Threat Intelligence Data Engineer

HEROIC

Pune District

On-site

INR 1,381,714 - 2,125,714

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

HEROIC is looking for a senior Threat Intelligence Data Engineer to drive the design and operation of automated intelligence collection systems. This role involves the discovery and ingestion of data from various digital environments. Candidates should possess strong Python skills, at least 4 years of related experience, and familiarity with both SQL and NoSQL databases. The position offers a full-time remote work arrangement from India, with compensation ranging from USD 1300-2000 monthly.

Qualifications

  • Minimum 4 years of experience in data engineering or intelligence collection.
  • Strong expertise in Python and knowledge of web scraping frameworks.
  • Proven experience with automated data collection systems.

Responsibilities

  • Design automated intelligence collection systems.
  • Develop scanning systems to identify unsecured databases.
  • Build ETL pipelines for data processing and normalization.

Skills

Python expertise
Data engineering
Distributed data pipelines
Web protocols
SQL databases
NoSQL databases
Docker
Kubernetes
Linux/Unix

Tools

Scrapy
AWS
Google Cloud Platform (GCP)

Job description

About the Role

HEROIC Cybersecurity (HEROIC.com) is seeking a senior-level Threat Intelligence Data Engineer - Automated Collection & Dark Web Intelligence to design, build, and operate fully automated intelligence collection systems that power our AI-driven cybersecurity and breach intelligence platforms.

This role owns the end-to-end discovery, acquisition, and ingestion pipeline for continuously discovering, crawling, extracting, indexing, and normalizing millions of new artifacts daily —including documents, chats, forums, leaked datasets, repositories, threat actor communications, hacker marketplaces, unsecured infrastructure, and decentralized networks across the surface web, deep web, dark web, and anonymized networks.

Our Threat Research Team’s mission is aggressive: achieve near-total coverage of global breach and leak data with 99%+ automation. Your work directly enables HEROIC’s ability to identify exposures before they are weaponized.

What You Will Do
Automated Intelligence Collection & Discovery

Architect and operate large-scale, distributed crawling and discovery systems across:

  • Surface web, deep web, and dark web
  • Hacker forums, underground marketplaces, and breach communities
  • Chat platforms (Telegram, Discord, IRC, WhatsApp, etc.)
  • Paste sites, code repositories, and social platforms used for breach disclosure
  • Continuously discover, archive, and download newly released datasets, logs, credentials, and artifacts the moment they appear
  • Build automated collectors and archivers for anonymized and decentralized networks including: Tor (.onion), I2P, ZeroNet, Freenet, IPFS, GNUnet, Lokinet, Yggdrasil, and similar systems
  • Design resilient workflows for unreliable, adversarial, or ephemereal data sources
  • Normalize and index data from non-traditional network protocols and formats
Infrastructure & Exposure Discovery
  • Develop automated scanning systems to identify unsecured databases (Elasticsearch, MySQL, PostgreSQL, MongoDB, etc.)
  • Exposed cloud storage (S3, Azure, GCP, DigitalOcean Spaces)
  • Open FTP servers, backups, and misconfigured archives
  • Monitor and ingest data from file hosting and distribution platforms commonly used for breach dumps
Pipeline Engineering & Operations
  • Build ETL pipelines to clean, normalize, enrich, and index structured and unstructured data
  • Implement advanced anti-bot evasion strategies (proxy rotation, fingerprinting, CAPTCHA mitigation, session management)
  • Integrate collected intelligence into centralized databases and search systems
  • Design APIs and internal tooling to support downstream analysis and AI/ML workflows
  • Automate deployment, scaling, and monitoring using Docker, Kubernetes, and cloud infrastructure
  • Continuously optimize performance, reliability, and cost efficiency of crawler clusters
Requirements
  • Minimum 4 years of hands‑on experience in data engineering, intelligence collection, crawling, or distributed data pipelines
  • Strong Python expertise and experience with frameworks such as Scrapy, Playwright, Selenium, or custom async systems
  • Proven experience operating high‑volume, automated data collection systems in production
  • Deep understanding of web protocols, HTTP, DOM parsing, and adversarial scraping environments
  • Experience with asynchronous, concurrent, and distributed architectures
  • Familiarity with SQL and NoSQL databases (PostgreSQL, MongoDB, Elasticsearch, Cassandra)
  • Strong Linux/Unix, shell scripting, and Git-based workflows
  • Experience deploying and operating systems using Docker, Kubernetes, AWS, or GCP
  • Excellent analytical, debugging, and problem‑solving skills
  • Strong written and verbal communication skills
Preferred / High-Value Experience
  • Direct experience with dark web intelligence, breach data, OSINT, or threat research
  • Familiarity with Tor, I2P, underground forums, stealer logs, or credential ecosystems
  • Experience processing large breach datasets or stealer logs
  • Background working in adversarial data environments
  • Exposure to AI/ML‑driven intelligence platforms
Position Details
  • Position Type: Full‑time
  • Location: Remote in India
  • Compensation: USD 1300-2000 monthly
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Database Infrastructure Engineer- Cassandra, DataStax, Big Data Pipelines
Senior Database Infrastructure Engineer- Cassandra, DataStax, Big Data Pipelines

HEROIC Cybersecurity • India

Remote
Paid Time Off
Public Holidays
Professional Growth
Senior Researcher - Dark Web & Threat Intelligence
Senior Researcher - Dark Web & Threat Intelligence

black.ai • Bengaluru

On-site
INR 1,000,000 - 2,000,000
Senior Researcher - Dark Web & Threat Intelligence
Senior Researcher - Dark Web & Threat Intelligence

Cyble • Karnataka

On-site
INR 1,200,000 - 2,000,000
Intelligence Analyst
Intelligence Analyst

Vigilante ATI, Now Part of ZeroFox • Bengaluru

On-site
INR 600,000 - 1,000,000
Competitive compensation
Community-driven culture
Generous time off
+2
Intelligence Analyst
Intelligence Analyst

ZeroFox • Bengaluru

On-site
INR 600,000 - 900,000
Competitive pay
Culture & events
Generous leave
+3
Threat Intelligence Analyst
Threat Intelligence Analyst

Deepwatch • Bengaluru

On-site
INR 1,200,000 - 2,400,000
Security Engineer - Threat Hunting / Threat Intelligence
Security Engineer - Threat Hunting / Threat Intelligence

KPMG Assurance and Consulting Services LLP • Dadri, Gurugram District, Bengaluru

On-site
INR 1,200,000 - 2,000,000
Offensive Security Researcher(Malware and Red Teaming)
Offensive Security Researcher(Malware and Red Teaming)

Globals Inc. • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Impactful cyber defense projects
Global collaboration and thought-lead
Research publication opportunities
+1
Senior Researcher - Dark Web & Threat Intelligence
Senior Researcher - Dark Web & Threat Intelligence

Cyble • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Threat Intelligence Researcher
Threat Intelligence Researcher

Arctic Wolf • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Equity for all employees
Comprehensive private benefits plan
Medical insurance for you and family
+2