Skip to content
← Back to job listings

Security Engineer (Cyber Threat Intelligence)

Saronic · San Diego, United States

External listingfull-time9 days ago

About The Role

Join Saronic, an autonomous-maritime defense company, as a Security Engineer for Cyber Threat Intelligence. In this hands-on role, you will run a real intelligence program, track priority adversaries, operationalize intelligence into actions, and produce actionable intelligence for security leadership. You will work across various security functions and directly shape how we anticipate threats to our vessels, supply chain, people, and data.

  • Help own and evolve the Priority Intelligence Requirements and collection-management framework, translating leadership decisions into tasked collection and finished intelligence.
  • Track priority adversaries, including nation-state and advanced criminal actors, and maintain adversary and campaign profiles.
  • Operationalize indicators and TTPs into detections, hunts, and prioritized remediation, and build the pipelines and connectors that ingest, enrich, and correlate intel.
  • 4+ years in cyber threat intelligence, threat hunting, detection engineering, or intrusion analysis, or an equivalent combination of experience and demonstrated ability, with demonstrable tracking of sophisticated or state-sponsored adversaries that drove detection, hunting, or response
  • Hands-on infrastructure and log analysis (passive DNS, certificate pivoting, WHOIS/ASN) and detection authoring (Sigma, YARA, or SIEM-native)
  • Strong software engineering to build automation, connectors, and data pipelines end to end
  • Working command of MITRE ATT&CK, the Diamond Model, and the Cyber Kill Chain, plus STIX/TAXII for modeling and sharing intelligence
  • Ability to obtain and maintain a U.S. security clearance
  • Fluency with the intelligence lifecycle, Priority Intelligence Requirements and collection management, and structured analytic techniques, and the ability to produce finished intelligence with calibrated confidence
  • Nation-state/APT tracking relevant to the defense industrial base, maritime, or manufacturing industries
  • Standing up or operating an in-house or graph-based CTI platform, MISP, or a TAXII/STIX pipeline
  • Malware analysis and adversary attribution (provisional clustering; tactical, operational, and strategic attribution)
  • Cyber-deception design and operations (honeytokens, canaries, decoys)
  • Digital risk protection and dark-web tradecraft: breach-credential, executive-protection, and brand-impersonation monitoring and takedowns
  • Applying LLMs and AI tooling to accelerate collection, enrichment, and analysis, including agentic case automation
  • DoD/DIB context (CMMC/NIST 800-171, GovCloud, ITAR) and military intelligence doctrine
  • OT/ICS or maritime security knowledge
  • Public CTI research, talks, or open-source contributions
  • If your experience doesn’t line up with every preferred qualification, we still encourage you to apply; we hire for demonstrated ability and outcomes
  • Manual dexterity to operate a computer keyboard, mouse, and other office equipment
  • Visual acuity to read screens, documents, and reports
  • Lifting and carrying items up to 20 pounds occasionally (e.g., office supplies, packages)
  • Occasional reaching, bending, or stooping to access file drawers, cabinets, or office supplies

This is an external listing. JobSpring does not represent or verify the employer. Report this listing