Threat Intelligence Engineer — AI-Driven & STIX Expert

Cyware

Charlotte (NC)

On-site

USD 140,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Time off
Paid holidays
Retirement plans
Insurance coverage

Job summary

Cyware is seeking a Threat Intelligence Engineer to map feeds to STIX 2.1, design semantic mappings, and own the connector portfolio. You will work across feeds from CrowdStrike to MISP, applying AI to accelerate workflows and uphold data fidelity.

This role requires hands-on coding in Python and deep MITRE ATT&CK knowledge. You will engage with customers and cross-functional teams to translate complex intelligence concepts into practical business value, shaping product direction and integration

Qualifications

  • 5+ years in threat intelligence as an analyst, engineer, or specialist.
  • Deep working knowledge of STIX/TAXII 2.1 objects, relationships, patterning, markings, and how to handle source data that does not fit the standard cleanly.
  • Hands-on experience with commercial and open-source threat feeds and enrichment sources.
  • Practical AI fluency using LLMs for schema inference, data mapping, and automation.
  • Strong command of MITRE ATT&CK and intelligence lifecycle.

Responsibilities

  • Map feeds to STIX and own the connector portfolio.
  • Design and maintain mappings from threat intelligence sources into STIX 2.1 objects and relationships.
  • Inspect live payloads and vendor dashboards to establish ground truth when API docs are incomplete.
  • Own connector lifecycle: onboarding, schema drift, validation, and production reliability.
  • Collaborate with feed, sandbox, DRP, and enrichment partners on integrations and use cases.
  • Leverage AI to accelerate engineering workflows and build AI-assisted mappings.
  • Be the threat intelligence SME for Product and customers, translating concepts into business value.
  • Write use cases that drive product design and validate against analyst workflows.

Skills

Threat intelligence
Python
AI fluency
MITRE ATT&CK
STIX/TAXII 2.1
Cross-functional collaboration

Tools

CrowdStrike
Mandiant
Recorded Future
Flashpoint
Intel 471
MISP

Job description

Cyware is seeking a Threat Intelligence Engineer to map feeds to STIX 2.1, design semantic mappings, and own the connector portfolio. You will work across feeds from CrowdStrike to MISP, applying AI to accelerate workflows and uphold data fidelity.

This role requires hands-on coding in Python and deep MITRE ATT&CK knowledge. You will engage with customers and cross-functional teams to translate complex intelligence concepts into practical business value, shaping product direction and integration

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI-Driven Threat Intelligence Engineer
AI-Driven Threat Intelligence Engineer

Cyware • United States

Remote
USD 120,000 - 180,000
Competitive compensation
Career growth opportunities
Comprehensive benefits package
+1
Threat Intelligence Engineer (REMOTE)
Threat Intelligence Engineer (REMOTE)

Cyware • Charlotte (NC)

On-site
USD 140,000 - 180,000
Time off
Paid holidays
Retirement plans
+1
Threat Intelligence Engineer: SIEM & Automation
Threat Intelligence Engineer: SIEM & Automation

Take-Two Interactive Software, Inc. • Austin (TX)

On-site
USD 110,000 - 170,000
Culture of innovation
Growth opportunities
Benefits package
Sr Cyber Threat Intelligence Analyst
Sr Cyber Threat Intelligence Analyst

PRI Technology • Austin (TX)

On-site
USD 90,000 - 120,000
Senior Threat Intelligence Engineer: Research to Production
Senior Threat Intelligence Engineer: Research to Production

Towards AI, Inc. • Washington

On-site
USD 140,000 - 150,000
Cyber Threat Intelligence Architect
Cyber Threat Intelligence Architect

Cyber Security Industry • United States

Remote
USD 110,000 - 160,000
Threat Intelligence Automation Specialist
Threat Intelligence Automation Specialist

Compunnel, Inc. • Pennsylvania

On-site
USD 120,000 - 150,000
Threat Intelligence Automation Engineer
Threat Intelligence Automation Engineer

Compunnel, Inc. • Pennsylvania

On-site
USD 120,000 - 150,000
Cyber Security - Threat Intelligence Automation Engineer
Cyber Security - Threat Intelligence Automation Engineer

The Planet Group • Exton (PA)

Hybrid
USD 103,320 - 117,096
Threat Intelligence Analyst: MITRE-Driven SOC Expert
Threat Intelligence Analyst: MITRE-Driven SOC Expert

Infosys Limited • Carolina (RI)

On-site
USD 110,000 - 150,000
Disability benefits
Health insurance
401(k) plan