Back to positions

Detection & Response Security Engineer, Threat Intelligence

Remote role Full-time Open position

Meta Security is looking for a threat intelligence investigator with extensive experience in investigating cyber threats with an intelligence-driven approach. You will be proactively responding to a broad set of security threats, as well as tracking actor groups with an interest or capability to target Meta and its employees. You will also be identifying the gaps in current detections and preventions by long-term intelligence tracking and research, and working with cross-functional stakeholders to improve Meta’s security posture. You will help the team establish, lead and execute multi-year roadmaps that improve research efficiency and quality across the team, and drive improvements to stakeholder management across a broad range of intelligence requirements.Detection & Response Security Engineer, Threat Intelligence Responsibilities

  • Influence and align the team’s vision and strategy. Collaboratively prioritize and deliver specific multi-year roadmaps and projects
  • Build, cultivate, and maintain impactful relationships with intelligence stakeholders to identify and facilitate solutions to increase the impact of the team’s work
  • Refine operational metrics, key performance indicators, and service level objectives to measure Intelligence research and services
  • Lead cross-functional projects to improve the security posture of Meta’s infrastructure, such as red team operations, surface detection coverage expansion and vulnerability management discussions
  • Track threat clusters posing threats to Meta’s infrastructure and employees, and identify, develop and implement countermeasures on our corporate network
  • Investigate, mitigate, and forecast emerging technical trends and communicate effectively with actionable suggestions to different types of audiences
  • Work closely with incident responders to provide useful and timely intelligence to enrich ongoing investigations
  • Improve the tooling of threat cluster tracking and intelligence data integration to existing systems

Minimum Qualifications

  • 8+ years threat intelligence experience
  • B.S. or M.S. in Computer Science or related field, or equivalent experience
  • Be a technical and process subject matter expert regarding Security Operations and Threat Intelligence services
  • Experience developing and delivering information on threats, incidents and program status for leadership
  • Expertise with campaign tracking techniques and converting tracking results to long term countermeasures
  • Expertise with threat modeling frameworks, such as Diamond Model or/and MITRE ATT&CK framework
  • Experience intelligence-driven hunting to spot suspicious activities in the network and identify potential risks
  • Proven track record of managing and executing on short term and long term projects
  • Ability to work with a team spanning multiple locations/time zones
  • Ability to prioritize and execute tasks with minimal direction or oversight
  • Ability to think critically and qualify assessments with solid communications skills
  • Coding or scripting experience in one or more scripting languages such as Python or PHP

Preferred Qualifications

  • Experience recruiting, building, and leading technical teams, including performance management
  • Experience close collaborating with incident responders on incident investigations
  • Experience in threat hunting including leveraging intelligence data to proactively identify and iteratively investigates suspicious behavior across networks and systems
  • Familiarity with malware analysis or network traffic analysis
  • Familiarity with nation-state, sophisticated criminal, or supply chain threats
  • Familiarity with file-based or network-based rules and signatures for detection and tracking of complex threats, such as YARA or Snort
  • Experience in one or more query languages such as SQL
  • Experience authoring production code for threat intelligence tooling
  • Experience conducting large scale data analysis
  • Experience working across the broader security community

For those who live in or expect to work from California if hired for this position, please click here for additional information. About Meta Meta builds technologies that help people connect, find communities, and grow businesses. When Facebook launched in 2004, it changed the way people connect. Apps like Messenger, Instagram and WhatsApp further empowered billions around the world. Now, Meta is moving beyond 2D screens toward immersive experiences like augmented and virtual reality to help build the next evolution in social technology. People who choose to build their careers by building with us at Meta help shape a future that will take us beyond what digital connection makes possible today—beyond the constraints of screens, the limits of distance, and even the rules of physics. $177,000/year to $251,000/year + bonus + equity + benefits Individual compensation is determined by skills, qualifications, experience, and location. Compensation details listed in this posting reflect the base hourly rate, monthly rate, or annual salary only, and do not include bonus, equity or sales incentives, if applicable. In addition to base compensation, Meta offers benefits. Learn more about benefits at Meta. Equal Employment Opportunity Meta is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. You may view our Equal Employment Opportunity notice here. Meta is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, fill out the Accommodations request form.

apply to this job

Further positions

Sales Executive, IT Services

Remote role Full-time

Senior Client Executive

Remote role Full-time

RN Lead, DRG Coding/Validation Remote

Remote role Full-time

RSR I

Remote role Full-time

Regional Development Manager I

Remote role Full-time

Operations Manager, Financial Crime, AML

Remote role Full-time

Account Executive, SMB | DACH

Remote role Full-time

AI Automation Engineer

Remote role Full-time

Product Manager – ChannelOps

Remote role Full-time

Solutions Architect – Security, Automation & AI – Product Management, Alliances

Remote role Full-time

Partner Integrations Specialist

Remote role Full-time

Equities Quantitative Analyst, AVP

Remote role Full-time

Experienced Data Entry/Customer Service Representative – Accurate Record Management and Exceptional Client Experience

Remote role Full-time

Flexible Part-time Research Study Participant – Paid Opportunities in Various Fields

Remote role Full-time

Specialist, Social Media Content Creator

Remote role Full-time

Remote Licensed Insurance Agent

Remote role Full-time

Experienced Entry-Level Data Entry Operator – Remote Work Opportunity at arenaflex

Remote role Full-time

Part‑Time Remote Accounting Data Entry & Bookkeeping Specialist – arenaflex‑Proficient Financial Support for Non‑Profit Organization

Remote role Full-time

[Remote/WFM] AT&T Sales Representative [REMOTE]

Remote role Full-time

Experienced Public Safety Dispatcher I-II – Emergency Response and Communications Specialist

Remote role Full-time