Deception & Automation: Help design and operate cyber-deception sensors (honeytokens, canaries ... Strong software engineering to build automation, connectors, and data pipelines end to end
Deception & Automation: Help design and operate cyber-deception sensors (honeytokens, canaries ... Strong software engineering to build automation, connectors, and data pipelines end to end
Deception & Automation: Help design and operate cyber-deception sensors (honeytokens, canaries ... Strong software engineering to build automation, connectors, and data pipelines end to end
Deception & Automation: Help design and operate cyber-deception sensors (honeytokens, canaries ... Strong software engineering to build automation, connectors, and data pipelines end to end
Cyber Systems Engineer with Security Clearance
San Diego, CA · On-site
$60.75 - $74.50/hr
WWT is seeking a Cyber Systems Engineer that will serve as a senior technical lead supporting the ... Design and deploy deception strategies across segmented enterprise and enclave environments.
Cyber Systems Engineer with Security Clearance
San Diego, CA · On-site
$60.75 - $74.50/hr
WWT is seeking a Cyber Systems Engineer that will serve as a senior technical lead supporting the ... Design and deploy deception strategies across segmented enterprise and enclave environments.
Senior Cyber Intelligence Engineer with Security Clearance
Annapolis Junction, MD · On-site
$129K - $161K/yr
... cyber deception and adversary engagement, cyber effects and reverse engineering, and cyber ... forensics. * Familiarity with adversarial C2 hardware and software. * Familiarity with supporting ...
Senior Cyber Intelligence Engineer with Security Clearance
Annapolis Junction, MD · On-site
$129K - $161K/yr
... cyber deception and adversary engagement, cyber effects and reverse engineering, and cyber ... forensics. * Familiarity with adversarial C2 hardware and software. * Familiarity with supporting ...
Principal Cyber Intelligence Engineer with Security Clearance
Annapolis Junction, MD · On-site
$172K - $216K/yr
... cyber deception and adversary engagement, cyber effects and reverse engineering, and cyber ... forensics. * Familiarity with adversarial C2 hardware and software. * Familiarity with supporting ...
Principal Cyber Intelligence Engineer with Security Clearance
Annapolis Junction, MD · On-site
$172K - $216K/yr
... cyber deception and adversary engagement, cyber effects and reverse engineering, and cyber ... forensics. * Familiarity with adversarial C2 hardware and software. * Familiarity with supporting ...
Defensive Cybersecurity Engineer/Blue Team with Security Clearance
Fairfax, VA · On-site
$158K - $198K/yr
... cyber deception and adversary engagement with increasing emphasis on Artificial Intelligence (AI ... Using detection engineering to create security analytics and dashboards in Splunk or Elastic and ...
Defensive Cybersecurity Engineer/Blue Team with Security Clearance
Fairfax, VA · On-site
$158K - $198K/yr
... cyber deception and adversary engagement with increasing emphasis on Artificial Intelligence (AI ... Using detection engineering to create security analytics and dashboards in Splunk or Elastic and ...
Defensive Cybersecurity Engineer/Blue Team with Security Clearance
Bedford, MA · On-site
$158K - $198K/yr
... cyber deception and adversary engagement with increasing emphasis on Artificial Intelligence (AI ... Using detection engineering to create security analytics and dashboards in Splunk or Elastic and ...
Defensive Cybersecurity Engineer/Blue Team with Security Clearance
Bedford, MA · On-site
$158K - $198K/yr
... cyber deception and adversary engagement with increasing emphasis on Artificial Intelligence (AI ... Using detection engineering to create security analytics and dashboards in Splunk or Elastic and ...
We're a nonprofit engineering, applied research, and advanced technology organization working in ... Direct, hands-on experience with industry and open-source DCO tools as well as with cyber deception ...
We're a nonprofit engineering, applied research, and advanced technology organization working in ... Direct, hands-on experience with industry and open-source DCO tools as well as with cyber deception ...
... deception). Preferred Qualifications * Master's degree in Cybersecurity, Computer Science ... GIAC Cyber Threat Intelligence GCTI, GIAC Reverse Engineering Malware GREM, ISC2 Certified ...
... deception). Preferred Qualifications * Master's degree in Cybersecurity, Computer Science ... GIAC Cyber Threat Intelligence GCTI, GIAC Reverse Engineering Malware GREM, ISC2 Certified ...
... deception). Preferred Qualifications * Master's degree in Cybersecurity, Computer Science ... GIAC Cyber Threat Intelligence GCTI, GIAC Reverse Engineering Malware GREM, ISC2 Certified ...
... deception). Preferred Qualifications * Master's degree in Cybersecurity, Computer Science ... GIAC Cyber Threat Intelligence GCTI, GIAC Reverse Engineering Malware GREM, ISC2 Certified ...
... deception). Preferred Qualifications * Master's degree in Cybersecurity, Computer Science ... GIAC Cyber Threat Intelligence GCTI, GIAC Reverse Engineering Malware GREM, ISC2 Certified ...
... deception). Preferred Qualifications * Master's degree in Cybersecurity, Computer Science ... GIAC Cyber Threat Intelligence GCTI, GIAC Reverse Engineering Malware GREM, ISC2 Certified ...
Cyber Systems Engineer
San Diego, CA · On-site
$185K - $200K/yr
Technologies & Platforms Security & Deception * Splunk Enterprise, Splunk Phantom, ELK (Elastic ... WWT is seeking a Cyber Systems Engineer that will serve as a senior technical lead supporting the ...
Cyber Systems Engineer
San Diego, CA · On-site
$185K - $200K/yr
Technologies & Platforms Security & Deception * Splunk Enterprise, Splunk Phantom, ELK (Elastic ... WWT is seeking a Cyber Systems Engineer that will serve as a senior technical lead supporting the ...
... cyber deception and adversary engagement with increasing emphasis in Artificial Intelligence (AI ... Using detection engineering to create security analytics and dashboards in Splunk or Elastic and ...
... cyber deception and adversary engagement with increasing emphasis in Artificial Intelligence (AI ... Using detection engineering to create security analytics and dashboards in Splunk or Elastic and ...
Job Category Software Engineering Job Details About Salesforce Salesforce is the #1 AI CRM, where ... defense capabilities, including cyber deception technology, decoys and honeypots, lures ...
Job Category Software Engineering Job Details About Salesforce Salesforce is the #1 AI CRM, where ... defense capabilities, including cyber deception technology, decoys and honeypots, lures ...
Job Category Software Engineering Job Details About Salesforce Salesforce is the #1 AI CRM, where ... defense capabilities, including cyber deception technology, decoys and honeypots, lures ...
Job Category Software Engineering Job Details About Salesforce Salesforce is the #1 AI CRM, where ... defense capabilities, including cyber deception technology, decoys and honeypots, lures ...
Partner with OEM alliances to integrate best-of-breed solutions across identity, deception, non ... Establish and scale the Cyber Engineering function, including operating models, team charters ...
Partner with OEM alliances to integrate best-of-breed solutions across identity, deception, non ... Establish and scale the Cyber Engineering function, including operating models, team charters ...
Summary The Senior Director of Cyber Defense Architecture & Engineering leads the strategy, design ... Deception technologies * Threat intelligence platforms * Security data lakes and analytics ...
Summary The Senior Director of Cyber Defense Architecture & Engineering leads the strategy, design ... Deception technologies * Threat intelligence platforms * Security data lakes and analytics ...
Summary The Senior Director of Cyber Defense Architecture & Engineering leads the strategy, design ... Deception technologies * Threat intelligence platforms * Security data lakes and analytics ...
Summary The Senior Director of Cyber Defense Architecture & Engineering leads the strategy, design ... Deception technologies * Threat intelligence platforms * Security data lakes and analytics ...
The Senior Director of Cyber Defense Architecture & Engineering leads the strategy, design ... Deception technologies | Threat intelligence platforms | Security data lakes and analytics ...
The Senior Director of Cyber Defense Architecture & Engineering leads the strategy, design ... Deception technologies | Threat intelligence platforms | Security data lakes and analytics ...
The Senior Director of Cyber Defense Architecture & Engineering leads the strategy, design ... Deception technologies | Threat intelligence platforms | Security data lakes and analytics ...
The Senior Director of Cyber Defense Architecture & Engineering leads the strategy, design ... Deception technologies | Threat intelligence platforms | Security data lakes and analytics ...
Cyber Deception Engineer information
See salary details
$29.5K - $44.8K
6% of jobs
$44.8K - $60K
5% of jobs
$60K - $75.3K
3% of jobs
$75.3K - $90.6K
0% of jobs
$103K is the 25th percentile. Wages below this are outliers.
$90.6K - $105.9K
13% of jobs
The median wage is $118.5K / yr.
$105.9K - $121.1K
27% of jobs
$121.1K - $136.4K
12% of jobs
$145.4K is the 75th percentile. Wages above this are outliers.
$136.4K - $151.7K
15% of jobs
$151.7K - $167K
11% of jobs
$167K - $182.2K
5% of jobs
$182.2K - $197.5K
3% of jobs
$29.5K
$122.1K
$197.5K
How much do cyber deception engineer jobs pay per year?
What is a cyber deception engineer?
What are the key skills and qualifications needed to thrive as a cyber deception engineer?
What are the main challenges faced by cyber deception engineers when designing and deploying deception environments?
What is the difference between Cyber Deception Engineer vs Threat Hunter?
| Aspect | Cyber Deception Engineer | Threat Hunter |
|---|---|---|
| Certifications | GCTI, CISSP, CEH | GCTI, CISSP, CEH |
| Work Environment | Designs deception tactics, implements honeypots, and manages deception tools | Proactively searches for threats within networks using data analysis and threat intelligence |
| Industry Usage | Cybersecurity teams focusing on deception strategies | Security teams conducting threat detection and incident response |
While both roles require similar certifications and work within cybersecurity, a Cyber Deception Engineer focuses on creating and managing deception technologies to mislead attackers, whereas a Threat Hunter actively searches for threats within networks to prevent breaches.
What are popular job titles related to Cyber Deception Engineer jobs?
For Cyber Deception Engineer jobs, the most frequently searched job titles are:

Security Engineer, Cyber Threat Intelligence
Austin, TX • On-site
Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Re-posted 19 days ago
Job description
Job Overview
Security at Saronic is a force multiplier, not a blocker. An autonomous-maritime defense company is a top-tier target for nation-state and advanced criminal actors, and we're looking for a Security Engineer for Cyber Threat Intelligence to make sure we see them coming. This is a hands-on, doctrine-driven engineering role, not a reporting desk: you'll run a real intelligence program and turn raw indicators into operational defenses.
You'll work across Security Operations, Detection Engineering, Vulnerability Management, Physical Security, Insider Threat, Data Loss Prevention, and Red Team to focus on the adversaries targeting the defense industrial base.
This is an opportunity to help run the threat-intelligence function for a fast-growing defense company, fuse intelligence with detection engineering rather than isolating it as reporting, and directly shape how we anticipate threats to our vessels, supply chain, people, and data.
Responsibilities
- Priority Intelligence Requirements & Collection: Help own and evolve our Priority Intelligence Requirements and collection-management framework, translating leadership decisions and our maritime-autonomy and defense-industrial-base threat model into tasked collection, hunts, and finished intelligence.
- Adversary Tracking: Track the priority adversaries, including nation-state, APT, and advanced criminal actors most likely to target defense, maritime, and the broader industrial base, along with their tooling, infrastructure, and tradecraft, and maintain adversary and campaign profiles.
- Turn Intelligence into Action: Operationalize indicators and TTPs into detections, hunts, and prioritized remediation, and build the pipelines and connectors that ingest, enrich, and correlate intel from commercial feeds and OSINT. Turn raw data into verified intelligence products that meaningfully influence decision-making at all levels of the organization.
- Fuse Internal & External: Fuse external intelligence with internal telemetry in our graph-based intelligence data store, running attack-path and identity-to-asset correlation to prioritize by real exposure rather than CVSS alone.
- Finished Intelligence: Produce concise, actionable intelligence and briefings for security leadership and cross-functional partners, applying analytic tradecraft, estimative language, calibrated confidence, and structured analytic techniques, and modeling with STIX and MITRE ATT&CK.
- Hunting & Detection: Develop and run intelligence-driven threat hunts across endpoint, cloud, identity, email, and network telemetry, and author durable detections (Sigma, YARA) with detection engineering and incident response.
- Infrastructure & Malware Analysis: Perform infrastructure pivoting (passive DNS, certificate pivoting, WHOIS/ASN) and malware triage to extract indicators, TTPs, and attribution signals.
- Digital Risk & Identity Protection: Run deep and dark-web, breach-credential, and identity-exposure monitoring, including account-takeover, executive and VIP protection, and brand-impersonation, and coordinate takedowns with Legal, Comms, and IT.
- Deception & Automation: Help design and operate cyber-deception sensors (honeytokens, canaries, decoys) for high-fidelity, low-noise alerts, and build case-automation and in-case AI-agent workflows for enrichment and triage.
Qualifications
- 4+ years in cyber threat intelligence, threat hunting, detection engineering, or intrusion analysis, or an equivalent combination of experience and demonstrated ability, with demonstrable tracking of sophisticated or state-sponsored adversaries that drove detection, hunting, or response
- Fluency with the intelligence lifecycle, Priority Intelligence Requirements and collection management, and structured analytic techniques, and the ability to produce finished intelligence with calibrated confidence
- Strong software engineering to build automation, connectors, and data pipelines end to end
- Working command of MITRE ATT&CK, the Diamond Model, and the Cyber Kill Chain, plus STIX/TAXII for modeling and sharing intelligence
- Hands-on infrastructure and log analysis (passive DNS, certificate pivoting, WHOIS/ASN) and detection authoring (Sigma, YARA, or SIEM-native)
- Ability to obtain and maintain a U.S. security clearance
Preferred Qualifications:
- Nation-state/APT tracking relevant to the defense industrial base, maritime, or manufacturing industries
- Standing up or operating an in-house or graph-based CTI platform, MISP, or a TAXII/STIX pipeline
- Malware analysis and adversary attribution (provisional clustering; tactical, operational, and strategic attribution)
- Cyber-deception design and operations (honeytokens, canaries, decoys)
- Digital risk protection and dark-web tradecraft: breach-credential, executive-protection, and brand-impersonation monitoring and takedowns
- Applying LLMs and AI tooling to accelerate collection, enrichment, and analysis, including agentic case automation
- DoD/DIB context (CMMC/NIST 800-171, GovCloud, ITAR) and military intelligence doctrine
- OT/ICS or maritime security knowledge
- Public CTI research, talks, or open-source contributions
- If your experience doesn't line up with every preferred qualification, we still encourage you to apply; we hire for demonstrated ability and outcomes.
Physical Demands
- Prolonged periods of sitting at a desk and working on a computer
- Occasional standing and walking within the office
- Manual dexterity to operate a computer keyboard, mouse, and other office equipment
- Visual acuity to read screens, documents, and reports
- Occasional reaching, bending, or stooping to access file drawers, cabinets, or office supplies
- Lifting and carrying items up to 20 pounds occasionally (e.g., office supplies, packages)
Benefits
Medical Insurance: Comprehensive health insurance plans covering a range of services
Saronic pays 100% of the premium for employees and 80% for dependents
Dental and Vision Insurance: Coverage for routine dental check-ups, orthodontics, and vision care
Saronic pays 100% of the premium under the basic plan for employees and 80% for dependents
Time Off: Generous PTO and Holidays
Parental Leave: Paid maternity and paternity leave to support new parents
Competitive Salary: Industry-standard salaries with opportunities for performance-based bonuses
Retirement Plan: 401(k) plan with company match
Stock Options: Equity options to give employees a stake in the company's success
Life and Disability Insurance: Basic life insurance and short- and long-term disability coverage
Pet Insurance: Discounted pet insurance options including 24/7 Telehealth helpline
Additional Perks: Free lunch benefit and unlimited free drinks and snacks in the office
Saronic CCPA Notice for Candidates and California Employees
If this role is based in the United States, it requires access to export-controlled information or items that require "U.S. Person" status. As defined by U.S. law, individuals who are any one of the following are considered to be a "U.S. Person": (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3).
Saronic does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits. We are also committed to providing reasonable accommodations for qualified individuals with disabilities.
About Saronic Technologies
Sourced by ZipRecruiter
Industry
Guided missile and space vehicle manufacturing
Company size
51 - 200 Employees
Headquarters location
Austin, TX, US
Year founded
2022