Detection & Response Security Engineer, Threat Intelligence
Meta London, England, United Kingdom
Software Development · 10,001+ employees
About the role
The role involves tracking threat clusters targeting Meta's infrastructure and employees while developing and implementing effective countermeasures. You will collaborate with incident responders to provide actionable intelligence and improve the company's overall security posture through cross-functional projects.
What they look for
Requirements
Candidates must have at least 3 years of experience in threat intelligence and a bachelor's degree in a relevant field. Proficiency in threat modeling frameworks, scripting languages like Python or PHP, and experience with campaign tracking techniques are required.
Full description
Meta Security is looking for a threat intelligence investigator with extensive experience in investigating cyber threats with an intelligence-driven approach. You will be proactively responding to a broad set of security threats, as well as tracking actor groups with an interest or capability to target Meta and its employees. You will also be identifying the gaps in current detections and preventions by long-term intelligence tracking and research, and working with cross-functional stakeholders to improve Meta’s security posture.
Responsibilities
- Track threat clusters posing threats to Meta’s infrastructure and employees, and identify, develop and implement countermeasures on our corporate network
- Investigate, mitigate, and forecast emerging technical trends and communicate effectively with actionable suggestions to different types of audiences
- Work closely with incident responders to provide useful and timely intelligence to enrich ongoing investigations
- Improve the tooling of threat cluster tracking and intelligence data integration to existing systems
- Engage constructively in cross-functional projects to improve the security posture of Meta’s infrastructure, such as red team operations, surface detection coverage expansion and vulnerability management discussions
Minimum Qualifications
- 3+ years threat intelligence experience
- Bachelor's degree in Computer Science, Information Security, or relevant field (or equivalent experience)
- Familiarity with campaign tracking techniques and ability to convert the tracking results to long term countermeasures
- Familiarity with threat modeling framework, such as Diamond Model and/or MITRE ATT&CK framework
- Experience intelligence-driven hunting to spot suspicious activities in the network and identify potential risks
- Proven track record of managing and executing on short term and long term projects
- Ability to work with a team spanning multiple locations/time zones
- Ability to prioritize and execute tasks with minimal direction or oversight
- Ability to think critically and qualify assessments with solid communications skills
- Coding or scripting experience in one or more scripting languages such as Python or PHP
Preferred Qualifications
- Familiarity with malware analysis or network traffic analysis
- Experience authoring production code for threat intelligence tooling
- Experience conducting large scale data analysis
- Experience in one or more query languages such as SQL
- Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
- Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
- Experience working across the broader security community
- Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
- Production of file-based or network-based rules and signatures for detection and tracking of complex threats, such as YARA or Snort
- Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
- Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
- Experience closely collaborating with incident responders on incident investigations
- Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
- Familiarity with nation-state, sophisticated criminal, or supply chain threats
Similar roles
-
Senior Account Executive, Public Relations (Cybersecurity)
Highwire Connecticut, United States
-
Staff Product Security Engineer, PSIRT
ServiceNow Hyderabad, Telangana, India
-
Senior Security Engineer
Capco London, England, United Kingdom
-
Principal Security Engineer
Capco London, England, United Kingdom
-
Senior Security Engineer
DAIWA CAPITAL MARKETS AMERICA INC New York, New York, United States · $160K–$190K/yr
-
Information Security Engineer
Peoples Bank Louisville, Kentucky, United States