Security Engineer, Cyber Threat Intelligence

Saronic

San Diego (CA)

On-site

USD 120,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Saronic in San Diego seeks a Security Engineer for Cyber Threat Intelligence to run a real intelligence program, turning indicators into operational defenses and guiding cross-functional teams. You will own threat-hunting initiatives, develop detections with Sigma/YARA, and model adversary campaigns using MITRE ATT&CK.

Responsibilities include evolving Priority Intelligence Requirements, fusing intel with internal telemetry, and delivering concise intelligence and briefings to leadership.

Qualifications

  • Experience leading intelligence programs and turning indicators into defensive actions.
  • Ability to track nation-state and advanced criminal actors affecting defense/industrial sectors.
  • Familiarity with CTI life cycle, collection management, and analytic tradecraft.

Responsibilities

  • Own and evolve Priority Intelligence Requirements and collection framework.
  • Track adversaries and maintain profiles for campaigns and threat actors.
  • Operationalize indicators into detections, hunts, and prioritized remediation.
  • Fuse external intel with internal telemetry in graph-based CTI platforms.
  • Produce concise, actionable intelligence and briefings for security leadership.

Skills

Threat intelligence
Threat hunting
Detection engineering
MITRE ATT&CK
Structured analytic techniques
Automation/engineering
DoD/DIB context

Tools

Sigma
YARA
SIEM
MISP
TAXII/STIX
Python

Job description

  • Security at Saronic is a force multiplier, not a blocker. An autonomous-maritime defense company is a top-tier target for nation-state and advanced criminal actors, and we’re looking for a Security Engineer for Cyber Threat Intelligence to make sure we see them coming. This is a hands‑on, doctrine‑driven engineering role, not a reporting desk: you’ll run a real intelligence program and turn raw indicators into operational defenses
  • You’ll work across Security Operations, Detection Engineering, Vulnerability Management, Physical Security, Insider Threat, Data Loss Prevention, and Red Team to focus on the adversaries targeting the defense industrial base
  • This is an opportunity to help run the threat‑intelligence function for a fast‑growing defense company, fuse intelligence with detection engineering rather than isolating it as reporting, and directly shape how we anticipate threats to our vessels, supply chain, people, and data
  • Priority Intelligence Requirements & Collection: Help own and evolve our Priority Intelligence Requirements and collection‑management framework, translating leadership decisions and our maritime‑autonomy and defense‑industrial‑base threat model into tasked collection, hunts, and finished intelligence
  • Adversary Tracking: Track the priority adversaries, including nation‑state, APT, and advanced criminal actors most likely to target defense, maritime, and the broader industrial base, along with their tooling, infrastructure, and tradecraft, and maintain adversary and campaign profiles
  • Turn Intelligence into Action: Operationalize indicators and TTPs into detections, hunts, and prioritized remediation, and build the pipelines and connectors that ingest, enrich, and correlate intel from commercial feeds and OSINT. Turn raw data into verified intelligence products that meaningfully influence decision‑making at all levels of the organization
  • Fuse Internal & External: Fuse external intelligence with internal telemetry in our graph‑based intelligence data store, running attack‑path and identity‑to‑asset correlation to prioritize by real exposure rather than CVSS alone
  • Finished Intelligence: Produce concise, actionable intelligence and briefings for security leadership and cross‑functional partners, applying analytic tradecraft, estimative language, calibrated confidence, and structured analytic techniques, and modeling with STIX and MITRE ATT&CK
  • Hunting & Detection: Develop and run intelligence‑driven threat hunts across endpoint, cloud, identity, email, and network telemetry, and author durable detections (Sigma, YARA) with detection engineering and incident response
  • Infrastructure & Malware Analysis: Perform infrastructure pivoting (passive DNS, certificate pivoting, WHOIS/ASN) and malware triage to extract indicators, TTPs, and attribution signals
  • Digital Risk & Identity Protection: Run deep and dark‑web, breach‑credential, and identity‑exposure monitoring, including account‑takeover, executive and VIP protection, and brand‑impersonation, and coordinate takedowns with Legal, Comms, and IT
  • Deception & Automation: Help design and operate cyber‑deception sensors (honeytokens, canaries, decoys) for high‑fidelity, low‑noise alerts, and build case‑automation and in‑case AI‑agent workflows for enrichment and triage
  • Prolonged periods of sitting at a desk and working on a computer
  • Occasional standing and walking within the office
  • 4+ years in cyber threat intelligence, threat hunting, detection engineering, or intrusion analysis, or an equivalent combination of experience and demonstrated ability, with demonstrable tracking of sophisticated or state‑sponsored adversaries that drove detection, hunting, or response
  • Hands‑on infrastructure and log analysis (passive DNS, certificate pivoting, WHOIS/ASN) and detection authoring (Sigma, YARA, or SIEM-native)
  • Strong software engineering to build automation, connectors, and data pipelines end to end
  • Working command of MITRE ATT&CK, the Diamond Model, and the Cyber Kill Chain, plus STIX/TAXII for modeling and sharing intelligence
  • Ability to obtain and maintain a U.S. security clearance
  • Fluency with the intelligence lifecycle, Priority Intelligence Requirements and collection management, and structured analytic techniques, and the ability to produce finished intelligence with calibrated confidence
  • Nation‑state/APT tracking relevant to the defense industrial base, maritime, or manufacturing industries
  • Standing up or operating an in‑house or graph‑based CTI platform, MISP, or a TAXII/STIX pipeline
  • Malware analysis and adversary attribution (provisional clustering; tactical, operational, and strategic attribution)
  • Cyber‑deception design and operations (honeytokens, canaries, decoys)
  • Digital risk protection and dark‑web tradecraft: breach‑credential, executive‑protection, and brand‑impersonation monitoring and takedowns
  • Applying LLMs and AI tooling to accelerate collection, enrichment, and analysis, including agentic case automation
  • DoD/DIB context (CMMC/NIST 800‑171, GovCloud, ITAR) and military intelligence doctrine
  • OT/ICS or maritime security knowledge
  • Public CTI research, talks, or open‑source contributions
  • If your experience doesn’t line up with every preferred qualification, we still encourage you to apply; we hire for demonstrated ability and outcomes
  • Manual dexterity to operate a computer keyboard, mouse, and other office equipment
  • Visual acuity to read screens, documents, and reports
  • Lifting and carrying items up to 20 pounds occasionally (e.g., office supplies, packages)
  • Occasional reaching, bending, or stooping to access file drawers, cabinets, or office supplies
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Cyber Threat Intelligence
Security Engineer, Cyber Threat Intelligence

Saronic Technologies • San Diego (CA)

On-site
USD 140,000 - 200,000
Medical Insurance
401(k) with company match
Dental and Vision Insurance
+5
Security Engineer, Cyber Threat Intelligence
Security Engineer, Cyber Threat Intelligence

Saronic Technologies • Austin (TX)

On-site
USD 130,000 - 180,000
Medical Insurance
401(k) plan with company match
Stock Options
+3
Detection Engineer, Security Operations & Telemetry
Detection Engineer, Security Operations & Telemetry

Saronic • Austin (TX)

On-site
Security Engineer (Detection Engineering)
Security Engineer (Detection Engineering)

Saronic • Austin (TX)

On-site
USD 95,000 - 120,000
Medical Insurance
Dental and Vision Insurance
Generous PTO
+7
Security Engineer, Detection Engineering
Security Engineer, Detection Engineering

NightDragon Acquisition Corp. • Austin (TX)

On-site
USD 120,000 - 170,000
Medical Insurance
Dental and Vision Insurance
Generous PTO and Holidays
+7
Manager, Threat Detection Engineer
Manager, Threat Detection Engineer

Jobtailor • Washington

On-site
USD 140,000 - 190,000
Senior Security Operations Analyst
Senior Security Operations Analyst

Saronic • San Diego (CA), Austin (TX)

On-site
USD 90,000 - 120,000
Security Engineer (Network Security)
Security Engineer (Network Security)

Saronic • San Diego (CA)

On-site
USD 120,000 - 160,000
Security Analyst: IT & OT Threat Hunter
Security Analyst: IT & OT Threat Hunter

Southern Star Central Gas Pipeline • Owensboro (KY)

On-site
USD 60,000 - 90,000
Medical
Vision
Supplemental Life Insurance
+9
Security Operations Engineer
Security Operations Engineer

Reserv • Atlanta (GA)

Hybrid
USD 80,000 - 100,000
Generous health-insurance package
401(k) retirement plan with employer matching
Competitive PTO policy
+1