2

Freelance Remote Threat Intelligence Jobs (NOW HIRING)

Threat Intelligence Engineer (REMOTE)

OR · Remote

$51 - $66.25/hr

The Threat Intelligence Engineer is someone with real threat intelligence depth and the technical ability to understand threat feeds' data model and map it correctly to STIX 2.1, who uses AI to make ...

New

Threat Intelligence Analyst III

Reston, VA · On-site +1

$110K - $165K/yr

Reston, VA (Hybrid/Remote) R eports To: Threat Intelligence Officer, Americas Travel Required: Up to 10% International Travel OUR CULTURE At FS-ISAC, how we work matters as much as what we do. We ...

Cyber Threat Intelligence - Threat actor tracking, malware analysis, data leak monitoring, darknet ... Location: Remote Key Responsibilities * Conduct in-depth OSINT/WEBINT investigations across ...

Cyber Threat Intelligence - Threat actor tracking, malware analysis, data leak monitoring, darknet ... Location: Remote Key Responsibilities * Conduct in-depth OSINT/WEBINT investigations across ...

Senior Cyber Threat Analyst

$102K - $132K/yr

They utilize advanced threat intelligence sources, security tools, and techniques to detect and ... Remote work requires a high level of trust in our employees, and we strictly adhere to the details ...

Senior Cyber Threat Analyst

$99K - $128K/yr

They utilize advanced threat intelligence sources, security tools, and techniques to detect and ... Remote work requires a high level of trust in our employees, and we strictly adhere to the details ...

Movies Author

$21.75 - $28/hr

**This is a paid freelance, remote position** Collider is the #1 entertainment website and publishes ... Intelligence.

Threat Hunt Analyst

Lakewood, CO · On-site +1

$99K - $225K/yr

Remote Work: No Job Number: R0238495 Location: Lakewood,CO,US Share job via: Share Threat Hunt ... Working at the intersection of cyber threat intelligence, detection engineering, and operational ...

next page

Showing results 1-20

Freelance Remote Threat Intelligence information

See salary details

$9

$22

$68

How much do freelance remote threat intelligence jobs pay per hour?

As of Jul 31, 2026, the average hourly pay for freelance remote threat intelligence in the United States is $22.97, according to ZipRecruiter salary data. Most workers in this role earn between $18.75 and $18.75 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Freelance Remote Threat Intelligence Analyst, and why are they important?

To thrive as a Freelance Remote Threat Intelligence Analyst, you need a strong background in cybersecurity, threat analysis, and risk assessment, often supported by relevant degrees or industry certifications like CISSP or CompTIA Security+. Familiarity with threat intelligence platforms, SIEM tools, and open-source intelligence (OSINT) frameworks is typically required. Strong analytical thinking, attention to detail, and effective written communication set successful analysts apart in this role. These skills are vital for identifying emerging threats, communicating findings clearly to stakeholders, and supporting proactive defense strategies in a rapidly evolving security landscape.

What is a Freelance Remote Threat Intelligence specialist?

A Freelance Remote Threat Intelligence specialist is a cybersecurity professional who works independently, often from a remote location, to monitor, analyze, and report on potential threats to an organization’s digital assets. Their main role involves gathering information on current and emerging cyber threats, assessing risks, and providing actionable intelligence to help companies prevent or respond to cyberattacks. Unlike full-time employees, freelancers typically work for multiple clients and may offer specialized expertise on a project basis.

How does a freelance remote threat intelligence analyst typically collaborate with clients and other security teams?

As a freelance remote threat intelligence analyst, you will often collaborate with clients and their internal security teams through virtual meetings, secure communication platforms, and shared documentation. Clear communication and timely reporting are critical, as you'll need to regularly update stakeholders on emerging threats, indicators of compromise, and actionable recommendations. Building strong client relationships remotely requires being proactive, responsive, and adaptable to each organization's unique risk environment and protocols. Collaboration may also involve participating in incident response calls or contributing to cross-functional security projects alongside other remote professionals.
More about Freelance Remote Threat Intelligence jobs
What cities are hiring for Freelance Remote Threat Intelligence jobs? Cities with the most Freelance Remote Threat Intelligence job openings:
What are the most commonly searched types of Remote Threat Intelligence jobs? The most popular types of Remote Threat Intelligence jobs are:
What states have the most Freelance Remote Threat Intelligence jobs? States with the most job openings for Freelance Remote Threat Intelligence jobs include:
What job categories do people searching Freelance Remote Threat Intelligence jobs look for? The top searched job categories for Freelance Remote Threat Intelligence jobs are:
Infographic showing various Freelance Remote Threat Intelligence job openings in the United States as of July 2026, with employment types broken down into 56% Full Time, 12% Part Time, 2% Temporary, 22% Contract, and 8% Nights. Highlights an 60% Physical, 2% Hybrid, and 38% Remote job distribution, with an average salary of $47,772 per year, or $23 per hour.

Threat Intelligence Engineer (REMOTE)

Cyware

OR • Remote

$51 - $66.25/hr

Other

Retirement

Posted yesterday

New


Job description

About Cyware

Cyware delivers an innovative approach to cybersecurity that unifies threat intelligence, automation, threat response, and vulnerability management with data insights gleaned from assets, users, malware, attackers, and vulnerabilities. Cyware's Cyber Fusion platform integrates SOAR and TIP technology, enabling collaboration across siloed security teams. Cyware is widely deployed by enterprises, government agencies, and MSSPs, and is the leading threat intelligence sharing platform for global ISACs and CERTs. 

Your next opportunity starts here!

More on Cyware: (www.cyware.com) 

Built and designed by SecOps practitioners and cybersecurity leaders, Cyware offers multiple technologies within its Cyber Fusion platform, including advanced threat intelligence solutions (TIP) for large and small security teams, vendor-agnostic security automation (SOAR), and purpose-built security case management. As a result, organizations can increase speed and accuracy while reducing costs and analyst burnout. Cyware's Virtual Cyber Fusion solutions make secure collaboration, information sharing, and enhanced threat visibility a reality for enterprises, sharing communities (ISAC/ISAO), MSSPs, and government agencies of all sizes and needs.

About you: 
  • You are driven, inquisitive, proactive, and energetic 
  • You have a growth mindset and are committed to delivering results 
  • You thrive in a fast-paced, collaborative environment
Why We Are Hiring:

The Threat Intelligence Engineer is someone with real threat intelligence depth and the technical ability to understand threat feeds' data model and map it correctly to STIX 2.1, who uses AI to make that work dramatically faster. Someone who can be our threat intelligence SME: writing the use cases, supporting pre-sales and customers, and giving Product the domain expertise that shapes what we build.

Come join an exciting cybersecurity product startup that has closed its Series C funding round!

What You Will Do:
  • Map feeds to STIX and own the connector portfolio
  • Design and maintain mappings from commercial, open-source, and community threat intelligence sources into STIX 2.1 objects, relationships, markings, patterning, and extensions while preserving semantic fidelity.
  • Understand threat intel feed data models when API documentation is incomplete, or missing: inspect live payloads, sample data, and vendor dashboards to establish ground truth
  • Own connector lifecycle and quality-from onboarding new sources to detecting schema drift, validating mappings, and ensuring production reliability
  • Work directly with feed, sandbox, DRP, and enrichment partners on integrations and joint use cases
  • Leverage AI to accelerate engineering workflows
  • Build and improve an AI-assisted mapping workflow: infer schemas from sample payloads, propose candidate field-to-STIX mappings from documentation, and flag schema changes, while maintaining rigorous validation and human oversight
  • Be the threat intelligence SME for Product
  • Write threat intelligence use cases that drive product design, and pressure-test new capabilities against real analyst workflows.
  • Partner with Product to shape intelligence workflows, including PIRs, ATT&CK-aligned investigations, threat modeling, prioritization, collaboration, and intelligence-driven automation
  • Represent Cyware on MITRE and industry alliance committees, and bring what you learn back inside
  • Be the threat intelligence SME for the field
  • Serve as the technical threat intelligence expert for customers, prospects, and partners, translating complex intelligence concepts into practical business value
  • Enable Solution Architects, Sales Engineers, and Customer Success Managers with the threat intelligence knowledge and use cases they need to win and deliver
Who You Are:
  • US Citizenship is a requirement of this position in accordance with 8 U.S.C 1324b(a)(2)(C)
  • 5+ years in threat intelligence as an analyst, engineer, or specialist, with hands-on experience on enterprise-scale security products
  • Deep working knowledge of STIX/TAXII 2.1 objects, relationships, patterning, markings, and how to handle source data that does not fit the standard cleanly. You have implemented STIX mappings in production-not just studied the specification
  • Hands-on experience with commercial and open-source threat feeds and enrichment sources (CrowdStrike, Mandiant, Recorded Future, Flashpoint, Intel 471, MISP, etc.), and with threat intelligence platforms
  • Python: you write real code. API clients, parsers, normalizers, validators. This role builds and debugs; it does not spec and hand off
  • Practical AI fluency. You have used LLMs for real technical work: schema inference, data mapping, documentation parsing, code generation, and you know where they fail
  • Strong command of the intelligence lifecycle, MITRE ATT&CK, and the handling of IOCs, TTPs, and threat actors in conjunction with SOC, incident response, and threat hunting operations
  • Comfortable in a customer-facing, cross-functional seat: you can defend a mapping decision to an engineer and explain the value of intelligence to a CISO
  • Demonstrated ability to work successfully with colleagues across different time zones and geographies

We're a lean team, so your impact will be felt immediately. If this all sounds like a good fit for you, why not join us?

You'll love working at Cyware because
  • We foster an exciting and challenging start-up culture. 
  • We're not just employees. We're people. We offer a comprehensive benefits package including time off, paid holidays, retirement plans, insurance coverage and much more.
  • We'll invest in your career. Our company is growing quickly and we will give you the opportunity to do the same. You will have access to a number of professional development opportunities so that you can keep up with the company's evolving needs.
  • We offer competitive compensation packages. We deeply value the talent our team brings to the table and believe that fair and equitable total compensation packages are part of our commitment to everyone who works here.
  • We value diversity of people, culture, and ideas.
EEO Statement:

Cyware is dedicated to hiring a diverse workplace that celebrates an inclusive culture and a sense of belonging. As an equal opportunity employer, we do not discriminate based on race, color, religion, sex (including pregnancy, gender identity, gender expression, and sexual orientation), national origin, age, veteran status, genetic information or disability.

How to Apply

Apply right here. You've found the application!


Cyware logo

About Cyware

Sourced by ZipRecruiter

Industry

Network security

Company size

201 - 500 Employees

Headquarters location

Jersey City, NJ, US

Year founded

2016