Job Summary
We are seeking a Threat Intelligence Automation Engineer to help modernize and automate enterprise cyber threat intelligence operations. This hands-on role focuses on building Python-based automation, integrating security platforms, and developing workflows that transform threat intelligence into actionable security operations. The ideal candidate will collaborate with cross-functional cybersecurity teams to improve operational efficiency through automation and scalable security solutions.
Key Responsibilities
• Develop Python-based automation to support threat intelligence operations.
• Build integrations between Threat Intelligence Platforms (TIP), SOAR, SIEM, EDR, cloud platforms, and other security tools using REST APIs and webhooks.
• Automate the collection, enrichment, validation, and distribution of threat intelligence and Indicators of Compromise (IOCs).
• Develop data ingestion and transformation pipelines for structured and unstructured security data.
• Partner with Threat Intelligence, Incident Response, Threat Hunting, Detection Engineering, and Security Operations teams to improve security workflows through automation.
• Identify opportunities to eliminate manual processes and enhance platform capabilities.
• Develop scalable automation solutions to improve operational efficiency and security workflows.
• Support the integration of enterprise security technologies and data sources.
Required Qualifications
• 4+ years of experience in Cybersecurity, Security Engineering, Security Automation, DevSecOps, or Software Development.
• Strong Python development and automation experience.
• Experience building REST API integrations and working with webhooks.
• Experience with Threat Intelligence Platforms (TIPs) and threat intelligence concepts.
• Knowledge of STIX/TAXII standards.
• Experience integrating security technologies such as SIEM, SOAR, EDR, and cloud security platforms.
• Experience working with JSON, XML, and CSV data formats.
• Strong communication, analytical, and collaboration skills.
Preferred Qualifications
• Experience with vulnerability management automation.
• Experience with cloud platforms, including AWS, Azure, or Google Cloud Platform (GCP).
• Experience developing ETL or data ingestion pipelines.
• Experience with threat hunting and incident response.
• Experience with AI-enabled security solutions.
• Experience with security orchestration platforms and automation frameworks.