Threat Intelligence Engineer

Entech

Malvern (Chester County)

Hybrid

USD 140,000 - 190,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health, Dental, Vision, 401(k)

Job summary

Entech is hiring a Threat Intelligence Engineer for a financial services client. This hybrid role requires on-site work in Malvern, PA three days per week, with remote flexibility on other days.

You will design and build automation workflows, integrate TIPs with SOAR, SIEM, and cloud tooling, and own the Threat Intelligence Platform, driving data quality and performance.

Qualifications

  • Hands-on experience with ThreatConnect or any of Anomali, ThreatQ, OpenCTI are acceptable
  • Cybersecurity experience with at least one year in security engineering, automation, DevSecOps, software development, or related technical discipline
  • Strong proficiency in Python and experience developing automation workflows and APIs
  • Experience integrating systems using REST APIs, webhooks, and modern data-exchange
  • Experience with structured and unstructured security data (JSON, XML, CSV)
  • Experience with threat intelligence concepts, methodologies, and operational workflows
  • Experience implementing or supporting Threat Intelligence Platforms (TIPs) and intelligence standards such as STIX, TAXII

Responsibilities

  • Design, develop, and maintain automation workflows for intelligence collection, enrichment, analysis, dissemination, and reporting
  • Build integrations between TIP, SOAR platforms, SIEMs, cloud environments, and security tooling
  • Design and maintain automated workflows for ingestion, enrichment, deduplication, scoring, validation, and dissemination of IOCs
  • Integrate diverse intelligence sources into the TIP and related security platforms
  • Automate delivery of intelligence to security controls (SIEM, EDR, email security, network security)
  • Serve as primary technical owner of the TIP, responsible for automation, data quality, platform integrations, workflow design, and maturation
  • Identify opportunities to improve platform performance, scalability, and user experience
  • Vulnerability Intelligence Automation: develop pipelines to collect, normalize, enrich, and correlate vulnerability intelligence
  • Build workflows correlating vulnerabilities with threat actor activity, exploits, campaigns, and tech exposure
  • Security Operations Integration: partner with IR, Detection Engineering, Threat Hunting, Vulnerability Management, SO teams
  • Develop integrations that improve information sharing, collaboration, and workflow efficiency
  • Translate intelligence requirements into scalable automation and engineering solutions
  • Collections and Data Engineering: develop data ingestion, normalization, transformation, and enrichment processes
  • Lead intelligence collections engineering and data integration initiatives
  • Innovation and Continuous Improvement: reduce manual processes via automation and orchestration
  • Evaluate emerging technologies, including AI-enabled capabilities, for intelligence collection and delivery
  • Establish metrics and reporting to measure automation effectiveness and operational outcomes

Skills

Python
Threat intelligence concepts
REST APIs
JSON/XML/CSV
Threat intelligence platforms (TIP)
Security engineering background

Tools

ThreatConnect
Anomali
ThreatQ
OpenCTI

Job description

Going digital requires holistic thinking that puts humans at the center of everything. Entech delivers complete solutions including strategies, technologies, and implementation services to master digital convergence. We integrate our unique outside-in approach to people, processes, and technology to orchestrate digital empowerment to address today's business challenges. Mastering digital convergence at enterprise scale.

Entech is hiring a Threat Intelligence Engineer for a financial services client. This is a hybrid role that involves working onsite in Malvern, Pennsylvania (3 days per week)

Job Description

This role sits at the intersection of threat intelligence, security engineering, automation, and software development. You will work closely with Threat Intelligence, Incident Response, Detection Engineering, Threat Hunting, Vulnerability Management, and Security Operations teams to develop scalable solutions that transform intelligence into action while enhancing client's ability to anticipate, detect, and respond to cyber threats.

  • Design, develop, and maintain automation workflows that support intelligence collection, enrichment, analysis, dissemination, and reporting.
  • Build integrations between the Threat Intelligence Platform (TIP), SOAR platforms, SIEMs, cloud environments, and security tooling.
  • Design and maintain automated workflows for ingestion, enrichment, deduplication, scoring, validation, and dissemination of indicators of compromise (IOCs).
  • Integrate commercial, open-source, industry, internal, and government intelligence sources into the TIP and related security platforms.
  • Automate delivery of intelligence to security controls, including SIEM, EDR, email security, network security, and detection engineering platforms.
  • Serve as a primary technical owner of the Threat Intelligence Platform, responsible for automation development, data quality, platform integrations, workflow design, and capability maturation.
  • Identify opportunities to improve platform performance, scalability, and user experience
  • Vulnerability Intelligence Automation
  • Develop automation pipelines that collect, normalize, enrich, and correlate vulnerability intelligence from sources including NVD, CISA KEV, vendor advisories, ISACs, security research, and internal telemetry.
  • Build workflows that correlate vulnerabilities with threat actor activity, exploit availability, malware campaigns, and enterprise technology exposure.
  • Security Operations Integration
  • Partner with Incident Response, Detection Engineering, Threat Hunting, Vulnerability Management, and Security Operations teams to automate intelligence-driven workflows.
  • Develop integrations that improve information sharing, operational collaboration, and workflow efficiency across security teams.
  • Translate intelligence requirements and analyst use cases into scalable automation and engineering solutions.
  • Collections and Data Engineering
  • Develop and maintain data ingestion, normalization, transformation, and enrichment processes that support intelligence operations.
  • Serve as a technical leader for intelligence collections engineering and data integration initiatives.
  • Innovation and Continuous Improvement
  • Identify opportunities to eliminate manual processes and improve efficiency through automation and orchestration.
  • Evaluate and implement emerging technologies, including AI-enabled capabilities, that enhance intelligence collection, enrichment, analysis, and operational effectiveness.
  • Establish metrics and reporting to measure automation effectiveness, analyst efficiency gains, intelligence delivery speed, and operational outcomes.
Qualification (8+ minimum years required)
  • Hands-on experience with ThreatConnect or Any of the following: Anomali, ThreatQ, OpenCTI are also acceptable
  • Must have cybersecurity experience with at least one year focused on security engineering, automation, DevSecOps, software development, or related technical disciplines.
  • Strong proficiency in Python and experience developing and maintaining automation workflows and APIs.
  • Experience integrating systems using REST APIs, webhooks, and modern data exchange methodologies.
  • Experience working with structured and unstructured security data, including JSON, XML, CSV, and related formats.
  • Experience with threat intelligence concepts, methodologies, and operational workflows
  • Experience implementing or supporting Threat Intelligence Platforms (TIPs) and intelligence standards such as STIX, TAXII
Company Benefits (Can includes)
  • Health, Dental, Vision, 401(k), 20 days of Paid Time Off (PTO)
Preference: W2
Schedule: Hybrid Work
Work Location: Malvern, PA
Additionally

Entech is an equal-opportunity employer.

This is an On-site role work schedule based out of Malvern, PA office three days on week

No Third-party candidates will be accepted, this is strictly a direct employment opportunity with Entech

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Intelligence Automation Engineer
Threat Intelligence Automation Engineer

The Planet Group • Exton (PA)

Hybrid
Threat Intelligence Engineer
Threat Intelligence Engineer

Anthropic • Washington, San Francisco (CA)

Hybrid
USD 320,000 - 405,000
Threat Intelligence Automation Engineer
Threat Intelligence Automation Engineer

Compunnel, Inc. • Pennsylvania

On-site
USD 120,000 - 150,000
Senior Threat Intelligence Engineer
Senior Threat Intelligence Engineer

Jobtailor • Austin (TX)

On-site
USD 100,000 - 130,000
Threat Intel Research Engineer
Threat Intel Research Engineer

DTEX Systems Inc. • San Francisco (CA)

Hybrid
USD 140,000 - 180,000
Competitive compensation
Equity participation
Health and wellness benefits
+2
Threat Intel Research Engineer
Threat Intel Research Engineer

DTEX • United States

Hybrid
USD 140,000 - 180,000
Competitive compensation
Equity participation
Health and wellness benefits
+2
Senior Threat Intelligence Analyst
Senior Threat Intelligence Analyst

TENEX.AI • United States

On-site
USD 90,000 - 130,000
Competitive salary and benefits
Culture of growth and development
Opportunity to work with cutting-edge AI-driven technologies
Advanced Threat Hunter-Public Trust Clearance required
Advanced Threat Hunter-Public Trust Clearance required

SixGen, Inc. • United States

On-site
USD 85,000 - 95,000
Disability & life insurance
401K with 4% match
Flexible/remote work policies
+1
Security Engineer - Threat Intel
Security Engineer - Threat Intel

Anthropic • New York (NY)

On-site
USD 320,000 - 405,000
Detection & Mitigation Engineer
Detection & Mitigation Engineer

United States Digital Space LLC • United States

Hybrid
USD 110,000 - 170,000
Equity plan eligibility