Jobedly Post a Job

Threat Intelligence Engineer

Black Duck Software, Inc. · Belfast
Full-time1220 - Security (GQP)Technology$136,000–$184,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Threat Intelligence Engineer role

Threat Intelligence Engineer positions focus on delivering results in their domain. This page aggregates open Threat Intelligence Engineer roles and what employers typically expect.

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle. The Threat Intelligence Engineer supports the research, collection, and analysis of threat data that enables Black Duck to detect and respond to threats targeting the enterprise and its software supply chain. Working within the Threat Intelligence function under moderate supervision, you apply foundational knowledge of adversary tradecraft to assist in producing intelligence products, maintaining indicator pipelines, and contributing threat context to security workflows across the organization. This role solves moderately complex problems within defined guidelines and policies, collaborates with senior engineers on intelligence operations, and supports broader cybersecurity and security operations functions as capacity allows. Essential Functions/Responsibilities • Assist with collection, processing, and analysis tasks across the intelligence requirements-to-dissemination workflow. • Help maintain the intelligence requirements register under guidance from senior team members. • Draft threat actor profiles, campaign summaries, and indicator packages for technical audiences; refine products based on senior engineer feedback. • Ingest, validate, and score indicators of compromise (IOCs) from commercial feeds (e.g., Recorded Future), open-source, and internal sources. • Support integration of IOC pipelines with SIEM and EDR platforms, including Sumo Logic and CrowdStrike Falcon/NG SIEM. • Apply confidence scoring and structured formats (e.g., STIX 2.1) to intelligence artifacts; escalate data quality issues to senior team members. • Monitor open-source package registries (npm, PyPI, Go, Maven, and others) and CI/CD pipeline integrity signals for indicators of adversarial activity including typosquatting, dependency confusion, and build-pipeline compromise. • Contribute to the internal supply chain threat detection program by assisting with data collection, documentation, and detection logic testing. • Assist broader cybersecurity and security operations functions — including CSIRT, Vulnerability Management, and PSIRT — with alert triage, threat research, and DLP investigation enrichment, as capacity allows. • Support security investigations by researching threat actor behaviors, identifying relevant IOCs, and providing contextual summaries. • Prepare threat intelligence summaries and briefing materials for internal consumers including CSIRT and Vulnerability Management. • Identify opportunities for workflow improvements within own area and recommend changes to senior team members. • Learn and follow applicable standards for intelligence data handling, sharing agreements, and governance; contribute to supporting documentation as directed. • Other tasks and activities as assigned. Required Education/Experience & Skills • Typically at least two (2) years of experience in threat intelligence, security operations, threat hunting, or a closely related cybersecurity role; demonstrated ability to solve moderately complex problems within established guidelines. • Working familiarity with the intelligence production lifecycle, threat actor profiling concepts, and structured formats (e.g., STIX 2.1); ability to apply MITRE ATT&CK for basic TTP mapping. • Practical experience working within enterprise SIEM or EDR environments; ability to run queries, review alerts, and support detection validation (current platforms include Sumo Logic and CrowdStrike Falcon/NG SIEM). • Co…

Salary estimate

$136,000 – $184,000/yr
Provided by the employer.

Skills for this role

GOCi/CdSecurity

Resume tips for Threat Intelligence Engineer applicants

Interview preparation

Prepare concrete STAR-format stories that show Threat Intelligence Engineer outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Threat Intelligence Engineer problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About Black Duck Software, Inc.

Black Duck Software, Inc. is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles