Remote Threat Detection Engineer

Team Cymru

United States

Remote

USD 120,000 - 180,000

Full time

10 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Team Cymru is seeking a seasoned threat intelligence analyst to join our remote team. You will conduct proactive threat research, develop detection rules, and analyze network data across PDNS, NetFlow, PCAP, and TLS. Strong coding in Python, SQL databases, and experience with large datasets are essential.

You’ll collaborate across groups to deliver actionable intelligence and client-ready reports. Join a mission-driven company protecting global cyber infrastructure through open collaboration and

Qualifications

  • 5+ years of experience as a threat intelligence analyst, network forensics analyst, or IT security analyst.
  • Experience coding with Python and database technologies (e.g. PostgreSQL, ClickHouse).
  • Demonstrated experience developing network-level threat detection rules derived from querying and analyzing large, disparate datasets.
  • Proven track record of leading complex analytical projects, including managing multiple concurrent workstreams.
  • Experience tracking APT, nation-state, or cybercriminal actors, with the ability to place their activity in a broader geopolitical or strategic context.
  • Outstanding network infrastructure and traffic analysis skills: PCAP, NetFlow, PDNS, open ports, certificates.
  • Deep working knowledge of IP networking and internet services: DNS, HTTP/HTTPS, TLS, VPNs, and routing protocols (BGP).
  • Strong familiarity with common OSINT platforms and research techniques.
  • Proven ability to work effectively in a distributed, remote team, including a willingness to conduct peer review and share tradecraft.
  • Exceptional oral and written communication skills.

Responsibilities

  • Translate research findings into durable detection rules and processes that build automated tracking mechanisms for ongoing monitoring of threats and adversary groups.
  • Generate detection rules for network infrastructure based on internal datasets, including PDNS, X.509, service banners, NetFlow, and more.
  • Develop multi-stage infrastructure detection processes involving sophisticated queries across multiple datasets and advanced filtering.
  • Build, maintain, and expand detection process infrastructure on K8s, bare-metal, and virtualized servers.
  • Conduct quality assurance (QA) reviews on candidate detections developed by teammates.

Skills

Threat intelligence
Python
Network forensics
PCAP/NetFlow analysis
OSINT
Data analysis
Threat actor tracking
Project leadership
Communication
Big data / SQL databases

Education

Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, or equivalent experience

Tools

GitLab
GitHub
Claude Code
Codex
YARA
Zeek
Suricata

Job description

Team Cymru is seeking a seasoned threat intelligence analyst to join our remote team. You will conduct proactive threat research, develop detection rules, and analyze network data across PDNS, NetFlow, PCAP, and TLS. Strong coding in Python, SQL databases, and experience with large datasets are essential.

You’ll collaborate across groups to deliver actionable intelligence and client-ready reports. Join a mission-driven company protecting global cyber infrastructure through open collaboration and

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Threat Detection Analyst
Threat Detection Analyst

Team Cymru • United States

Remote
USD 120,000 - 180,000
Remote Threat Intelligence Systems Engineer
Remote Threat Intelligence Systems Engineer

Censys • United States

On-site
USD 170,000 - 240,000
Equity
Remote work
Flexible schedule
Threat Detection & Response Engineer (Remote)
Threat Detection & Response Engineer (Remote)

Runway Financial, Inc. • Northern (KY)

Hybrid
USD 150,000 - 230,000
Senior Cyber Defense & Threat Response Lead - Remote
Senior Cyber Defense & Threat Response Lead - Remote

Prestige Staffing • Dallas (TX)

On-site
USD 120,000 - 180,000
Contract extension potential
Remote work
Career growth
+2
Remote Threat Detection & Response Engineer — IR & SOC
Remote Threat Detection & Response Engineer — IR & SOC

Whatnot • United States

Remote
USD 120,000 - 170,000
Health Insurance
401(k) with employer match
Work From Home Support
+2
Technical Trainer - Curriculum Developer
Technical Trainer - Curriculum Developer

Team Cymru • United States

On-site
USD 90,000 - 140,000
Remote work
Travel opportunities
Senior Threat Detection & Incident Response Engineer
Senior Threat Detection & Incident Response Engineer

Cypress HCM • United States

On-site
USD 174,000 - 190,000
Remote Threat Detection Analyst
Remote Threat Detection Analyst

Zscaler, Inc. • Northern (KY)

Hybrid
USD 97,000 - 138,000
Time off plans
Parental leave
Retirement options
+1
Senior Threat Detection Engineer — Hybrid Role
Senior Threat Detection Engineer — Hybrid Role

Earlywarning • Scottsdale (AZ)

Hybrid
USD 132,000 - 165,000
Discretionary incentive plan
Benefits
Threat Intelligence Engineer - Remote-Ready Detection Systems
Threat Intelligence Engineer - Remote-Ready Detection Systems

Anthropic • Washington, San Francisco (CA)

Hybrid
USD 320,000 - 405,000