Get more replies from employers
Send a job-specific resume in minutes.
Proofpoint in the United States (Arizona) seeks a software engineer to build and operate the Threat Intelligence Services platform. You will own tools end to end: standing up and running the team\'s AWS environment, building APIs and integrations, and shipping web front-ends and automation relied on daily to produce and deliver intelligence at scale.
You will work with Python and React on a security-focused team, delivering reliable software with minimal supervision and collaborating with
Proofpoint is a global leader in human- and agent-centric cybersecurity. We protect how people, data, and AI agents connect across email, cloud, and collaboration tools. Over 80 of the Fortune 100, 10,000 large enterprises, and millions of smaller organizations trust Proofpoint to stop threats, prevent data loss, and build resilience across their people and AI workflows. Our mission is simple: safeguard the digital world and empower people to work securely and confidently. Join us in our pursuit to defend data and protect people.
The Threat Intelligence Services (TIS) team turns Proofpoint's threat data and telemetry into intelligence products for customers through reporting, analytics, detection content, and live briefings. Behind that work is a fast-growing suite of internal web applications, data integrations, automation, cloud infrastructure, and a customer -facing CMS. We are hiring a software engineer to build and operate that platform.
You will own tools end to end: standing up and running the team's AWS environment, building the APIs and integrations that connect internal threat-intel systems, third-party feeds, and AI/LLM services, and shipping the web front-ends and automation the analyst team relies on daily to produce and deliver intelligence at scale. This is a builder role for a full-stack, infrastructure-comfortable engineer who can take an idea from an analyst to a deployed, dependable tool with minimal supervision.
This is the engineering counterpart to our customer-facing Threat Intelligence Analyst role: you make the analysts faster and their output sharper by replacing manual, repetitive workflows with reliable software and ensure that customers can reliably access content and APIs.
Languages: Python, JavaScript (React/JSX)
Cloud: AWS - Lambda, API Gateway, IAM, Secrets Manager, CloudWatch, ALB/VPC
IaC : Terraform / Terramake
CMS: dotCMS
API/Auth: REST APIs, custom authorizers, JWT / API keys
Domain: Threat intelligence / IOC feeds (STIX, MISP, CSV)
Tooling: Git, CI/CD, AWS CLI
At Proofpoin