Snowflake Computing

Principal Security Engineer - Threat Intelligence

Snowflake Computing$130K — $180K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years in threat intelligence, cyber threat research, or related security fields.
  • Strong engineering skills with coding experience in Python or Go.
  • Expertise in the threat actor ecosystem and tactics used by adversaries.
  • Experience operationalizing threat intelligence and influencing security measures.
  • Familiarity with OSINT tools and methodologies.
  • Ability to assess security risks associated with cloud-native environments.
  • Collaborative communication skills for engaging with multiple security functions.

Responsibilities

  • Define and evolve Snowflake's Threat Intelligence strategy and investments.
  • Profile and track threat actors relevant to Snowflake and its ecosystem.
  • Operationalize intelligence to prioritize and drive security initiatives.
  • Produce high-quality intelligence reports for various stakeholders.
  • Engineer solutions to enhance efficiency and impact of the Threat Intelligence program.
  • Develop AI-assisted workflows for intelligence tasks and quality measurement.
  • Collaborate with security teams to convert intelligence into actionable detections.

Benefits

  • Opportunity to shape and lead Snowflake's Threat Intelligence program.
  • Engage in cutting-edge AI and automation in security workflows.
  • Collaborative and team-oriented culture emphasizing partnership.
  • Mentorship opportunities to elevate team technical and operational skills.
  • Work with a global leader in cloud-native data solutions.
Full Job Description
As we continue to scale globally, we are investing in security capabilities that help us better understand, anticipate, and mitigate threats targeting Snowflake, our customers, and our ecosystem. We are looking for a Principal Security Engineer - Threat Intelligence who will help shape the next phase of Snowflake's Threat Intelligence program and extend the reach and impact of Threat Intelligence across Snowflake. This role will combine deep intelligence expertise with strong engineering and program leadership skills, with AI and automation as core primitives in how we collect, analyze, prioritize, and operationalize intelligence.

The ideal candidate will help Snowflake leadership and security stakeholders make informed, risk-based, and data-driven decisions based on actionable threat intelligence. You will identify and track threat actors targeting cloud-native environments such as Snowflake, translate intelligence into concrete defensive outcomes, and build scalable approaches that improve how intelligence is delivered across the company.

This is a principal-level individual contributor role for someone who can operate strategically and technically: driving program maturity, building durable partnerships across Security and Engineering, and engineering AI-assisted workflows that help us move faster without sacrificing quality.

WHAT YOU NEED:
  • Deep experience in threat intelligence, with strong background in several of: adversary intelligence, intrusion intelligence, supply-chain intelligence, identity intelligence, domain intelligence, and threat-informed defense.
  • Strong understanding of today's threat actor ecosystem, including nation-state actors, criminal organizations, ransomware groups, fraud ecosystems, and the platforms and communities that enable them.
  • Demonstrated ability to operationalize threat intelligence and influence security priorities in partnership with detection, incident response, product security, cloud security, anti-abuse, and other stakeholders.
  • Strong engineering skills, including experience writing code in high-level languages such as Python or Go, building automations, and working with data-heavy security workflows.
  • Experience building or driving AI-assisted workflows for intelligence analysis, research triage, summarization, collection, prioritization, or investigative support, and good judgment about where AI adds value versus where human analysis is required.
  • Ability to research threat actors' TTPs, infrastructure, targets, and objectives, and map those risks to Snowflake's product, enterprise, and customer environment.
  • Experience with OSINT tools, data sources, investigative methodologies, and intelligence reporting for technical and executive audiences.
  • Strong understanding of threat hunting and threat detection methodologies, and the ability to turn intelligence into hunts, detection opportunities, and control recommendations.
  • A risk-based approach to security, with the ability to prioritize work based on business impact and evolving threat conditions.
  • A humble, team-oriented mindset with a bias toward collaboration, execution, and raising the bar for the broader team.


WHAT YOU WILL DO:
  • Help define and mature the strategy for Threat Intelligence at Snowflake, including where the program should invest in people, processes, engineering, and AI-enabled capabilities.
  • Identify, profile, and track threat actors targeting Snowflake, our customers, partners, and ecosystem, and translate that intelligence into relevant, actionable outcomes.
  • Operationalize threat intelligence to help prioritize security initiatives and drive action with the relevant security teams and stakeholders.
  • Produce high-quality intelligence reports, assessments, briefs, and leadership-ready communications based on external events, internal requirements, and proactive research.
  • Engineer solutions that improve the efficiency, scale, and impact of the Threat Intelligence program, including automations, collection pipelines, enrichment workflows, and analyst tooling.
  • Build and improve AI-assisted intelligence workflows for tasks such as report triage, signal enrichment, summarization, vendor/customer monitoring, and threat-informed hunts, with strong measurement and quality..
  • Partner closely with Threat Detection, Incident Response, and other security teams to convert intelligence into detections, threat hunts, investigative pivots, and control recommendations.
  • Monitor alerts, intelligence feeds, vendor reporting, and external developments for threat events that may affect Snowflake.
  • Drive standards for how intelligence is curated, evaluated, delivered, and measured so the program remains high-signal, timely, and scalable.
  • Mentor other engineers and analysts by raising the team's technical depth, analytic rigor, and operational maturity.


MINIMUM QUALIFICATIONS:
  • Significant experience in threat intelligence, cyber threat research, intelligence engineering, or closely related security disciplines.
  • Experience researching and tracking sophisticated threat actors targeting cloud-native and SaaS environments.
  • Experience writing code in a high-level programming language such as Python or Go and using code to automate manual workflows or analyze security data at scale.
  • Experience handling data programmatically using tools such as SQL and Python, ideally against large datasets relevant to security analytics or intelligence workflows.
  • Experience collaborating across multiple security functions and communicating effectively with technical stakeholders and leadership.
  • Strong understanding of enterprise security controls, threat hunting, and detection methodologies.
  • Experience with one or more major cloud providers (AWS, Azure, GCP) and familiarity with the risks that impact cloud and SaaS environments.


PREFERRED QUALIFICATIONS:
  • Experience leading or materially shaping a Threat Intelligence program at scale.
  • Experience building AI/ML-assisted security workflows or evaluating AI systems for security use cases.
  • Experience with data engineering, workflow orchestration, or production-grade systems that support intelligence or security operations at scale.
  • Experience with Snowflake or equivalent cloud data platforms for large-scale analysis and investigative workflows.
  • Experience presenting externally, publishing research, or demonstrating thought leadership in the security space.
  • Experience building capabilities that support intelligence-driven detection, hunting, or response at a global scale.

About Snowflake Computing

Snowflake is a cloud-based data-warehousing company that was founded in 2012. The company provides a data platform that allows customers to store and analyze data using cloud-based infrastructure. Snowflake's platform is designed to be highly scalable and flexible, allowing customers to easily add or remove computing resources as needed. The company's customers include a wide range of businesses, from startups to Fortune 500 companies. Snowflake has received significant funding from investors and has been recognized as one of the fastest-growing companies in the United States.
Learn more about Snowflake Computing
Size
2,037 employees
Market Cap
$44.9 billion
Industry
Net Income
-$539.1 million
Founded
2012
Revenue
$592 million
NASDAQ

Similar Jobs

More Jobs at Snowflake Computing

More Information Technology Jobs

Find similar Principal Security Engineer - Threat Intelligence jobs: