Security Engineer, Threat Intelligence

Fluidstack

$220K — $280K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Expertise in tracking nation-state or advanced criminal actors and understanding their tactics, techniques, and procedures (TTPs).
  • Proficient in writing production-quality Python (or similar) for automation and data pipelines.
  • Hands-on experience with malware, infrastructure, and log analysis to validate findings.
  • Experience in developing and deploying detection logic (YARA, Sigma, or SIEM queries) in production environments.
  • Collaborative experience with detection engineering and incident response teams during live events.
  • Strong ability to distill complex intelligence into actionable insights for technical and executive stakeholders.
  • Bonus: Active network in the threat intelligence community and contributions to public research or open-source projects.

Responsibilities

  • Secure cutting-edge AI infrastructure, proactively preventing breaches.
  • Develop and execute a comprehensive security program from the ground up.
  • Analyze large-scale threats with an emphasis on newly emerging nation-state tactics.
  • Create pipelines for real-time intelligence processing and integration.
  • Conduct intelligence-led hunts across diverse IT and OT environments.
  • Perform hands-on malware analysis to inform defense strategies.
  • Build and nurture relationships for external intelligence sharing with partners.

Benefits

  • Competitive total compensation package including salary and equity.
  • Retirement or pension plan aligned with local standards.
  • Comprehensive health, dental, and vision insurance.
  • Generous PTO policy consistent with local practices.
Full Job Description
How We Operate
  • Be a barrel. Full autonomy. Own things end to end, take on scope without being asked, no permission required to operate outside your core role.
  • Insane urgency. We drive everything forward as fast as possible.
  • Reason from first principles. Challenge every assumption. Zero analogy thinking, no egos, the best idea wins.
  • Love of the game. The frontier of AI is the most interesting problem of our time. We put in long hours at high intensity to push the frontier forward.
  • Build something that actually matters. If you're going to spend your time, spend it on something that matters to the world.


How We Operate
  • Extreme ownership. Full autonomy. Own things end to end often taking on scope outside your core role without being asked to get things done.
  • Velocity. We drive everything forward as fast as possible.
  • First principles. Challenge every assumption. Zero analogy thinking, no egos, the best idea wins.
  • Love of the game. The frontier of AI is the most interesting problem of our time. We put in long hours at high intensity to push the frontier forward.
The Security Team

Examples of key problems the team is working on
  • You're securing the frontier of AI. The model weights training on our infrastructure are the most valuable and most targeted artifacts in technology, and we're standing up the compute to hold them faster than anyone ever has. A breach isn't a leak, it's the frontier walking out the door.
  • Build the entire security program from scratch. Most leaders inherit someone else's system and spend a career patching it. Here you own it end to end, bare metal to boardroom, as we scale across continents.
  • Your threat surface is measured in gigawatts. The customers running on our infrastructure are building the most consequential technology in human history, and being responsible for the physical and logical security of that work makes everything else feel small.
Role Scope
  • Track the nation-state and advanced criminal actors most likely to target frontier AI infrastructure, and turn their tooling, infrastructure patterns, and tradecraft into intelligence that changes what the program detects and hunts for.
  • Build and run the pipelines that collect, enrich, and correlate indicators, then push them into the detection and agentic triage stack so intelligence becomes operational instantly.
  • Drive intelligence-led hunts across enterprise, cloud, identity, data center IT, and OT telemetry, and convert findings into high-fidelity detections authored as code.
  • Perform hands-on malware, phishing-infrastructure, and attacker-tooling analysis to extract indicators, TTPs, and attribution signals that feed detection engineering and incident response in near real time.
  • Curate the inbound intelligence pipeline across commercial feeds, open source, government, and peer relationships, and prioritize what actually matters for the program's threat model.
  • Build and maintain the external intelligence-sharing relationships (ISACs, peer AI and cloud security teams, government partners) that keep the program ahead of active campaigns.
What We're Looking For

The below is a starting point. We always make space for exceptional people, so if you don't fit this role exactly, tell us where you would.
  • You've tracked specific nation-state or advanced criminal actors as a core part of your job, and you know their tooling, infrastructure, and targeting well enough to anticipate their next move.
  • You write production-quality Python (or similar) and have built the automation and data pipelines your intelligence work depended on, end to end.
  • You've done hands-on malware, infrastructure, and log analysis to develop and validate your own findings.
  • You've authored quality detection logic (YARA, Sigma, or SIEM-native queries) that shipped to production and held up against real adversary activity.
  • You've worked shoulder to shoulder with detection engineers and incident responders, turning intelligence into detections, hunting hypotheses, and incident context while an event was still live.
  • You write intelligence that gets read and acted on, distilling a complex campaign into a decision and a next step for an engineer or an executive.
  • Bonus: An active network in the threat intelligence community and a habit of sharing in both directions. Experience defending large-scale GPU or AI compute infrastructure, data centers, or multi-tenant cloud environments. Applying LLMs or agentic tooling to accelerate collection, enrichment, and analysis. Public research, conference talks, or open-source contributions in the CTI space.
Salary & Benefits
  • Competitive total compensation package (salary + equity).
  • Retirement or pension plan, in line with local norms.
  • Health, dental, and vision insurance.
  • Generous PTO policy, in line with local norms.

The base salary range for this position is $220,000 - $280,000 per year, depending on experience, skills, qualifications, and location. This range represents our good faith estimate of the compensation for this role at the time of posting. Total compensation may also include equity in the form of stock options.

We are committed to pay equity and transparency.

You will receive a confirmation email once your application has successfully been accepted. If there is an error with your submission and you did not receive a confirmation email, please email [redacted] with your resume/CV, the role you've applied for, and the date you submitted your application-- someone from our recruiting team will be in touch.

Similar Jobs

More Jobs at Fluidstack

More Information Technology Jobs

Find similar Security Engineer, Threat Intelligence jobs: