×
Register Here to Apply for Jobs or Post Jobs. X

Security Engineer, Cyber Threat Intelligence

Job in San Diego, San Diego County, California, 92189, USA
Listing for: Saronic Technologies
Full Time position
Listed on 2026-08-03
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 140000 - 210000 USD Yearly USD 140000.00 210000.00 YEAR
Job Description & How to Apply Below

Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms.

Job Overview

Security at Saronic is a force multiplier, not a blocker. An autonomous-maritime defense company is a top-tier target for nation-state and advanced criminal actors, and we’re looking for a Security Engineer for Cyber Threat Intelligence to make sure we see them coming. This is a hands-on, doctrine-driven engineering role, not a reporting desk: you’ll run a real intelligence program and turn raw indicators into operational defenses.

You’ll work across Security Operations, Detection Engineering, Vulnerability Management, Physical Security, Insider Threat, Data Loss Prevention, and Red Team to focus on the adversaries targeting the defense industrial base.

This is an opportunity to help run the threat-intelligence function for a fast-growing defense company, fuse intelligence with detection engineering rather than isolating it as reporting, and directly shape how we anticipate threats to our vessels, supply chain, people, and data.

Responsibilities
  • Priority Intelligence Requirements & Collection:
    Help own and evolve our Priority Intelligence Requirements and collection-management framework, translating leadership decisions and our maritime-autonomy and defense-industrial-base threat model into tasked collection, hunts, and finished intelligence.

  • Adversary Tracking:
    Track the priority adversaries, including nation-state, APT, and advanced criminal actors most likely to target defense, maritime, and the broader industrial base, along with their tooling, infrastructure, and tradecraft, and maintain adversary and campaign profiles.

  • Turn Intelligence into Action:
    Operationalize indicators and TTPs into detections, hunts, and prioritized remediation, and build the pipelines and connectors that ingest, enrich, and correlate intel from commercial feeds and OSINT. Turn raw data into verified intelligence products that meaningfully influence decision-making at all levels of the organization.

  • Fuse Internal & External:
    Fuse external intelligence with internal telemetry in our graph-based intelligence data store, running attack-path and identity-to-asset correlation to prioritize by real exposure rather than CVSS alone.

  • Finished Intelligence:
    Produce concise, actionable intelligence and briefings for security leadership and cross-functional partners, applying analytic tradecraft, estimative language, calibrated confidence, and structured analytic techniques, and modeling with STIX and MITRE ATT&CK.

  • Hunting & Detection:
    Develop and run intelligence-driven threat hunts across endpoint, cloud, identity, email, and network telemetry, and author durable detections (Sigma, YARA) with detection engineering and incident response.

  • Infrastructure & Malware Analysis:
    Perform infrastructure pivoting (passive DNS, certificate pivoting, WHOIS/ASN) and malware triage to extract indicators, TTPs, and attribution signals.

  • Digital Risk & Identity Protection:
    Run deep and dark-web, breach-credential, and identity-exposure monitoring, including account-takeover, executive and VIP protection, and brand-impersonation, and coordinate takedowns with Legal, Comms, and IT.

  • Deception & Automation:
    Help design and operate cyber-deception sensors (honey tokens, canaries, decoys) for high-fidelity, low-noise alerts, and build case-automation and in-case AI-agent workflows for enrichment and triage.

Qualifications
  • 4+ years in cyber threat intelligence, threat hunting, detection engineering, or intrusion analysis, or an equivalent combination of experience and demonstrated ability, with demonstrable tracking of sophisticated or state-sponsored adversaries that drove detection, hunting, or response

  • Fluency with the intelligence lifecycle, Priority Intelligence Requirements and collection management, and structured analytic techniques, and the ability to produce finished intelligence with calibrated confidence

  • Strong software engineering to build automation, connectors, and data pipelines end to end

  • Working command of MITRE ATT&CK, the Diamond…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary