SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
SecurityScorecard is the global leader in cybersecurity ratings, continuously rating over 12 million companies across 64 countries. The company's patented technology is used by 25,000+ organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting.
You'll join STRIKE, SecurityScorecard's Threat Intelligence team, as a Senior Research Engineer bridging research and production. STRIKE operates multiple research motions in parallel: rapid response to active events, product-tied work, and standards-anchored quarterly research. The role solves the core problem of translating research findings into shipped detections and feeds.
You'll report to the Head of Threat Research for people management while receiving technical direction from R&D leadership. Your core responsibility is taking research artifacts—malware findings, infrastructure clusters, indicator classes, behavioral patterns—and transforming them into production-ready outputs: schemas, pipeline hooks, distribution feeds, detection rules, and platform APIs.
Key responsibilities include:
**Research-to-Production Pipeline**: Own the complete path from research output to production artifact. Partner with adjacent teams to define clean handoff contracts ensuring new signals arrive downstream with proper schema, value framing, and consumption patterns.
**Threat Intelligence Platform Engineering**: Build and maintain STRIKE platform components across multiple services and runtimes, including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines operating over standards-anchored predicates.
**Detection Content and Signal Production**: Convert research into shipped detection content (YARA, Sigma, STIX patterns, behavioral indicators) and the pipelines distributing them. Build correlation pipelines linking scan data, attack surface signals, vulnerability data, and adversary tracking into customer-facing intelligence.
**Data Model and Standards Adoption**: Drive STIX 2.1 adoption as unified output schema and TAXII 2.1 as distribution standard. Define and govern schemas that maintain integrity downstream.
**Research Workflow Engineering**: Build automation removing commodity overhead from research: indicator enrichment, report drafting, corpus correlation, feed normalization, and sandbox triage. Transition the team from analyst-driven, model-assisted workflows toward model-driven workflows with analyst review. Focus on retrieval grounded in the team's corpus, schema-constrained output, and evaluation harnesses catching regressions early. Understand when models are the wrong tool—regex for known patterns, SQL for structured data.
**Cross-Functional Delivery**: Coordinate with engineering, measurement, and platform teams to ship research at scale.