement strategy.
  • Draft and organize communication logs, negotiation notes, timelines, and case records to keep the engagement team informed.

Vector3, Inc., an incident response firm supporting TMHCC Cyber and Professional Lines Group, specializes in responding to Business Email Compromise and Ransomware incidents. Tokio Marine HCC, with over 50 years of service, offers over 100 products to commercial customers in 180 countries and has grown its workforce to 4,300 worldwide.

US Unlimited PTO

  • Own the research-to-production pipeline, turning research artifacts into production-ready detection rules, feeds, or platform APIs.
  • Build and maintain threat intelligence platform components across multiple services, including distribution servers, sandbox orchestration, and rules engines.
  • Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard, defining schemas that hold up downstream.

SecurityScorecard is the global leader in cybersecurity ratings, continuously rating over 12 million companies across 64 countries. Headquartered in New York City, the company has been recognized as a Best Workplace by Inc Magazine and a Best Place to Work in NYC, with a culture that values innovation and employee engagement.

US 3w PTO 17w maternity 17w paternity

  • Hunt through first-party data and telemetry to identify and expose new malicious cyber activity and campaigns.
  • Cluster, track, attribute, and disrupt malicious cyber threats with advanced tradecraft.
  • Develop and integrate new intelligence sources, tools, and systems to produce a comprehensive threat picture.

GreyNoise Intelligence is a mission driven security startup focused on helping organizations understand and mitigate risks from Internet scanning and exploitation. It is a high-growth Series-A startup with a remote-first culture emphasizing transparency, honesty, and continuous learning.

$159,800–$235,000/yr
US Unlimited PTO 16w maternity 16w paternity

  • Conduct hands-on detection engineering for custom alerting, integrating threat intelligence and building agentic tooling.
  • Work with structured and unstructured telemetry to produce meaningful security signals across cloud, endpoints, and marketplace.
  • Collaborate with cross-functional teams and mentor engineers to improve detection capabilities and maintain standards.

DoorDash is a technology and logistics company that enables door-to-door delivery, empowering local economies. We grow rapidly and constantly change, with a diverse and inclusive team committed to supporting employees' happiness and well-being.