Threat Intelligence Engineer (REMOTE)
About the role
About Cyware
Cyware delivers an innovative approach to cybersecurity that unifies threat intelligence, automation, threat response, and vulnerability management with data insights gleaned from assets, users, malware, attackers, and vulnerabilities. Cyware’s Cyber Fusion platform integrates SOAR and TIP technology, enabling collaboration across siloed security teams. Cyware is widely deployed by enterprises, government agencies, and MSSPs, and is the leading threat intelligence sharing platform for global ISACs and CERTs.
About you
- You are driven, inquisitive, proactive, and energetic
- You have a growth mindset and are committed to delivering results
- You thrive in a fast-paced, collaborative environment
Why We Are Hiring
The Threat Intelligence Engineer is someone with real threat intelligence depth and the technical ability to understand threat feeds’ data model and map it correctly to STIX 2.1, who uses AI to make that work dramatically faster. Someone who can be our threat intelligence SME: writing the use cases, supporting pre-sales and customers, and giving Product the domain expertise that shapes what we build.
Come join an exciting cybersecurity product startup that has closed its Series C funding round!
What You Will Do
- Map feeds to STIX and own the connector portfolio
- Design and maintain mappings from commercial, open-source, and community threat intelligence sources into STIX 2.1 objects, relationships, markings, patterning, and extensions while preserving semantic fidelity.
- Understand threat intel feed data models when API documentation is incomplete, or missing: inspect live payloads, sample data, and vendor dashboards to establish ground truth
- Own connector lifecycle and quality—from onboarding new sources to detecting schema drift, validating mappings, and ensuring production reliability
- Work directly with feed, sandbox, DRP, and enrichment partners on integrations and joint use cases
- Leverage AI to accelerate engineering workflows
- Build and improve an AI-assisted mapping workflow: infer schemas from sample payloads, propose candidate field-to-STIX mappings from documentation, and flag schema changes, while maintaining rigorous validation and human oversight
- Be the threat intelligence SME for Product
- Write threat intelligence use cases that drive product design, and pressure-test new capabilities against real analyst workflows.
- Partner with Product to shape intelligence workflows, including PIRs, ATT&CK-aligned investigations, threat modeling, prioritization, collaboration, and intelligence-driven automation
- Represent Cyware on MITRE and industry alliance committees, and bring what you learn back inside
- Be the threat intelligence SME for the field
- Serve as the technical threat intelligence expert for customers, prospects, and partners, translating complex intelligence concepts into practical business value
- Enable Solution Architects, Sales Engineers, and partners to communicate Cyware’s threat intelligence value proposition effectively