Senior Threat and Attack Research Engineer

Anduril Anduril · Defense · CT · Remote · Corporate Technology : Information Security : Offensive Security

This role focuses on threat intelligence and cyber security within the defense technology sector, aiming to protect products and infrastructure by analyzing and mitigating sophisticated cyber threats. It involves developing and enhancing tooling for threat actor tracking and integrating intelligence data, with a strong emphasis on proactive collaboration and research into emerging technical trends in the threat landscape.

What you'd actually do

  1. Monitor and analyze sophisticated cyber threats targeting Anduril's products, infrastructure, and personnel.
  2. Research, mitigate, and anticipate emerging technical trends in the threat landscape.
  3. Collaborate closely with the detection and response team to provide timely and actionable intelligence to support ongoing investigations.
  4. Engage cross functionally with the offensive security team on product and infrastructure red team engagements.
  5. Enhance tooling for threat actor tracking and intelligence data integration.

Skills

Required

  • Python
  • Rust
  • Golang
  • Swift
  • analyzing complex threat actor campaigns
  • developing long term countermeasures
  • prioritize and execute tasks independently
  • Strong and professional communication skills (written and verbal)
  • Ability to obtain and hold a U.S. Secret security clearance

Nice to have

  • nation-state, sophisticated criminal, or supply chain threats
  • YARA
  • Snort
  • large scale data analysis
  • Established connection within the broader security and threat intel community
  • Strong analytical and problem-solving capabilities
  • Demonstrated ability to work effectively in team environments
  • Vertex Synapse

What the JD emphasized

  • Proven experience analyzing complex threat actor campaigns, including supply chain and infrastructure, with the ability to develop long term countermeasures.
  • Track record of writing production code for threat intelligence tools