SecurityScorecard

SecurityScorecard

11 open positions available

2 locations
1 employment type
Actively hiring
Full-time

Latest Positions

Showing 11 most recent jobs
SecurityScorecard

Senior Research Engineer, Threat Intelligence

SecurityScorecardAnywhereFull-time
View Job
Compensation$143K - 193K a year

Lead engineering delivery of threat intelligence research outputs into production-ready artifacts and platforms. | 5-8 years engineering experience with threat intelligence, production systems, Python, TypeScript, cloud infrastructure, and knowledge of threat intel standards and tooling. | About SecurityScorecard: SecurityScorecard is the global leader in cybersecurity ratings, with over 12 million companies continuously rated, operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and funded by world-class investors, SecurityScorecard’s patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their digital footprint. Headquartered in New York City, our culture has been recognized by Inc Magazine as a "Best Workplace,” by Crain’s NY as a "Best Places to Work in NYC," and as one of the 10 hottest SaaS startups in New York for two years in a row. Most recently, SecurityScorecard was named to Fast Company’s annual list of the World’s Most Innovative Companies for 2023 and to the Achievers 50 Most Engaged Workplaces in 2023 award recognizing “forward-thinking employers for their unwavering commitment to employee engagement.” SecurityScorecard is proud to be funded by world-class investors including Silver Lake Waterman, Moody’s, Sequoia Capital, GV and Riverwood Capital. About the Role: You'll join STRIKE, SecurityScorecard's Threat Intelligence team, as the engineering counterpart to research. STRIKE runs several research motions in parallel, each on its own clock: rapid response to active events, longer product-tied work, and standards-anchored research on a quarterly cadence. The path from a finding to a shipped detection or feed gets reinvented every time. That's the problem this role is here to solve. You'll work directly with the senior technical leader who owns STRIKE's R&D direction, and report to the Head of Threat Research for people management. Technical direction comes from R&D leadership; you own delivery. You'll take a research artifact (a malware finding, an infrastructure cluster, a new indicator class, a behavioral pattern) and turn it into something the company can use without a second round of engineering: schemas, pipeline hooks, distribution feeds, detection rules, or platform APIs. This isn't a pure research role, and it isn't a pure platform role either. Researchers ideate, you ship. Key Responsibilities: Research-to-Production Pipeline • Own the path from research output to production-ready artifact: a detection rule, a distributed feed, a scoring input, or a customer alert. Partner with adjacent teams to define clean handoff contracts, so new signals arrive downstream with the schema, value framing, and consumption pattern already defined. Threat Intelligence Platform Engineering • Build and maintain STRIKE platform components across multiple services and runtimes, including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines that operate over standards-anchored predicates. Extend these systems without breaking the data contracts already in production. Detection Content and Signal Production • Turn research into shipped detection content: YARA, Sigma, STIX patterns, behavioral indicators, and the pipelines that distribute them. Build correlation pipelines that link scan data, attack surface signals, vulnerability data, and adversary tracking into customer-facing intelligence. Data Model and Standards Adoption • Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard. Define and govern schemas that hold up once they reach downstream teams. Research Workflow Engineering • Build the automation that removes commodity overhead from research work: indicator enrichment, report drafting, corpus correlation, feed normalization, and sandbox triage. Help move the team from analyst-driven, model-assisted workflows toward model-driven workflows with analyst review. • The work that matters most here is often the unglamorous part: retrieval grounded in the team's own corpus so outputs cite sources rather than model priors, schema-constrained output so a generated indicator is a valid one, and eval harnesses that catch regressions before analysts do. Cost accounting, latency budgeting, prompt versioning, and output logging round out the infrastructure that makes a workflow safe to run unattended. • You should have a clear sense of when a model is the wrong tool. A regex beats a model for known patterns; a SQL query beats a model for structured data. Knowing where that line sits, and respecting it, is part of the job. Cross-Functional Delivery • Coordinate with engineering, measurement, and platform product teams so research actually lands in product. You'll often serve as the engineering voice translating between researchers, product managers, and platform engineers, and you may occasionally explain the work to customers, journalists, or executives. Qualifications Education: Bachelor's or Master's in Computer Science, Cybersecurity, or a related technical field. Self-taught practitioners with strong public work are welcome. Experience: 5 to 8 years in a hands-on engineering role with meaningful exposure to threat intelligence, security research, or detection engineering. Prior experience building production systems that consume or emit threat intel data is required. Technical Skills: • Python and TypeScript/Node at a production level • Relational and cache data stores, plus at least one streaming or batch data platform • Cloud infrastructure (AWS preferred), containers, and CI/CD pipelines • Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK, and how they work together in practice Detection and Research Tooling: Hands-on experience with YARA, Sigma, and STIX Patterning. Comfortable reading malware analysis output, parsing adversary infrastructure data, and writing detection logic that holds up under production load. Applied Language Models: You've shipped production systems that use language models, not just demos. That includes retrieval over a real corpus, structured output with schema validation, eval harnesses that catch regressions before users do, and a solid understanding of where models fail: recency, long-tail facts, numerical reasoning, and adversarial input or prompt injection. You can do the cost-per-task math for your workloads, and you can make the case when a smaller, tightly scaffolded model beats a larger one. You approach model output with healthy skepticism by default. The bar for shipping a model-generated indicator or detection is higher than for shipping a regex, and you understand why and design accordingly. Bridge Mindset: You write code that ships, and you understand why researchers think the way they do. If you've only ever worked from a backlog handed down by a product manager, this probably isn't the right fit. If you've taken an idea sketched out in a chat message and turned it into a deployed pipeline before the next sprint began, that's the mode we're looking for. Bonus: • Experience with policy-as-code or expression-language engines (CEL, OPA, or similar) • Published or co-authored security research (campaigns, vulnerabilities, adversary tracking) • Large-scale telemetry experience (Splunk, Kinesis, NetFlow, or equivalent) • Contributor or maintainer on open-source threat intel projects (MISP, OpenCTI, Sigma, STIX, ATT&CK) • Familiarity with quantitative risk frameworks such as FAIR • Familiarity with Golang at a production level Benefits: Specific to each country, we offer a competitive salary, stock options, Health benefits, and unlimited PTO, parental leave, tuition reimbursements, and much more! The estimated total compensation range for this position is $142,500 - $192,500 (base plus bonus). Actual compensation for the position is based on a variety of factors, including, but not limited to affordability, skills, qualifications and experience, and may vary from the range. In addition to base salary, employees may also be eligible for annual performance-based incentive compensation awards and equity, among other company benefits. SecurityScorecard is committed to Equal Employment Opportunity and embraces diversity. We believe that our team is strengthened through hiring and retaining employees with diverse backgrounds, skill sets, ideas, and perspectives. We make hiring decisions based on merit and do not discriminate based on race, color, religion, national origin, sex or gender (including pregnancy) gender identity or expression (including transgender status), sexual orientation, age, marital, veteran, disability status or any other protected category in accordance with applicable law. We also consider qualified applicants regardless of criminal histories, in accordance with applicable law. We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need assistance or accommodation due to a disability, please contact talentacquisitionoperations@securityscorecard.io. Any information you submit to SecurityScorecard as part of your application will be processed in accordance with the Company’s privacy policy and applicable law. SecurityScorecard does not accept unsolicited resumes from employment agencies. Please note that we do not provide immigration sponsorship for this position.

Cybersecurity Leadership
Governance Risk Compliance
Security Program Management
Verified Source
Posted 17 days ago
SecurityScorecard

Senior Research Engineer, Threat Intelligence

SecurityScorecardAnywhereFull-time
View Job
Compensation$143K - 193K a year

Lead the engineering delivery of threat intelligence research outputs into production-ready artifacts and platform components. | Requires 5-8 years engineering experience with threat intelligence, proficiency in Python and TypeScript, knowledge of threat intel standards, and experience shipping production detection systems. | About SecurityScorecard: SecurityScorecard is the global leader in cybersecurity ratings, with over 12 million companies continuously rated, operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and funded by world-class investors, SecurityScorecard’s patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their digital footprint. Headquartered in New York City, our culture has been recognized by Inc Magazine as a "Best Workplace,” by Crain’s NY as a "Best Places to Work in NYC," and as one of the 10 hottest SaaS startups in New York for two years in a row. Most recently, SecurityScorecard was named to Fast Company’s annual list of the World’s Most Innovative Companies for 2023 and to the Achievers 50 Most Engaged Workplaces in 2023 award recognizing “forward-thinking employers for their unwavering commitment to employee engagement.” SecurityScorecard is proud to be funded by world-class investors including Silver Lake Waterman, Moody’s, Sequoia Capital, GV and Riverwood Capital. About the Role: You'll join STRIKE, SecurityScorecard's Threat Intelligence team, as the engineering counterpart to research. STRIKE runs several research motions in parallel, each on its own clock: rapid response to active events, longer product-tied work, and standards-anchored research on a quarterly cadence. The path from a finding to a shipped detection or feed gets reinvented every time. That's the problem this role is here to solve. You'll work directly with the senior technical leader who owns STRIKE's R&D direction, and report to the Head of Threat Research for people management. Technical direction comes from R&D leadership; you own delivery. You'll take a research artifact (a malware finding, an infrastructure cluster, a new indicator class, a behavioral pattern) and turn it into something the company can use without a second round of engineering: schemas, pipeline hooks, distribution feeds, detection rules, or platform APIs. This isn't a pure research role, and it isn't a pure platform role either. Researchers ideate, you ship. Key Responsibilities: Research-to-Production Pipeline • Own the path from research output to production-ready artifact: a detection rule, a distributed feed, a scoring input, or a customer alert. Partner with adjacent teams to define clean handoff contracts, so new signals arrive downstream with the schema, value framing, and consumption pattern already defined. Threat Intelligence Platform Engineering • Build and maintain STRIKE platform components across multiple services and runtimes, including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines that operate over standards-anchored predicates. Extend these systems without breaking the data contracts already in production. Detection Content and Signal Production • Turn research into shipped detection content: YARA, Sigma, STIX patterns, behavioral indicators, and the pipelines that distribute them. Build correlation pipelines that link scan data, attack surface signals, vulnerability data, and adversary tracking into customer-facing intelligence. Data Model and Standards Adoption • Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard. Define and govern schemas that hold up once they reach downstream teams. Research Workflow Engineering • Build the automation that removes commodity overhead from research work: indicator enrichment, report drafting, corpus correlation, feed normalization, and sandbox triage. Help move the team from analyst-driven, model-assisted workflows toward model-driven workflows with analyst review. • The work that matters most here is often the unglamorous part: retrieval grounded in the team's own corpus so outputs cite sources rather than model priors, schema-constrained output so a generated indicator is a valid one, and eval harnesses that catch regressions before analysts do. Cost accounting, latency budgeting, prompt versioning, and output logging round out the infrastructure that makes a workflow safe to run unattended. • You should have a clear sense of when a model is the wrong tool. A regex beats a model for known patterns; a SQL query beats a model for structured data. Knowing where that line sits, and respecting it, is part of the job. Cross-Functional Delivery • Coordinate with engineering, measurement, and platform product teams so research actually lands in product. You'll often serve as the engineering voice translating between researchers, product managers, and platform engineers, and you may occasionally explain the work to customers, journalists, or executives. Qualifications Education: Bachelor's or Master's in Computer Science, Cybersecurity, or a related technical field. Self-taught practitioners with strong public work are welcome. Experience: 5 to 8 years in a hands-on engineering role with meaningful exposure to threat intelligence, security research, or detection engineering. Prior experience building production systems that consume or emit threat intel data is required. Technical Skills: • Python and TypeScript/Node at a production level • Relational and cache data stores, plus at least one streaming or batch data platform • Cloud infrastructure (AWS preferred), containers, and CI/CD pipelines • Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK, and how they work together in practice Detection and Research Tooling: Hands-on experience with YARA, Sigma, and STIX Patterning. Comfortable reading malware analysis output, parsing adversary infrastructure data, and writing detection logic that holds up under production load. Applied Language Models: You've shipped production systems that use language models, not just demos. That includes retrieval over a real corpus, structured output with schema validation, eval harnesses that catch regressions before users do, and a solid understanding of where models fail: recency, long-tail facts, numerical reasoning, and adversarial input or prompt injection. You can do the cost-per-task math for your workloads, and you can make the case when a smaller, tightly scaffolded model beats a larger one. You approach model output with healthy skepticism by default. The bar for shipping a model-generated indicator or detection is higher than for shipping a regex, and you understand why and design accordingly. Bridge Mindset: You write code that ships, and you understand why researchers think the way they do. If you've only ever worked from a backlog handed down by a product manager, this probably isn't the right fit. If you've taken an idea sketched out in a chat message and turned it into a deployed pipeline before the next sprint began, that's the mode we're looking for. Bonus: • Experience with policy-as-code or expression-language engines (CEL, OPA, or similar) • Published or co-authored security research (campaigns, vulnerabilities, adversary tracking) • Large-scale telemetry experience (Splunk, Kinesis, NetFlow, or equivalent) • Contributor or maintainer on open-source threat intel projects (MISP, OpenCTI, Sigma, STIX, ATT&CK) • Familiarity with quantitative risk frameworks such as FAIR • Familiarity with Golang at a production level Benefits: Specific to each country, we offer a competitive salary, stock options, Health benefits, and unlimited PTO, parental leave, tuition reimbursements, and much more! The estimated total compensation range for this position is $142,500 - $192,500 (base plus bonus). Actual compensation for the position is based on a variety of factors, including, but not limited to affordability, skills, qualifications and experience, and may vary from the range. In addition to base salary, employees may also be eligible for annual performance-based incentive compensation awards and equity, among other company benefits. SecurityScorecard is committed to Equal Employment Opportunity and embraces diversity. We believe that our team is strengthened through hiring and retaining employees with diverse backgrounds, skill sets, ideas, and perspectives. We make hiring decisions based on merit and do not discriminate based on race, color, religion, national origin, sex or gender (including pregnancy) gender identity or expression (including transgender status), sexual orientation, age, marital, veteran, disability status or any other protected category in accordance with applicable law. We also consider qualified applicants regardless of criminal histories, in accordance with applicable law. We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need assistance or accommodation due to a disability, please contact talentacquisitionoperations@securityscorecard.io. Any information you submit to SecurityScorecard as part of your application will be processed in accordance with the Company’s privacy policy and applicable law. SecurityScorecard does not accept unsolicited resumes from employment agencies. Please note that we do not provide immigration sponsorship for this position.

Cybersecurity Leadership
Governance Risk Compliance
Security Program Management
Verified Source
Posted 17 days ago
SecurityScorecard

Threat Intelligence Researcher

SecurityScorecardAnywhereFull-time
View Job
Compensation$100K - 120K a year

Track and analyze threat actors, produce intelligence reports, and communicate findings to various stakeholders. | 3-5 years hands-on threat intelligence research experience, proficiency in data querying tools, and strong communication skills. | About SecurityScorecard: SecurityScorecard is the global leader in cybersecurity ratings, with over 12 million companies continuously rated, operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and funded by world-class investors, SecurityScorecard’s patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their digital footprint. Headquartered in New York City, our culture has been recognized by Inc Magazine as a "Best Workplace,” by Crain’s NY as a "Best Places to Work in NYC," and as one of the 10 hottest SaaS startups in New York for two years in a row. Most recently, SecurityScorecard was named to Fast Company’s annual list of the World’s Most Innovative Companies for 2023 and to the Achievers 50 Most Engaged Workplaces in 2023 award recognizing “forward-thinking employers for their unwavering commitment to employee engagement.” SecurityScorecard is proud to be funded by world-class investors including Silver Lake Waterman, Moody’s, Sequoia Capital, GV and Riverwood Capital. About the Role: You'll be joining SecurityScorecard's threat research team as its intelligence-focused practitioner, working alongside deep technical researchers to produce timely, actionable intelligence for customers, partners, and internal stakeholders. Where the Threat Researcher role is anchored in technical analysis, this role sits at the intersection of research and communication — you'll be tracking threat actors and their infrastructure, producing intelligence reports, and translating complex findings into clear, credible content for a range of audiences. Marketing is currently one of the team's primary stakeholders, and you'll work closely with them on research-driven content and campaigns — but the team's ambition is to become a resource for every division in the company, and you'll be part of building that reputation. Customer briefings, coordinated threat actor takedowns, and participation in industry events are all part of the mandate. Strong written and spoken English is essential, as is the ability to represent the team's work credibly in external settings. This is a role for someone who combines analytical depth with the communication skills to make that work land. Key Responsibilities: • Deep Technical Research and Tracking: Identify, track, and analyze advanced persistent threats (APTs), their TTPs, and their live infrastructure to gain insights into attack vectors, victimology, and attack scale. • Intelligence Briefing and Reporting: Produce timely and actionable intelligence reports for customers, press, and partners. Participate in customer briefings, incident mitigation, and coordinated threat actor (TA) takedowns. • Detection Engineering: Develop and maintain high-fidelity detection signatures (YARA, Snort, Sigma) to protect customers. • Hunting and Monitoring: Query massive datasets (using SQL, Python, or Splunk) to identify anomalies and map out adversary infrastructure. Build workbooks, dashboards, and develop methodologies to improve detections. • AI and LLM Automation: Design and leverage AI and LLM automations to support your analysis workload. Qualifications: • Education: Bachelor's or Master's in Computer Science, Cybersecurity, or a highly technical equivalent. • Experience: 3–5 years in a hands-on threat intelligence research role within a prominent industry organization, military, law enforcement, or government. • Knowledge: Familiarity with prominent threat actors, APTs, emerging threat vectors, and the wider threat landscape. • Technical Skills: Proficiency with large dataset querying and dashboard design using Splunk, SQL, or similar platforms. • Mindset: A hacker's curiosity — the ability to look at a data point and see the hidden pattern. • Bonus: Experience with open source and commercial attack surface, malware analysis, and network intelligence tools and platforms. • Additional Bonus: Native-level reading and writing proficiency in Russian, Mandarin, Korean, or Farsi. Benefits: Specific to each country, we offer a competitive salary, stock options, Health benefits, and unlimited PTO, parental leave, tuition reimbursements, and much more! The estimated total compensation range for this position is $100,000 - $120,000 (base plus bonus). Actual compensation for the position is based on a variety of factors, including, but not limited to affordability, skills, qualifications and experience, and may vary from the range. In addition to base salary, employees may also be eligible for annual performance-based incentive compensation awards and equity, among other company benefits. SecurityScorecard is committed to Equal Employment Opportunity and embraces diversity. We believe that our team is strengthened through hiring and retaining employees with diverse backgrounds, skill sets, ideas, and perspectives. We make hiring decisions based on merit and do not discriminate based on race, color, religion, national origin, sex or gender (including pregnancy) gender identity or expression (including transgender status), sexual orientation, age, marital, veteran, disability status or any other protected category in accordance with applicable law. We also consider qualified applicants regardless of criminal histories, in accordance with applicable law. We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need assistance or accommodation due to a disability, please contact talentacquisitionoperations@securityscorecard.io. Any information you submit to SecurityScorecard as part of your application will be processed in accordance with the Company’s privacy policy and applicable law. SecurityScorecard does not accept unsolicited resumes from employment agencies. Please note that we do not provide immigration sponsorship for this position.

Threat Intelligence
Cybersecurity Compliance
Security Program Management
Verified Source
Posted 17 days ago
SecurityScorecard

Senior Research Engineer, Threat Intelligence

SecurityScorecardAnywhereFull-time
View Job
Compensation$140K - 150K a year

Translate threat research findings into production-ready detection content and platform components. | Requires 5-8 years engineering experience with threat intelligence, production coding in Python/TypeScript, and knowledge of STIX/TAXII standards. | About the Role: You'll join STRIKE, SecurityScorecard's Threat Intelligence team, as the engineering counterpart to research. STRIKE runs several research motions in parallel, each on its own clock: rapid response to active events, longer product-tied work, and standards-anchored research on a quarterly cadence. The path from a finding to a shipped detection or feed gets reinvented every time. That's the problem this role is here to solve. You'll work directly with the senior technical leader who owns STRIKE's R&D direction, and report to the Head of Threat Research for people management. Technical direction comes from R&D leadership; you own delivery. You'll take a research artifact (a malware finding, an infrastructure cluster, a new indicator class, a behavioral pattern) and turn it into something the company can use without a second round of engineering: schemas, pipeline hooks, distribution feeds, detection rules, or platform APIs. This isn't a pure research role, and it isn't a pure platform role either. Researchers ideate, you ship. Key Responsibilities: Research-to-Production Pipeline • Own the path from research output to production-ready artifact: a detection rule, a distributed feed, a scoring input, or a customer alert. Partner with adjacent teams to define clean handoff contracts, so new signals arrive downstream with the schema, value framing, and consumption pattern already defined. Threat Intelligence Platform Engineering • Build and maintain STRIKE platform components across multiple services and runtimes, including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines that operate over standards-anchored predicates. Extend these systems without breaking the data contracts already in production. Detection Content and Signal Production • Turn research into shipped detection content: YARA, Sigma, STIX patterns, behavioral indicators, and the pipelines that distribute them. Build correlation pipelines that link scan data, attack surface signals, vulnerability data, and adversary tracking into customer-facing intelligence. Data Model and Standards Adoption • Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard. Define and govern schemas that hold up once they reach downstream teams. Research Workflow Engineering • Build the automation that removes commodity overhead from research work: indicator enrichment, report drafting, corpus correlation, feed normalization, and sandbox triage. Help move the team from analyst-driven, model-assisted workflows toward model-driven workflows with analyst review. • The work that matters most here is often the unglamorous part: retrieval grounded in the team's own corpus so outputs cite sources rather than model priors, schema-constrained output so a generated indicator is a valid one, and eval harnesses that catch regressions before analysts do. Cost accounting, latency budgeting, prompt versioning, and output logging round out the infrastructure that makes a workflow safe to run unattended. • You should have a clear sense of when a model is the wrong tool. A regex beats a model for known patterns; a SQL query beats a model for structured data. Knowing where that line sits, and respecting it, is part of the job. Cross-Functional Delivery • Coordinate with engineering, measurement, and platform product teams so research actually lands in product. You'll often serve as the engineering voice translating between researchers, product managers, and platform engineers, and you may occasionally explain the work to customers, journalists, or executives. Qualifications Education: Bachelor's or Master's in Computer Science, Cybersecurity, or a related technical field. Self-taught practitioners with strong public work are welcome. Experience: 5 to 8 years in a hands-on engineering role with meaningful exposure to threat intelligence, security research, or detection engineering. Prior experience building production systems that consume or emit threat intel data is required. Technical Skills: • Python and TypeScript/Node at a production level • Relational and cache data stores, plus at least one streaming or batch data platform • Cloud infrastructure (AWS preferred), containers, and CI/CD pipelines • Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK, and how they work together in practice Detection and Research Tooling: Hands-on experience with YARA, Sigma, and STIX Patterning. Comfortable reading malware analysis output, parsing adversary infrastructure data, and writing detection logic that holds up under production load. Applied Language Models: You've shipped production systems that use language models, not just demos. That includes retrieval over a real corpus, structured output with schema validation, eval harnesses that catch regressions before users do, and a solid understanding of where models fail: recency, long-tail facts, numerical reasoning, and adversarial input or prompt injection. You can do the cost-per-task math for your workloads, and you can make the case when a smaller, tightly scaffolded model beats a larger one. You approach model output with healthy skepticism by default. The bar for shipping a model-generated indicator or detection is higher than for shipping a regex, and you understand why and design accordingly. Bridge Mindset: You write code that ships, and you understand why researchers think the way they do. If you've only ever worked from a backlog handed down by a product manager, this probably isn't the right fit. If you've taken an idea sketched out in a chat message and turned it into a deployed pipeline before the next sprint began, that's the mode we're looking for. Bonus: • Experience with policy-as-code or expression-language engines (CEL, OPA, or similar) • Published or co-authored security research (campaigns, vulnerabilities, adversary tracking) • Large-scale telemetry experience (Splunk, Kinesis, NetFlow, or equivalent) • Contributor or maintainer on open-source threat intel projects (MISP, OpenCTI, Sigma, STIX, ATT&CK) • Familiarity with quantitative risk frameworks such as FAIR • Familiarity with Golang at a production level Benefits: Specific to each country, we offer a competitive salary, stock options, Health benefits, and unlimited PTO, parental leave, tuition reimbursements, and much more! The estimated total compensation range for this position is $140,00 - $150,000 (base plus bonus). Actual compensation for the position is based on a variety of factors, including, but not limited to affordability, skills, qualifications and experience, and may vary from the range. In addition to base salary, employees may also be eligible for annual performance-based incentive compensation awards and equity, among other company benefits.

detection engineering
threat intelligence
SOAR automation
MITRE ATT&CK
Python
SIEM
digital forensics
Verified Source
Posted about 1 month ago
SecurityScorecard

Senior Research Engineer, Threat Intelligence

SecurityScorecardAnywhereFull-time
View Job
Compensation$85K - 120K a year

Convert threat research into scalable detection systems and automate workflows using LLMs and data pipelines. | 5-8 years in threat intelligence or security research with Python and TypeScript proficiency and experience shipping production LLM systems. | About SecurityScorecard: SecurityScorecard is the global leader in cybersecurity ratings, with over 12 million companies continuously rated, operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and funded by world-class investors, SecurityScorecard’s patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their digital footprint. Headquartered in New York City, our culture has been recognized by Inc Magazine as a "Best Workplace,” by Crain’s NY as a "Best Places to Work in NYC," and as one of the 10 hottest SaaS startups in New York for two years in a row. Most recently, SecurityScorecard was named to Fast Company’s annual list of the World’s Most Innovative Companies for 2023 and to the Achievers 50 Most Engaged Workplaces in 2023 award recognizing “forward-thinking employers for their unwavering commitment to employee engagement.” SecurityScorecard is proud to be funded by world-class investors including Silver Lake Waterman, Moody’s, Sequoia Capital, GV and Riverwood Capital. About the Role: You'll join STRIKE, SecurityScorecard's Threat Intelligence team, as the engineering counterpart to research. STRIKE runs several research motions in parallel, each on its own clock: rapid response to active events, longer product-tied work, and standards-anchored research on a quarterly cadence. The path from a finding to a shipped detection or feed gets reinvented every time. That's the problem this role is here to solve. You'll work directly with the senior technical leader who owns STRIKE's R&D direction, and report to the Head of Threat Research for people management. Technical direction comes from R&D leadership; you own delivery. You'll take a research artifact (a malware finding, an infrastructure cluster, a new indicator class, a behavioral pattern) and turn it into something the company can use without a second round of engineering: schemas, pipeline hooks, distribution feeds, detection rules, or platform APIs. This isn't a pure research role, and it isn't a pure platform role either. Researchers ideate, you ship. Key Responsibilities: Research-to-Production Pipeline Own the path from research output to production-ready artifact: a detection rule, a distributed feed, a scoring input, or a customer alert. Partner with adjacent teams to define clean handoff contracts, so new signals arrive downstream with the schema, value framing, and consumption pattern already defined. Threat Intelligence Platform Engineering Build and maintain STRIKE platform components across multiple services and runtimes, including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines that operate over standards-anchored predicates. Extend these systems without breaking the data contracts already in production. Detection Content and Signal Production Turn research into shipped detection content: YARA, Sigma, STIX patterns, behavioral indicators, and the pipelines that distribute them. Build correlation pipelines that link scan data, attack surface signals, vulnerability data, and adversary tracking into customer-facing intelligence. Data Model and Standards Adoption Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard. Define and govern schemas that hold up once they reach downstream teams. Research Workflow Engineering Build the automation that removes commodity overhead from research work: indicator enrichment, report drafting, corpus correlation, feed normalization, and sandbox triage. Help move the team from analyst-driven, model-assisted workflows toward model-driven workflows with analyst review. The work that matters most here is often the unglamorous part: retrieval grounded in the team's own corpus so outputs cite sources rather than model priors, schema-constrained output so a generated indicator is a valid one, and eval harnesses that catch regressions before analysts do. Cost accounting, latency budgeting, prompt versioning, and output logging round out the infrastructure that makes a workflow safe to run unattended. You should have a clear sense of when a model is the wrong tool. A regex beats a model for known patterns; a SQL query beats a model for structured data. Knowing where that line sits, and respecting it, is part of the job. Cross-Functional Delivery Coordinate with engineering, measurement, and platform product teams so research actually lands in product. You'll often serve as the engineering voice translating between researchers, product managers, and platform engineers, and you may occasionally explain the work to customers, journalists, or executives. Qualifications Education: Bachelor's or Master's in Computer Science, Cybersecurity, or a related technical field. Self-taught practitioners with strong public work are welcome. Experience: 5 to 8 years in a hands-on engineering role with meaningful exposure to threat intelligence, security research, or detection engineering. Prior experience building production systems that consume or emit threat intel data is required. Technical Skills: Python and TypeScript/Node at a production level Relational and cache data stores, plus at least one streaming or batch data platform Cloud infrastructure (AWS preferred), containers, and CI/CD pipelines Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK, and how they work together in practice Detection and Research Tooling: Hands-on experience with YARA, Sigma, and STIX Patterning. Comfortable reading malware analysis output, parsing adversary infrastructure data, and writing detection logic that holds up under production load. Applied Language Models: You've shipped production systems that use language models, not just demos. That includes retrieval over a real corpus, structured output with schema validation, eval harnesses that catch regressions before users do, and a solid understanding of where models fail: recency, long-tail facts, numerical reasoning, and adversarial input or prompt injection. You can do the cost-per-task math for your workloads, and you can make the case when a smaller, tightly scaffolded model beats a larger one. You approach model output with healthy skepticism by default. The bar for shipping a model-generated indicator or detection is higher than for shipping a regex, and you understand why and design accordingly. Bridge Mindset: You write code that ships, and you understand why researchers think the way they do. If you've only ever worked from a backlog handed down by a product manager, this probably isn't the right fit. If you've taken an idea sketched out in a chat message and turned it into a deployed pipeline before the next sprint began, that's the mode we're looking for. Bonus: Experience with policy-as-code or expression-language engines (CEL, OPA, or similar) Published or co-authored security research (campaigns, vulnerabilities, adversary tracking) Large-scale telemetry experience (Splunk, Kinesis, NetFlow, or equivalent) Contributor or maintainer on open-source threat intel projects (MISP, OpenCTI, Sigma, STIX, ATT&CK) Familiarity with quantitative risk frameworks such as FAIR Familiarity with Golang at a production level Benefits: Specific to each country, we offer a competitive salary, stock options, Health benefits, and unlimited PTO, parental leave, tuition reimbursements, and much more! The estimated total compensation range for this position is $140,00 - $150,000 (base plus bonus). Actual compensation for the position is based on a variety of factors, including, but not limited to affordability, skills, qualifications and experience, and may vary from the range. In addition to base salary, employees may also be eligible for annual performance-based incentive compensation awards and equity, among other company benefits. SecurityScorecard is committed to Equal Employment Opportunity and embraces diversity. We believe that our team is strengthened through hiring and retaining employees with diverse backgrounds, skill sets, ideas, and perspectives. We make hiring decisions based on merit and do not discriminate based on race, color, religion, national origin, sex or gender (including pregnancy) gender identity or expression (including transgender status), sexual orientation, age, marital, veteran, disability status or any other protected category in accordance with applicable law. We also consider qualified applicants regardless of criminal histories, in accordance with applicable law. We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need assistance or accommodation due to a disability, please contact talentacquisitionoperations@securityscorecard.io. Any information you submit to SecurityScorecard as part of your application will be processed in accordance with the Company’s privacy policy and applicable law. SecurityScorecard does not accept unsolicited resumes from employment agencies. Please note that we do not provide immigration sponsorship for this position. #LI-DNI

Python
TypeScript
Node.js
AWS
Large Language Models
Direct Apply
Posted about 1 month ago
SecurityScorecard

Senior Research Engineer, Threat Intelligence

SecurityScorecardAnywhereFull-time
View Job
Compensation$143K - 193K a year

Translate threat research into production-ready detection content and platform components, coordinating cross-functional delivery. | 5-8 years engineering experience in threat intelligence or detection engineering with strong Python/TypeScript skills, cloud infrastructure knowledge, and familiarity with STIX, TAXII, and MITRE ATT&CK. | About SecurityScorecard: SecurityScorecard is the global leader in cybersecurity ratings, with over 12 million companies continuously rated, operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and funded by world-class investors, SecurityScorecard’s patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their digital footprint. Headquartered in New York City, our culture has been recognized by Inc Magazine as a "Best Workplace,” by Crain’s NY as a "Best Places to Work in NYC," and as one of the 10 hottest SaaS startups in New York for two years in a row. Most recently, SecurityScorecard was named to Fast Company’s annual list of the World’s Most Innovative Companies for 2023 and to the Achievers 50 Most Engaged Workplaces in 2023 award recognizing “forward-thinking employers for their unwavering commitment to employee engagement.” SecurityScorecard is proud to be funded by world-class investors including Silver Lake Waterman, Moody’s, Sequoia Capital, GV and Riverwood Capital. About the Role: You'll join STRIKE, SecurityScorecard's Threat Intelligence team, as the engineering counterpart to research. STRIKE runs several research motions in parallel, each on its own clock: rapid response to active events, longer product-tied work, and standards-anchored research on a quarterly cadence. The path from a finding to a shipped detection or feed gets reinvented every time. That's the problem this role is here to solve. You'll work directly with the senior technical leader who owns STRIKE's R&D direction, and report to the Head of Threat Research for people management. Technical direction comes from R&D leadership; you own delivery. You'll take a research artifact (a malware finding, an infrastructure cluster, a new indicator class, a behavioral pattern) and turn it into something the company can use without a second round of engineering: schemas, pipeline hooks, distribution feeds, detection rules, or platform APIs. This isn't a pure research role, and it isn't a pure platform role either. Researchers ideate, you ship. Key Responsibilities: Research-to-Production Pipeline • Own the path from research output to production-ready artifact: a detection rule, a distributed feed, a scoring input, or a customer alert. Partner with adjacent teams to define clean handoff contracts, so new signals arrive downstream with the schema, value framing, and consumption pattern already defined. Threat Intelligence Platform Engineering • Build and maintain STRIKE platform components across multiple services and runtimes, including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines that operate over standards-anchored predicates. Extend these systems without breaking the data contracts already in production. Detection Content and Signal Production • Turn research into shipped detection content: YARA, Sigma, STIX patterns, behavioral indicators, and the pipelines that distribute them. Build correlation pipelines that link scan data, attack surface signals, vulnerability data, and adversary tracking into customer-facing intelligence. Data Model and Standards Adoption • Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard. Define and govern schemas that hold up once they reach downstream teams. Research Workflow Engineering • Build the automation that removes commodity overhead from research work: indicator enrichment, report drafting, corpus correlation, feed normalization, and sandbox triage. Help move the team from analyst-driven, model-assisted workflows toward model-driven workflows with analyst review. • The work that matters most here is often the unglamorous part: retrieval grounded in the team's own corpus so outputs cite sources rather than model priors, schema-constrained output so a generated indicator is a valid one, and eval harnesses that catch regressions before analysts do. Cost accounting, latency budgeting, prompt versioning, and output logging round out the infrastructure that makes a workflow safe to run unattended. • You should have a clear sense of when a model is the wrong tool. A regex beats a model for known patterns; a SQL query beats a model for structured data. Knowing where that line sits, and respecting it, is part of the job. Cross-Functional Delivery • Coordinate with engineering, measurement, and platform product teams so research actually lands in product. You'll often serve as the engineering voice translating between researchers, product managers, and platform engineers, and you may occasionally explain the work to customers, journalists, or executives. Qualifications Education: Bachelor's or Master's in Computer Science, Cybersecurity, or a related technical field. Self-taught practitioners with strong public work are welcome. Experience: 5 to 8 years in a hands-on engineering role with meaningful exposure to threat intelligence, security research, or detection engineering. Prior experience building production systems that consume or emit threat intel data is required. Technical Skills: • Python and TypeScript/Node at a production level • Relational and cache data stores, plus at least one streaming or batch data platform • Cloud infrastructure (AWS preferred), containers, and CI/CD pipelines • Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT&CK, and how they work together in practice Detection and Research Tooling: Hands-on experience with YARA, Sigma, and STIX Patterning. Comfortable reading malware analysis output, parsing adversary infrastructure data, and writing detection logic that holds up under production load. Applied Language Models: You've shipped production systems that use language models, not just demos. That includes retrieval over a real corpus, structured output with schema validation, eval harnesses that catch regressions before users do, and a solid understanding of where models fail: recency, long-tail facts, numerical reasoning, and adversarial input or prompt injection. You can do the cost-per-task math for your workloads, and you can make the case when a smaller, tightly scaffolded model beats a larger one. You approach model output with healthy skepticism by default. The bar for shipping a model-generated indicator or detection is higher than for shipping a regex, and you understand why and design accordingly. Bridge Mindset: You write code that ships, and you understand why researchers think the way they do. If you've only ever worked from a backlog handed down by a product manager, this probably isn't the right fit. If you've taken an idea sketched out in a chat message and turned it into a deployed pipeline before the next sprint began, that's the mode we're looking for. Bonus: • Experience with policy-as-code or expression-language engines (CEL, OPA, or similar) • Published or co-authored security research (campaigns, vulnerabilities, adversary tracking) • Large-scale telemetry experience (Splunk, Kinesis, NetFlow, or equivalent) • Contributor or maintainer on open-source threat intel projects (MISP, OpenCTI, Sigma, STIX, ATT&CK) • Familiarity with quantitative risk frameworks such as FAIR • Familiarity with Golang at a production level Benefits: Specific to each country, we offer a competitive salary, stock options, Health benefits, and unlimited PTO, parental leave, tuition reimbursements, and much more! The estimated total compensation range for this position is $142,500 - $192,500 (base plus bonus). Actual compensation for the position is based on a variety of factors, including, but not limited to affordability, skills, qualifications and experience, and may vary from the range. In addition to base salary, employees may also be eligible for annual performance-based incentive compensation awards and equity, among other company benefits. SecurityScorecard is committed to Equal Employment Opportunity and embraces diversity. We believe that our team is strengthened through hiring and retaining employees with diverse backgrounds, skill sets, ideas, and perspectives. We make hiring decisions based on merit and do not discriminate based on race, color, religion, national origin, sex or gender (including pregnancy) gender identity or expression (including transgender status), sexual orientation, age, marital, veteran, disability status or any other protected category in accordance with applicable law. We also consider qualified applicants regardless of criminal histories, in accordance with applicable law. We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need assistance or accommodation due to a disability, please contact talentacquisitionoperations@securityscorecard.io. Any information you submit to SecurityScorecard as part of your application will be processed in accordance with the Company’s privacy policy and applicable law. SecurityScorecard does not accept unsolicited resumes from employment agencies. Please note that we do not provide immigration sponsorship for this position.

Detection Engineering
Threat Intelligence
SOAR Automation
Incident Response
OT/ICS Security
Verified Source
Posted about 1 month ago
SE

Senior/Principal Product Manager, AI

SecurityScorecardNew York, New YorkFull-time
View Job
Compensation$120K - 160K a year

Lead product strategy and go-to-market planning for AI-powered wearable fitness and commerce products. | MBA with product management experience in AI and wearables, but less than 8 years in B2B SaaS AI product management and limited technical system design experience. | About SecurityScorecard: SecurityScorecard is the global leader in cybersecurity ratings, with over 12 million companies continuously rated, operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and funded by world-class investors, SecurityScorecard’s patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their digital footprint. Headquartered in New York City, our culture has been recognized by Inc Magazine as a "Best Workplace,” by Crain’s NY as a "Best Places to Work in NYC," and as one of the 10 hottest SaaS startups in New York for two years in a row. Most recently, SecurityScorecard was named to Fast Company’s annual list of the World’s Most Innovative Companies for 2023 and to the Achievers 50 Most Engaged Workplaces in 2023 award recognizing “forward-thinking employers for their unwavering commitment to employee engagement.” SecurityScorecard is proud to be funded by world-class investors including Silver Lake Waterman, Moody’s, Sequoia Capital, GV and Riverwood Capital. About The Role We are looking for a Principal Product Manager to own high-impact product initiatives across SecurityScorecard's platform, driving the strategy, execution, and continuous evolution of capabilities that deliver measurable value to our customers. This role sits at the intersection of product, engineering, data, and AI and is expected to operate with a high degree of autonomy, setting direction as much as following it. At SecurityScorecard we put our users first, strategically drive our decisions with data, and operate as a unit. We are customer obsessed and always seek to drive excellence, both in ourselves and others. As a Principal Product Manager at SecurityScorecard, you will work cross-functionally to guide products from conception to launch by connecting the security and business worlds. You can break down complex problems into steps that drive product development at both speed and scale. You understand that it is your job to align roadmap planning with key metrics and KPIs, and you critically focus on creating customer value based on data as well as a strong understanding of the user journey. At the principal level, you will also be expected to help elevate the PM practice, shaping how we think about product problems, and influencing beyond your immediate scope. You will be a leader in our mission to help the world instantly and non-intrusively measure, collaborate, and reduce the cyber-risk of any company in the world. Core Responsibilities Own the product vision, strategy, and roadmap for a major product area, driving alignment across engineering, design, data, and business stakeholders. Define, prioritize, and deliver customer-facing features and platform capabilities, balancing short-term execution with long-term strategic positioning. Lead the design and delivery of agentic AI workflows — including human-in-the-loop systems, autonomous task execution, and AI-assisted decision-making — that meaningfully reduce manual effort for customers and internal teams. Partner with AI engineering to define agent behavior, escalation logic, output quality standards, and evaluation frameworks; treat AI pipelines as products that require iteration, not one-time launches. Identify opportunities to embed intelligent automation into existing workflows, working backward from customer pain points to determine where agentic systems create the most leverage. Work directly with customers, customer-facing teams, and external partners to deeply understand problems, validate solutions, and shape joint outcomes. Collaborate with data, security, privacy, and legal teams to ensure product decisions comply with regulatory, contractual, and internal governance requirements. Define and track success metrics — adoption, reliability, quality, efficiency gains — and use those insights to guide prioritization and communicate progress to leadership. Operate as a product leader: influence without authority, drive clarity in ambiguous situations, and help other PMs on the team grow through pairing, feedback, and example. Create and maintain documentation, guidelines, and best practices that scale knowledge across product and engineering teams. Qualifications 8+ years of product management experience, with a track record of owning and shipping significant products or platforms in a B2B SaaS environment. Demonstrated experience defining and delivering AI-powered product features — including agentic workflows, LLM integration, or intelligent automation — with clear ownership over outcomes, not just requirements. Strong technical fluency: comfortable discussing system design, APIs, data models, AI pipelines, and product architecture with engineers and able to make informed tradeoff decisions. Proven ability to set direction, align stakeholders, and drive outcomes at a senior level without relying on direct authority. Data-driven decision maker with experience defining product metrics and using them to guide strategy and prioritization. Excellent communication skills, with the ability to clearly articulate complex technical and strategic concepts to both technical and non-technical audiences, including executive leadership. Experience working in or adjacent to cybersecurity, compliance, or risk management is preferred. Prior experience mentoring PMs or contributing to the growth of a product organization is a plus. Benefits: Specific to each country, we offer a competitive salary, stock options, Health benefits, and unlimited PTO, parental leave, tuition reimbursements, and much more! The estimated total compensation range for this position is $175,000 - $285,000 (base plus bonus). Actual compensation for the position is based on a variety of factors, including, but not limited to affordability, skills, qualifications and experience, and may vary from the range. In addition to base salary, employees may also be eligible for annual performance-based incentive compensation awards and equity, among other company benefits. SecurityScorecard is committed to Equal Employment Opportunity and embraces diversity. We believe that our team is strengthened through hiring and retaining employees with diverse backgrounds, skill sets, ideas, and perspectives. We make hiring decisions based on merit and do not discriminate based on race, color, religion, national origin, sex or gender (including pregnancy) gender identity or expression (including transgender status), sexual orientation, age, marital, veteran, disability status or any other protected category in accordance with applicable law. We also consider qualified applicants regardless of criminal histories, in accordance with applicable law. We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need assistance or accommodation due to a disability, please contact talentacquisitionoperations@securityscorecard.io. Any information you submit to SecurityScorecard as part of your application will be processed in accordance with the Company’s privacy policy and applicable law. SecurityScorecard does not accept unsolicited resumes from employment agencies. Please note that we do not provide immigration sponsorship for this position. #LI-DNI

Product Management
AI Strategy
Go-to-Market Planning
Direct Apply
Posted 2 months ago
SE

Senior Software Engineer

SecurityScorecardAnywhereFull-time
View Job
Compensation$85K - 130K a year

Lead design and evolution of platform systems and microservices, mentor engineers, and optimize infrastructure for reliability and scalability. | 5+ years experience with Node.js, TypeScript, AWS, distributed systems, containerization, and CI/CD tools. | About SecurityScorecard: SecurityScorecard is the global leader in cybersecurity ratings, with over 12 million companies continuously rated, operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and funded by world-class investors, SecurityScorecard’s patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their digital footprint. Headquartered in New York City, our culture has been recognized by Inc Magazine as a "Best Workplace,” by Crain’s NY as a "Best Places to Work in NYC," and as one of the 10 hottest SaaS startups in New York for two years in a row. Most recently, SecurityScorecard was named to Fast Company’s annual list of the World’s Most Innovative Companies for 2023 and to the Achievers 50 Most Engaged Workplaces in 2023 award recognizing “forward-thinking employers for their unwavering commitment to employee engagement.” SecurityScorecard is proud to be funded by world-class investors including Silver Lake Waterman, Moody’s, Sequoia Capital, GV and Riverwood Capital. About the Role: We are looking for an experienced Senior Engineer to join our Platform team — a strategic, hands-on technical leader who will own and evolve the foundational systems that power SecurityScorecard’s core products. You’ll work across the stack to build scalable services, optimize infrastructure, and improve internal tooling. Collaborating with engineers, product managers, and stakeholders, you will accelerate development velocity, improve reliability, and ensure our platform evolves with scale in mind. This role is both people- and technology-focused: you’ll mentor engineers while guiding complex technical initiatives around microservices architecture, distributed systems, infrastructure, and automation. What You'll Do: Technical Leadership: Architect, design, and build scalable platform components using Node.js, TypeScript, AWS, and React Build and maintain distributed systems, real-time pipelines, and core microservices to support platform growth Lead code and architecture reviews to uphold high standards for reliability, performance, and maintainability Contribute to and drive adoption of modern infrastructure practices — CI/CD, containerization (Docker), ArgoCD, Terraform, GitHub Actions Own and deliver impactful projects end-to-end, translating business needs and R&D insights into scalable technical solutions Identify opportunities to reduce toil, improve developer workflows, and increase system resiliency Build systems for the long term — balancing speed of delivery with sustainability and technical excellence Take part in production support responsibilities Required Skills & Experience: 5+ years of professional software engineering experience, with a strong focus on backend systems, platform services, or infrastructure Expertise in Node.js and modern development patterns (TypeScript/JavaScript) Solid experience designing and scaling distributed systems with strong focus on performance, scalability, and reliability Hands-on experience with cloud infrastructure (AWS preferred) and production-grade deployments Experience with CI/CD, monitoring, and containerization (Docker, Terraform, Jenkins, New Relic) Strong computer science fundamentals (algorithms, data structures, systems design, and networking) Excellent communication skills and successful collaboration with technical and non-technical stakeholders Passion for mentoring, knowledge-sharing, and helping teams grow Our Tech Stack: Programming Languages: Mainly TypeScript / JavaScript; subsystems may use other languages Cloud & Infrastructure: AWS, Docker, Terraform, Jenkins Production Monitoring: New Relic Databases: ClickHouse, PostgreSQL Nice to Have: Experience in cybersecurity, threat intelligence, or other security-focused platforms Familiarity with front-end development and full-stack delivery practices Experience building internal platforms, developer tools, or SDKs Background working with high-scale systems and large datasets Benefits: Specific to each country, we offer a competitive salary, stock options, Health benefits, and unlimited PTO, parental leave, tuition reimbursements, and much more! The estimated total compensation range for this position is $160,000 - $185,000 (base plus bonus). Actual compensation for the position is based on a variety of factors, including, but not limited to affordability, skills, qualifications and experience, and may vary from the range. In addition to base salary, employees may also be eligible for annual performance-based incentive compensation awards and equity, among other company benefits. SecurityScorecard is committed to Equal Employment Opportunity and embraces diversity. We believe that our team is strengthened through hiring and retaining employees with diverse backgrounds, skill sets, ideas, and perspectives. We make hiring decisions based on merit and do not discriminate based on race, color, religion, national origin, sex or gender (including pregnancy) gender identity or expression (including transgender status), sexual orientation, age, marital, veteran, disability status or any other protected category in accordance with applicable law. We also consider qualified applicants regardless of criminal histories, in accordance with applicable law. We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need assistance or accommodation due to a disability, please contact talentacquisitionoperations@securityscorecard.io. Any information you submit to SecurityScorecard as part of your application will be processed in accordance with the Company’s privacy policy and applicable law. SecurityScorecard does not accept unsolicited resumes from employment agencies. Please note that we do not provide immigration sponsorship for this position. #LI-DNI

TypeScript
Microservices Architecture
API Design
System Architecture
Mentorship
Direct Apply
Posted 2 months ago
SE

Senior Software Engineer

SecurityScorecardAnywhereFull-time
View Job
Compensation$90K - 140K a year

Architect and build scalable distributed systems using Node.js, TypeScript, and AWS while leading technical initiatives and mentoring engineers. | Requires 5+ years professional experience with Node.js, TypeScript, cloud infrastructure, and scaling distributed systems in production. | About SecurityScorecard: SecurityScorecard is the global leader in cybersecurity ratings, with over 12 million companies continuously rated, operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and funded by world-class investors, SecurityScorecard’s patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their digital footprint. Headquartered in New York City, our culture has been recognized by Inc Magazine as a "Best Workplace,” by Crain’s NY as a "Best Places to Work in NYC," and as one of the 10 hottest SaaS startups in New York for two years in a row. Most recently, SecurityScorecard was named to Fast Company’s annual list of the World’s Most Innovative Companies for 2023 and to the Achievers 50 Most Engaged Workplaces in 2023 award recognizing “forward-thinking employers for their unwavering commitment to employee engagement.” SecurityScorecard is proud to be funded by world-class investors including Silver Lake Waterman, Moody’s, Sequoia Capital, GV and Riverwood Capital. About the Role: We are looking for an experienced Senior Engineer to join our Platform team — a strategic, hands-on technical leader who will own and evolve the foundational systems that power SecurityScorecard’s core products. You’ll work across the stack to build scalable services, optimize infrastructure, and improve internal tooling. Collaborating with engineers, product managers, and stakeholders, you will accelerate development velocity, improve reliability, and ensure our platform evolves with scale in mind. This role is both people- and technology-focused: you’ll mentor engineers while guiding complex technical initiatives around microservices architecture, distributed systems, infrastructure, and automation. What You'll Do: Technical Leadership: Architect, design, and build scalable platform components using Node.js, TypeScript, AWS, and React Build and maintain distributed systems, real-time pipelines, and core microservices to support platform growth Lead code and architecture reviews to uphold high standards for reliability, performance, and maintainability Contribute to and drive adoption of modern infrastructure practices — CI/CD, containerization (Docker), ArgoCD, Terraform, GitHub Actions Own and deliver impactful projects end-to-end, translating business needs and R&D insights into scalable technical solutions Identify opportunities to reduce toil, improve developer workflows, and increase system resiliency Build systems for the long term — balancing speed of delivery with sustainability and technical excellence Take part in production support responsibilities Required Skills & Experience: 5+ years of professional software engineering experience, with a strong focus on backend systems, platform services, or infrastructure Expertise in Node.js and modern development patterns (TypeScript/JavaScript) Solid experience designing and scaling distributed systems with strong focus on performance, scalability, and reliability Hands-on experience with cloud infrastructure (AWS preferred) and production-grade deployments Experience with CI/CD, monitoring, and containerization (Docker, Terraform, Jenkins, New Relic) Strong computer science fundamentals (algorithms, data structures, systems design, and networking) Excellent communication skills and successful collaboration with technical and non-technical stakeholders Passion for mentoring, knowledge-sharing, and helping teams grow Our Tech Stack: Programming Languages: Mainly TypeScript / JavaScript; subsystems may use other languages Cloud & Infrastructure: AWS, Docker, Terraform, Jenkins Production Monitoring: New Relic Databases: ClickHouse, PostgreSQL Nice to Have: Experience in cybersecurity, threat intelligence, or other security-focused platforms Familiarity with front-end development and full-stack delivery practices Experience building internal platforms, developer tools, or SDKs Background working with high-scale systems and large datasets Benefits: Specific to each country, we offer a competitive salary, stock options, Health benefits, and unlimited PTO, parental leave, tuition reimbursements, and much more! The estimated total compensation range for this position is $160,000 - $185,000 (base plus bonus). Actual compensation for the position is based on a variety of factors, including, but not limited to affordability, skills, qualifications and experience, and may vary from the range. In addition to base salary, employees may also be eligible for annual performance-based incentive compensation awards and equity, among other company benefits. SecurityScorecard is committed to Equal Employment Opportunity and embraces diversity. We believe that our team is strengthened through hiring and retaining employees with diverse backgrounds, skill sets, ideas, and perspectives. We make hiring decisions based on merit and do not discriminate based on race, color, religion, national origin, sex or gender (including pregnancy) gender identity or expression (including transgender status), sexual orientation, age, marital, veteran, disability status or any other protected category in accordance with applicable law. We also consider qualified applicants regardless of criminal histories, in accordance with applicable law. We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need assistance or accommodation due to a disability, please contact talentacquisitionoperations@securityscorecard.io. Any information you submit to SecurityScorecard as part of your application will be processed in accordance with the Company’s privacy policy and applicable law. SecurityScorecard does not accept unsolicited resumes from employment agencies. Please note that we do not provide immigration sponsorship for this position. #LI-DNI

TypeScript
Microservices Architecture
API Design
System Architecture
Terraform
Direct Apply
Posted 3 months ago
SecurityScorecard

Sales Engineer, ANZ

SecurityScorecardAnywhereFull-time
View Job
Compensation$170K - 190K a year

Partner with sales and channel teams to provide technical sales support, deliver presentations, enable partners, and align product roadmaps with customer needs in cybersecurity. | 3+ years technical sales or pre-sales experience in cybersecurity or related field, strong presentation skills, preferably with cybersecurity certifications like CISSP or GIAC. | About SecurityScorecard: SecurityScorecard is the global leader in cybersecurity ratings, with over 12 million companies continuously rated, operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and funded by world-class investors, SecurityScorecard’s patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their digital footprint. Headquartered in New York City, our culture has been recognized by Inc Magazine as a "Best Workplace,” by Crain’s NY as a "Best Places to Work in NYC," and as one of the 10 hottest SaaS startups in New York for two years in a row. Most recently, SecurityScorecard was named to Fast Company’s annual list of the World’s Most Innovative Companies for 2023 and to the Achievers 50 Most Engaged Workplaces in 2023 award recognizing “forward-thinking employers for their unwavering commitment to employee engagement.” SecurityScorecard is proud to be funded by world-class investors including Silver Lake Waterman, Moody’s, Sequoia Capital, GV and Riverwood Capital. About the team SecurityScorecard's Sales Engineering team are trusted security advisors and business partners both internally and to prospective clients, offering deep knowledge about the market and our solution. We are intellectually curious, find great reward in delivering valuable solutions to customers, and are passionate about cybersecurity. As a Sales Engineer, you will partner with Field Sales and Channel Team in the ANZ region throughout the sales relationship lifecycle to build solutions to address specific customer security needs. Key to the role is communicating the value proposition of SecurityScorecard's platform and suite of solutions, positioning SecurityScorecard effectively against competing offerings. You'll also collaborate cross functionally, providing customer feedback to product teams to inform the roadmap. The role will also include working with and providing key technical enablement to SecurityScorecard Channel, ensuring they are kept up to date on new product enhancements and developments. Success in this role requires security and technical acumen to develop a deep understanding of SecurityScorecard's architecture and services and a consultative approach to understanding customer business needs. You'll leverage your strategic communication skills to engage in technical and business discussions with engineers and senior decision makers alike, translating customer needs into technical requirements and conveying the merit of SecurityScorecard's solutions throughout. Key Responsibilities • Serve as the domain expert on SecurityScorecard solutions throughout the sales lifecycle • Provide specific solution/technology/product consulting, technical and sales support for major potential accounts • Perform in-depth and high-level technical presentations for customers, partners and prospects • Work with and provide Technical enablement to Partners in the region • Maintain area or operation responsibilities for selected major account opportunities • Maintain product roadmaps and alignment between the customer and relevant business entities • Devise, present and document technical solutions • Keep up-to-date on relevant competitive solutions, products and services Qualifications • Minimum 3+ years of technical sales or pre-sales experience in cybersecurity, or as a cybersecurity practitioner who desires to grow a career in a client facing role • Industry recognized certifications such as a CISSP, GIAC, etc. a plus • Demonstrated presentation and interpersonal skills; communicate in front of large groups with a mixed audience of technical and non-technical • Native speaker or proficient Additional Qualifications • Highly motivated self starter who works well independently • Intellectually curious; seeks to continually self-educate and evolve domain specific knowledge • Chinese-Mandarin is a plus Benefits: Specific to each country, we offer a competitive salary, stock options, Health benefits, and unlimited PTO, parental leave, tuition reimbursements, and much more! The estimated total compensation range for this position is $170,000 - $190,000 USD (base plus bonus). Actual compensation for the position is based on a variety of factors, including, but not limited to affordability, skills, qualifications and experience, and may vary from the range. In addition to base salary, employees may also be eligible for annual performance-based incentive compensation awards and equity, among other company benefits. SecurityScorecard is committed to Equal Employment Opportunity and embraces diversity. We believe that our team is strengthened through hiring and retaining employees with diverse backgrounds, skill sets, ideas, and perspectives. We make hiring decisions based on merit and do not discriminate based on race, color, religion, national origin, sex or gender (including pregnancy) gender identity or expression (including transgender status), sexual orientation, age, marital, veteran, disability status or any other protected category in accordance with applicable law. We also consider qualified applicants regardless of criminal histories, in accordance with applicable law. We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need assistance or accommodation due to a disability, please contact talentacquisitionoperations@securityscorecard.io. Any information you submit to SecurityScorecard as part of your application will be processed in accordance with the Company’s privacy policy and applicable law. SecurityScorecard does not accept unsolicited resumes from employment agencies. Please note that we do not provide immigration sponsorship for this position. #LI-DNI

Technical Sales Engineering
Consultative Sales
Customer Relationship Management
Presentation and Communication Skills
Multilingual (English, Spanish, French, Portuguese)
Solution Selling
CRM Software
Verified Source
Posted 10 months ago
SecurityScorecard

Business Development Team Manager EMEA & LATAM

SecurityScorecardAnywhereFull-time
View Job
Compensation$120K - 160K a year

Lead and manage a team of BDRs across EMEA and LATAM to drive pipeline growth and optimize outbound sales strategies. | Proven experience managing sales or BDR teams, strong leadership skills, proficiency in CRM tools, and ability to operate across diverse international markets. | About SecurityScorecard: SecurityScorecard is the global leader in cybersecurity ratings, with over 12 million companies continuously rated, operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and funded by world-class investors, SecurityScorecard’s patented rating technology is used by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their digital footprint. Headquartered in New York City, our culture has been recognized by Inc Magazine as a "Best Workplace,” by Crain’s NY as a "Best Places to Work in NYC," and as one of the 10 hottest SaaS startups in New York for two years in a row. Most recently, SecurityScorecard was named to Fast Company’s annual list of theWorld’s Most Innovative Companies for 2023 and to the Achievers 50 Most Engaged Workplaces in 2023 award recognizing “forward-thinking employers for their unwavering commitment to employee engagement.” SecurityScorecard is proud to be funded by world-class investors including Silver Lake Waterman, Moody’s, Sequoia Capital, GV and Riverwood Capital. Role Overview: The BDR Manager - EMEA / LATAM, will lead and scale a high-performing team of Business Development Representatives across both regions. This role is similar to an enterprise BDR manager role. This leader will drive pipeline growth, optimize outbound strategies, and ensure the team is equipped to engage prospects in key EMEA and LATAM markets. The BDR Manager will collaborate closely with Sales, Marketing, and regional leadership to align on go-to-market strategies and deliver on SecurityScorecard’s ambitious growth targets in the country. Key Responsibilities: • Lead, mentor, and manage a team of BDRs across EMEA and LATAM, ensuring achievement of individual and team KPIs such as meetings booked, qualified leads, and pipeline contribution. • Develop and execute outbound prospecting strategies tailored to both. markets, targeting key industries and buyer personas across the country’s diverse regions. • Oversee daily operations: onboarding, training, performance management, and career development of BDRs. • Monitor and report on team performance using CRM tools (e.g., Salesforce), providing regular feedback and identifying areas for improvement. • Collaborate with Sales and Marketing to align messaging, campaign strategies, and lead handoff processes; ensure smooth cross-functional communication. • Build and maintain a scalable BDR playbook, incorporating best practices for prospecting, lead qualification, and objection handling. • Work with partners and distributors to maximize SecurityScorecard’s reach and impact in local EMEA and LATAM markets. • Stay up to date on SecurityScorecard’s product offerings and the evolving cybersecurity landscape. • Foster a culture of continuous learning, inclusivity, and high performance within the team. Key Markets Language Requirements: The BDR Manager will oversee activities in the following priority regions: • Europe • Middle East • Latin America Languages: • Proficiency in English is required for national collaboration and reporting. • Additional proficiency in Spanish or other languages is a plus Benefits: Specific to each country, we offer a competitive salary, stock options, Health benefits, and unlimited PTO, parental leave, tuition reimbursements, and much more! SecurityScorecard is committed to Equal Employment Opportunity and embraces diversity. We believe that our team is strengthened through hiring and retaining employees with diverse backgrounds, skill sets, ideas, and perspectives. We make hiring decisions based on merit and do not discriminate based on race, color, religion, national origin, sex or gender (including pregnancy) gender identity or expression (including transgender status), sexual orientation, age, marital, veteran, disability status or any other protected category in accordance with applicable law. We also consider qualified applicants regardless of criminal histories, in accordance with applicable law. We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need assistance or accommodation due to a disability, please contact talentacquisitionoperations@securityscorecard.io. Any information you submit to SecurityScorecard as part of your application will be processed in accordance with the Company’s privacy policy and applicable law. SecurityScorecard does not accept unsolicited resumes from employment agencies. Please note that we do not provide immigration sponsorship for this position.

Sales Leadership
Business Development
Pipeline Growth
Outbound Prospecting
Team Management
CRM (Salesforce)
Cross-functional Collaboration
Multilingual Communication
Verified Source
Posted 11 months ago

Ready to join SecurityScorecard?

Create tailored applications specifically for SecurityScorecard with our AI-powered resume builder

Get Started for Free

Ready to have AI work for you in your job search?

Sign-up for free and start using JobLogr today!

Get Started »
JobLogr badgeTinyLaunch BadgeJobLogr - AI Job Search Tools to Land Your Next Job Faster than Ever | Product Hunt