Senior Security Engineer, Threat Intelligence

1Password 1Password · Enterprise · United States, Canada · Remote · Technology

This role focuses on operationalizing cyber threat intelligence by building automation, integrating intelligence into security tooling, developing intelligence-driven hunting hypotheses, and applying AI/ML-assisted tools to accelerate analysis. The primary focus is on translating adversary research into actionable security improvements within identity and cloud environments.

What you'd actually do

  1. Track and analyze threat actors, campaigns, and techniques targeting identity and cloud environments
  2. Translate intelligence into actionable detections, hunting hypotheses, and adversary simulations
  3. Partner with Detection Engineering, Incident Response, and other security teams to drive security decisions
  4. Produce clear technical assessments and executive-ready insights to inform risk prioritization
  5. Build and maintain automated pipelines to ingest, enrich, and distribute threat intelligence

Skills

Required

  • 5+ years of experience in cyber threat intelligence
  • 3+ years focused on security engineering and automation
  • Strong understanding of modern attacker techniques, particularly in identity, credential abuse, cloud exploitation, and AI-assisted attack scenarios
  • Experience integrating threat intelligence platforms and building automation around intelligence ingestion and enrichment
  • Proficiency in scripting or programming (e.g., Python, Go) and working with APIs and data pipelines
  • Experience applying AI/ML-assisted tools to enhance intelligence analysis or signal prioritization
  • Willingness to participate in an on-call rotation

Nice to have

  • Comfortable writing code, working with APIs, and integrating security platforms
  • Analytical and hypothesis-driven, with strong judgment in assessing threat credibility and relevance
  • A strong collaborator who can translate intelligence into practical security improvements
  • Able to clearly communicate complex ideas to technical and non-technical audiences

What the JD emphasized

  • operationalizing intelligence
  • build automation
  • integrate intelligence into security tooling
  • intelligence-driven hunting hypotheses
  • AI and intelligent tooling to accelerate analysis
  • AI-assisted attack scenarios

Other signals

  • operationalizing intelligence
  • build automation
  • integrate intelligence into security tooling
  • intelligence-driven hunting hypotheses
  • AI and intelligent tooling to accelerate analysis