About the Role
Security at Saronic is a force multiplier, not a blocker. As a Security Engineer for Cyber Threat Intelligence, you will make sure we see threats coming. This is a hands-on, doctrine-driven engineering role where you will run a real intelligence program and turn raw indicators into operational defenses. You will work across various security functions to focus on adversaries targeting the defense industrial base. This is an opportunity to help run the threat-intelligence function for a fast-growing defense company, fuse intelligence with detection engineering, and directly shape how we anticipate threats.
Responsibilities
- Own and evolve the Priority Intelligence Requirements and collection-management framework, translating leadership decisions and threat models into tasked collection, hunts, and finished intelligence.
- Track priority adversaries, including nation-state, APT, and advanced criminal actors, along with their tooling, infrastructure, and tradecraft, and maintain adversary and campaign profiles.
- Operationalize indicators and TTPs into detections, hunts, and prioritized remediation, and build pipelines and connectors to ingest, enrich, and correlate intel from commercial feeds and OSINT.
- Turn raw data into verified intelligence products that meaningfully influence decision-making.
- Fuse external intelligence with internal telemetry in a graph-based intelligence data store, running attack-path and identity-to-asset correlation to prioritize by real exposure.
- Produce concise, actionable intelligence and briefings for security leadership and cross-functional partners, applying analytic tradecraft, estimative language, calibrated confidence, and structured analytic techniques, and modeling with STIX and MITRE ATT&CK.
- Develop and run intelligence-driven threat hunts across endpoint, cloud, identity, email, and network telemetry.
- Author durable detections (Sigma, YARA) with detection engineering and incident response.
- Perform infrastructure pivoting (passive DNS, certificate pivoting, WHOIS/ASN) and malware triage to extract indicators, TTPs, and attribution signals.
- Run deep and dark-web, breach-credential, and identity-exposure monitoring, including account-takeover, executive and VIP protection, and brand-impersonation.
- Coordinate takedowns with Legal, Comms, and IT.
- Help design and operate cyber-deception sensors (honeytokens, canaries, decoys) for high-fidelity, low-noise alerts.
- Build case-automation and in-case AI-agent workflows for enrichment and triage.
Requirements
- 4+ years in cyber threat intelligence, threat hunting, detection engineering, or intrusion analysis, or an equivalent combination of experience and demonstrated ability.
- Demonstrable tracking of sophisticated or state-sponsored adversaries that drove detection, hunting, or response.
- Fluency with the intelligence lifecycle, Priority Intelligence Requirements and collection management, and structured analytic techniques.
- Ability to produce finished intelligence with calibrated confidence.
- Strong software engineering skills to build automation, connectors, and data pipelines end to end.
- Working command of MITRE ATT&CK, the Diamond Model, and the Cyber Kill Chain, plus STIX/TAXII for modeling and sharing intelligence.
- Hands-on infrastructure and log analysis (passive DNS, certificate pivoting, WHOIS/ASN) and detection authoring (Sigma, YARA, or SIEM-native).
- Ability to obtain and maintain a U.S. security clearance.
Skills
- Cyber Threat Intelligence
- Threat Hunting
- Detection Engineering
- Intrusion Analysis
- Intelligence Lifecycle
- Priority Intelligence Requirements
- Collection Management
- Structured Analytic Techniques
- Software Engineering
- Automation
- Data Pipelines
- MITRE ATT&CK
- Diamond Model
- Cyber Kill Chain
- STIX/TAXII
- Infrastructure and Log Analysis
- Passive DNS
- Certificate Pivoting
- WHOIS/ASN
- Sigma
- YARA
- SIEM-native
- Nation-state/APT Tracking
- Graph-based CTI Platform
- MISP
- Malware Analysis
- Adversary Attribution
- Cyber-deception Design and Operations
- Honeytokens
- Canaries
- Decoys
- Digital Risk Protection
- Dark-web Tradecraft
- Breach-credential Monitoring
- Executive-protection Monitoring
- Brand-impersonation Monitoring
- LLMs and AI Tooling
- Agentic Case Automation
- DoD/DIB Context
- CMMC/NIST 800-171
- GovCloud
- ITAR
- Military Intelligence Doctrine
- OT/ICS Security
- Maritime Security
Location
- United States
Work Type
- Full-time
Experience Level
- 4+ years
Salary/Compensations
- Competitive Salary
- Industry-standard salaries with opportunities for performance-based bonuses
Benefits
- Medical Insurance (Saronic pays 100% of employee premium, 80% for dependents)
- Dental and Vision Insurance (Saronic pays 100% of employee premium for basic plan, 80% for dependents)
- Generous PTO and Holidays
- Paid Parental Leave (maternity and paternity)
- 401(k) plan with company match
- Stock Options
- Life and Disability Insurance
- Pet Insurance (discounted options including 24/7 Telehealth helpline)
- Free lunch benefit
- Unlimited free drinks and snacks in the office
About the Company
- Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms.
Equal Opportunity
- Saronic does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits.
- We are also committed to providing reasonable accommodations for qualified individuals with disabilities.
- If this role is based in the United States, it requires access to export-controlled information or items that require “U.S. Person” status. As defined by U.S. law, individuals who are any one of the following are considered to be a “U.S. Person”: (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3).
