Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
FluidStack

Security Engineer, Threat Intelligence

FluidStack

Security Engineer focusing on threat intelligence to protect AI infrastructure. Building security systems and analyzing threats to ensure operational security across vast compute resources.

Posted 7/20/2026full-timeNew York City • New York • 🇺🇸 United StatesMid-LevelSenior💰 $220,000 - $300,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in threat intelligence analysis, including tracking nation-state and advanced criminal actors, and converting intelligence into actionable detections. Proficient in building automation and data pipelines, as well as authoring detection logic that withstands real adversary activity.

Highest-signal resume keywords
Threat Intelligence AnalysisProduction-Quality Python DevelopmentMalware and Infrastructure AnalysisDetection Logic Authoring (YARA, Sigma, SIEM)Intelligence Sharing and Collaboration

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Threat IntelligenceMalware AnalysisLog AnalysisDetection EngineeringData Pipeline DevelopmentAutomationTTP ExtractionIncident ResponseAdversary AttributionHunting Hypotheses
Soft Skills
CommunicationCollaborationAnalytical ThinkingDecision-Making
Tools & Technologies
YARASigmaSIEMCloud SecurityAI InfrastructureData Center SecurityOpen Source IntelligenceISACs
Industry Keywords
Nation-State ActorsAdvanced Criminal ActorsThreat ModelTelemetryOperational IntelligenceIncident ContextPeer RelationshipsActive Campaigns

Tech Stack

Tools & technologies
CloudOpen SourcePython

About the role

Key responsibilities & impact
  • Track the nation-state and advanced criminal actors most likely to target frontier AI infrastructure, and turn their tooling, infrastructure patterns, and tradecraft into intelligence that changes what the program detects and hunts for.
  • Build and run the pipelines that collect, enrich, and correlate indicators, then push them into the detection and agentic triage stack so intelligence becomes operational instantly.
  • Drive intelligence-led hunts across enterprise, cloud, identity, data center IT, and OT telemetry, and convert findings into high-fidelity detections authored as code.
  • Perform hands-on malware, phishing-infrastructure, and attacker-tooling analysis to extract indicators, TTPs, and attribution signals that feed detection engineering and incident response in near real time.
  • Curate the inbound intelligence pipeline across commercial feeds, open source, government, and peer relationships, and prioritize what actually matters for the program's threat model.
  • Build and maintain the external intelligence-sharing relationships (ISACs, peer AI and cloud security teams, government partners) that keep the program ahead of active campaigns.

Requirements

What you’ll need
  • You've tracked specific nation-state or advanced criminal actors as a core part of your job, and you know their tooling, infrastructure, and targeting well enough to anticipate their next move.
  • You write production-quality Python (or similar) and have built the automation and data pipelines your intelligence work depended on, end to end.
  • You've done hands-on malware, infrastructure, and log analysis to develop and validate your own findings.
  • You've authored quality detection logic (YARA, Sigma, or SIEM-native queries) that shipped to production and held up against real adversary activity.
  • You've worked shoulder to shoulder with detection engineers and incident responders, turning intelligence into detections, hunting hypotheses, and incident context while an event was still live.
  • You write intelligence that gets read and acted on, distilling a complex campaign into a decision and a next step for an engineer or an executive.
  • Bonus: An active network in the threat intelligence community and a habit of sharing in both directions. Experience defending large-scale GPU or AI compute infrastructure, data centers, or multi-tenant cloud environments. Applying LLMs or agentic tooling to accelerate collection, enrichment, and analysis. Public research, conference talks, or open-source contributions in the CTI space.

Benefits

Comp & perks
  • Competitive total compensation package (salary + equity).
  • Retirement or pension plan, in line with local norms.
  • Health, dental, and vision insurance.
  • Generous PTO policy, in line with local norms.