- Robot type
- Marine and Space · Defense
- Location
- AustinTexasUSA
- Job type
- Software
- Posted
- Jul 23, 2026
Security Engineer, Cyber Threat Intelligence
Job description
Security at Saronic is a force multiplier, not a blocker. An autonomous-maritime defense company is a top-tier target for nation-state and advanced criminal actors, and we’re looking for a Security Engineer for Cyber Threat Intelligence to make sure we see them coming. This is a hands-on, doctrine-driven engineering role, not a reporting desk: you’ll run a real intelligence program and turn raw indicators into operational defenses.
You’ll work across Security Operations, Detection Engineering, Vulnerability Management, Physical Security, Insider Threat, Data Loss Prevention, and Red Team to focus on the adversaries targeting the defense industrial base.
Job responsibilities
- Priority Intelligence Requirements & Collection: Help own and evolve our Priority Intelligence Requirements and collection-management framework, translating leadership decisions and our maritime-autonomy and…
- Adversary Tracking: Track the priority adversaries, including nation-state, APT, and advanced criminal actors most likely to target defense, maritime, and the broader industrial base, along with their tooling,…
- Turn Intelligence into Action: Operationalize indicators and TTPs into detections, hunts, and prioritized remediation, and build the pipelines and connectors that ingest, enrich, and correlate intel from commercial…
- Fuse Internal & External: Fuse external intelligence with internal telemetry in our graph-based intelligence data store, running attack-path and identity-to-asset correlation to prioritize by real exposure rather than…
- Finished Intelligence: Produce concise, actionable intelligence and briefings for security leadership and cross-functional partners, applying analytic tradecraft, estimative language, calibrated confidence, and…
- Hunting & Detection: Develop and run intelligence-driven threat hunts across endpoint, cloud, identity, email, and network telemetry, and author durable detections (Sigma, YARA) with detection engineering and incident…
- Infrastructure & Malware Analysis: Perform infrastructure pivoting (passive DNS, certificate pivoting, WHOIS/ASN) and malware triage to extract indicators, TTPs, and attribution signals.
- Digital Risk & Identity Protection: Run deep and dark-web, breach-credential, and identity-exposure monitoring, including account-takeover, executive and VIP protection, and brand-impersonation, and coordinate…
Job requirements
- 4+ years in cyber threat intelligence, threat hunting, detection engineering, or intrusion analysis, or an equivalent combination of experience and demonstrated ability, with demonstrable tracking of sophisticated or…
- Fluency with the intelligence lifecycle, Priority Intelligence Requirements and collection management, and structured analytic techniques, and the ability to produce finished intelligence with calibrated confidence
- Strong software engineering to build automation, connectors, and data pipelines end to end
- Working command of MITRE ATT&CK, the Diamond Model, and the Cyber Kill Chain, plus STIX/TAXII for modeling and sharing intelligence
- Hands-on infrastructure and log analysis (passive DNS, certificate pivoting, WHOIS/ASN) and detection authoring (Sigma, YARA, or SIEM-native)
- Ability to obtain and maintain a U.S. security clearance
- Nation-state/APT tracking relevant to the defense industrial base, maritime, or manufacturing industries
- Standing up or operating an in-house or graph-based CTI platform, MISP, or a TAXII/STIX pipeline
Similar jobs
Saronic · Software
Software Engineer Intern (Summer 2027)
Austin, Texas
Saronic · Software
ServiceNow Developer
Austin, Texas
Saronic · Software
Senior Systems Software Engineer
Austin, Texas · San Diego, California
Saronic · Software
Security Engineer, Application Security
Austin, Texas · San Diego, California
