1

Threat Intelligence Jobs in Raleigh, NC (NOW HIRING)

Intelligence Analyst

Cary, NC · On-site

$80K/yr

Serve as the primary SME for the MSOC's intelligence tool suite (e.g., threat intelligence, critical event management, mass communications, travel risk, and social media monitoring platforms ...

Experience with threat hunting or cyber threat intelligence fundamentals * Experience with data fabric technologies such as Bindplane or Cribl * Experience with infrastructure and networking concepts ...

Cyber Manager - AI SOC

Raleigh, NC · On-site

$107K - $145K/yr

Experience with threat hunting, cyber threat intelligence, or purple team collaboration * Experience applying artificial intelligence, machine learning, or large language model workflows to security ...

next page

Showing results 1-20

Threat Intelligence information

See Raleigh, NC salary details

$10.7K

$97.8K

$129.3K

How much do threat intelligence jobs pay per year?

As of Sep 5, 2026, the average yearly pay for threat intelligence in Raleigh, NC is $97,760.00, according to ZipRecruiter salary data. Most workers in this role earn between $71,400.00 and $128,800.00 per year, depending on experience, location, and employer.

What is a threat intelligence?

A Threat Intelligence job involves collecting, analyzing, and interpreting data on cyber threats to help organizations anticipate and mitigate security risks. Professionals in this field monitor threat actors, vulnerabilities, and attack patterns to provide actionable insights for security teams. They work with tools like threat feeds, dark web monitoring, and malware analysis to detect potential threats. The goal is to enhance an organization's cybersecurity posture by proactively identifying and preventing attacks before they happen.

What does a threat intelligence do?

A typical day in Threat Intelligence often involves monitoring real-time security alerts, analyzing cyber threat data, and preparing intelligence reports for IT and security leadership. Professionals in this field regularly collaborate with incident response teams, conduct threat assessments, and research emerging vulnerabilities or tactics used by threat actors. The role requires balancing proactive research with reactive support, ensuring the organization remains aware of the latest threats. You may also participate in cross-functional meetings and share findings with both technical and non-technical stakeholders.

What are the key skills and qualifications needed to thrive in threat intelligence?

To thrive in Threat Intelligence, you need strong analytical thinking, cybersecurity expertise, and a background in information security or related fields. Familiarity with tools such as SIEM platforms, threat intelligence feeds, malware analysis tools, and certifications like CISSP or GIAC GCTI are highly valued. Effective communication, problem-solving, and teamwork are crucial soft skills in this role. These skills and qualities ensure timely threat detection, clear reporting, and strong collaboration to protect organizational assets from evolving cyber threats.

What are the most commonly searched types of Threat Intelligence jobs in Raleigh, NC?

The most popular types of Threat Intelligence jobs in Raleigh, NC are:

What are popular job titles related to Threat Intelligence jobs in Raleigh, NC?

For Threat Intelligence jobs in Raleigh, NC, the most frequently searched job titles are:

What cities near Raleigh, NC are hiring for Threat Intelligence jobs?

Cities near Raleigh, NC with the most Threat Intelligence job openings:

Infographic showing various Threat Intelligence job openings in Raleigh, NC as of August 2026, with employment types broken down into 83% Full Time, and 17% Part Time. Highlights an 50% In-person, 17% Hybrid, and 33% Remote job distribution, with an average salary of $97,760 per year, or $47 per hour.

Senior Research Engineer, Threat Intelligence

Zoomcar

Raleigh, NC • On-site

$140 - $150/hr

Other

Medical, PTO

Re-posted yesterday


Key responsibilities

  • Own the process of transforming research artifacts into production‑ready detection rules, feeds, or alerts.

  • Build and maintain platform components such as distribution servers, sandbox orchestration, and rules engines, ensuring compatibility with existing data contracts.

  • Develop detection content like YARA, Sigma, and STIX patterns, and create pipelines to distribute and correlate threat signals.


Job description

About the Role

You'll join STRIKE, SecurityScorecard's Threat Intelligence team, as the engineering counterpart to research. STRIKE runs several research motions in parallel, each on its own clock: rapid response to active events, longer product‑tied work, and standards‑anchored research on a quarterly cadence. The path from a finding to a shipped detection or feed gets reinvented every time. That’s the problem this role is here to solve.

You'll work directly with the senior technical leader who owns STRIKE’s R&D direction, and report to the Head of Threat Research for people management. Technical direction comes from R&D leadership; you own delivery. You'll take a research artifact (a malware finding, an infrastructure cluster, a new indicator class, a behavioral pattern) and turn it into something the company can use without a second round of engineering: schemas, pipeline hooks, distribution feeds, detection rules, or platform APIs.

This isn’t a pure research role, and it isn’t a pure platform role either. Researchers ideate, you ship.

Key Responsibilities Research‑to‑Production Pipeline
  • Own the path from research output to production‑ready artifact: a detection rule, a distributed feed, a scoring input, or a customer alert. Partner with adjacent teams to define clean handoff contracts, so new signals arrive downstream with the schema, value framing, and consumption pattern already defined.
Threat Intelligence Platform Engineering
  • Build and maintain STRIKE platform components across multiple services and runtimes, including distribution servers, sandbox orchestration, OSINT ingestion, federated sharing endpoints, agent runtimes, and rules engines that operate over standards‑anchored predicates. Extend these systems without breaking the data contracts already in production.
Detection Content and Signal Production
  • Turn research into shipped detection content: YARA, Sigma, STIX patterns, behavioral indicators, and the pipelines that distribute them. Build correlation pipelines that link scan data, attack surface signals, vulnerability data, and adversary tracking into customer‑facing intelligence.
Data Model and Standards Adoption
  • Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard. Define and govern schemas that hold up once they reach downstream teams.
Research Workflow Engineering
  • Build the automation that removes commodity overhead from research work: indicator enrichment, report drafting, corpus correlation, feed normalization, and sandbox triage. Help move the team from analyst‑driven, model‑assisted workflows toward model‑driven workflows with analyst review.
  • The work that matters most here is often the unglamorous part: retrieval grounded in the team’s own corpus so outputs cite sources rather than model priors, schema‑constrained output so a generated indicator is a valid one, and eval harnesses that catch regressions before analysts do. Cost accounting, latency budgeting, prompt versioning, and output logging round out the infrastructure that makes a workflow safe to run unattended.
  • You should have a clear sense of when a model is the wrong tool. A regex beats a model for known patterns; a SQL query beats a model for structured data. Knowing where that line sits, and respecting it, is part of the job.
Cross‑Functional Delivery
  • Coordinate with engineering, measurement, and platform product teams so research actually lands in product. You’ll often serve as the engineering voice translating between researchers, product managers, and platform engineers, and you may occasionally explain the work to customers, journalists, or executives.
Qualifications Education
  • Bachelor’s or Master’s in Computer Science, Cybersecurity, or a related technical field. Self‑taught practitioners with strong public work are welcome.
Experience
  • 5 to 8 years in a hands‑on engineering role with meaningful exposure to threat intelligence, security research, or detection engineering. Prior experience building production systems that consume or emit threat intel data is required.
Technical Skills
  • Python and TypeScript/Node at a production level
  • Relational and cache data stores, plus at least one streaming or batch data platform
  • Cloud infrastructure (AWS preferred), containers, and CI/CD pipelines
  • Working knowledge of STIX 2.1, TAXII 2.1, MISP, and MITRE ATT\&CK, and how they work together in practice
Detection and Research Tooling

Hands‑on experience with YARA, Sigma, and STIX Patterning. Comfortable reading malware analysis output, parsing adversary infrastructure data, and writing detection logic that holds up under production load.

Applied Language Models

You’ve shipped production systems that use language models, not just demos. That includes retrieval over a real corpus, structured output with schema validation, eval harnesses that catch regressions before users do, and a solid understanding of where models fail: recency, long‑tail facts, numerical reasoning, and adversarial input or prompt injection. You can do the cost‑per‑task math for your workloads, and you can make the case when a smaller, tightly scaffolded model beats a larger one.

You approach model output with healthy skepticism by default. The bar for shipping a model‑generated indicator or detection is higher than for shipping a regex, and you understand why and design accordingly.

Bridge Mindset

You write code that ships, and you understand why researchers think the way they do. If you’ve only ever worked from a backlog handed down by a product manager, this probably isn’t the right fit. If you’ve taken an idea sketched out in a chat message and turned it into a deployed pipeline before the next sprint began, that’s the mode we’re looking for.

Bonus
  • Experience with policy‑as‑code or expression‑language engines (CEL, OPA, or similar)
  • Published or co‑authored security research (campaigns, vulnerabilities, adversary tracking)
  • Large‑scale telemetry experience (Splunk, Kinesis, NetFlow, or equivalent)
  • Contributor or maintainer on open‑source threat intel projects (MISP, OpenCTI, Sigma, STIX, ATT\&CK)
  • Familiarity with quantitative risk frameworks such as FAIR
  • Familiarity with Golang at a production level
Benefits

Specific to each country, we offer a competitive salary, stock options, health benefits, and unlimited PTO, parental leave, tuition reimbursements, and much more!

The estimated total compensation range for this position is $140,000 - $150,000 (base plus bonus). Actual compensation for the position is based on a variety of factors, including, but not limited to affordability, skills, qualifications and experience, and may vary from the range. In addition to base salary, employees may also be eligible for annual performance‑based incentive compensation awards and equity, among other company benefits.

Equal Employment Opportunity

SecurityScorecard is committed to Equal Employment Opportunity and embraces diversity. We believe that our team is strengthened through hiring and retaining employees with diverse backgrounds, skill sets, ideas, and perspectives. We make hiring decisions based on merit and do not discriminate based on race, color, religion, national origin, sex or gender (including pregnancy) gender identity or expression (including transgender status), sexual orientation, age, marital, veteran, disability status or any other protected category in accordance with applicable law.

We also consider qualified applicants regardless of criminal histories, in accordance with applicable law. We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need assistance or accommodation due to a disability, please contact talentacquisitionoperations@securityscorecard.io.

Any information you submit to SecurityScorecard as part of your application will be processed in accordance with the Company’s privacy policy and applicable law.

SecurityScorecard does not accept unsolicited resumes from employment agencies. Please note that we do not provide immigration sponsorship for this position. #LI-DNI

#J-18808-Ljbffr