SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 220,000 - 0 / annual
Fluidstack is building civilization-scale AI compute infrastructure, acquiring power, designing and operating data centers globally. The Security team is standing up a comprehensive security program from scratch to protect the most valuable and targeted artifacts in technology—frontier AI model weights and training infrastructure.
As Security Engineer, Threat Intelligence, you will own the threat intelligence function end-to-end, tracking nation-state and advanced criminal actors targeting frontier AI infrastructure. Your core responsibilities include:
• Track specific nation-state and advanced criminal actors, understanding their tooling, infrastructure patterns, and tradecraft deeply enough to anticipate their next moves and inform detection strategy.
• Build and operate data pipelines that collect, enrich, and correlate threat indicators from commercial feeds, open source, government, and peer relationships, pushing intelligence into detection and triage systems for immediate operational use.
• Conduct hands-on malware, phishing-infrastructure, and attacker-tooling analysis to extract indicators, TTPs, and attribution signals that feed detection engineering and incident response in near real time.
• Drive intelligence-led hunts across enterprise, cloud, identity, data center IT, and OT telemetry, converting findings into high-fidelity detections authored as code (YARA, Sigma, SIEM-native queries).
• Curate the inbound intelligence pipeline and prioritize what matters for the program's threat model, ensuring focus on the most consequential threats.
• Build and maintain external intelligence-sharing relationships with ISACs, peer AI/cloud security teams, and government partners to stay ahead of active campaigns.
• Write production-quality Python automation and data pipelines that operationalize your intelligence work end-to-end.
• Collaborate shoulder-to-shoulder with detection engineers and incident responders, turning intelligence into detections, hunting hypotheses, and incident context during live events.
You'll work in an environment of extreme ownership, velocity, and first-principles thinking. The company operates with full autonomy, insane urgency, and a focus on building something that matters. Your threat surface is measured in gigawatts—the customers running on Fluidstack infrastructure are building the most consequential technology in human history.