Overview
Company
Profile match
Impact
Conditions
Benefits
Hiring process
Similar jobs

Blackducksoftware

Black Duck delivers True Scale Application Security — SAST, SCA, DAST, and AI-powered AppSec — to help security and development teams detect vulnerabilities, manage open source license risk, and secure the software supply chain. Trusted by 4,000+ organizations.

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.

The Threat Intelligence Engineer supports the research, collection, and analysis of threat data that enables Black Duck to detect and respond to threats targeting the enterprise and its software supply chain. Working within the Threat Intelligence function under moderate supervision, you apply foundational knowledge of adversary tradecraft to assist in producing intelligence products, maintaining indicator pipelines, and contributing threat context to security workflows across the organization. This role solves moderately complex problems within defined guidelines and policies, collaborates with senior engineers on intelligence operations, and supports broader cybersecurity and security operations functions as capacity allows.

Essential Functions/Responsibilities

  • Assist with collection, processing, and analysis tasks across the intelligence requirements-to-dissemination workflow.
  • Help maintain the intelligence requirements register under guidance from senior team members.
  • Draft threat actor profiles, campaign summaries, and indicator packages for technical audiences; refine products based on senior engineer feedback.
  • Ingest, validate, and score indicators of compromise (IOCs) from commercial feeds (e.g., Recorded Future), open-source, and internal sources.
  • Support integration of IOC pipelines with SIEM and EDR platforms, including Sumo Logic and CrowdStrike Falcon/NG SIEM.
  • Apply confidence scoring and structured formats (e.g., STIX 2.1) to intelligence artifacts; escalate data quality issues to senior team members.
  • Monitor open-source package registries (npm, PyPI, Go, Maven, and others) and CI/CD pipeline integrity signals for indicators of adversarial activity including typosquatting, dependency confusion, and build-pipeline compromise.
  • Contribute to the internal supply chain threat detection program by assisting with data collection, documentation, and detection logic testing.
  • Assist broader cybersecurity and security operations functions - including CSIRT, Vulnerability Management, and PSIRT - with alert triage, threat research, and DLP investigation enrichment, as capacity allows.
  • Support security investigations by researching threat actor behaviors, identifying relevant IOCs, and providing contextual summaries.
  • Prepare threat intelligence summaries and briefing materials for internal consumers including CSIRT and Vulnerability Management.
  • Identify opportunities for workflow improvements within own area and recommend changes to senior team members.
  • Learn and follow applicable standards for intelligence data handling, sharing agreements, and governance; contribute to supporting documentation as directed.
  • Other tasks and activities as assigned.

Required Education/Experience & Skills

  • Typically at least two (2) years of experience in threat intelligence, security operations, threat hunting, or a closely related cybersecurity role; demonstrated ability to solve moderately complex problems within established guidelines.
  • Working familiarity with the intelligence production lifecycle, threat actor profiling concepts, and structured formats (e.g., STIX 2.1); ability to apply MITRE ATT&CK for basic TTP mapping.
  • Practical experience working within enterprise SIEM or EDR environments; ability to run queries, review alerts, and support detection validation (current platforms include Sumo Logic and CrowdStrike Falcon/NG SIEM).
  • Conceptual understanding of adversarial techniques targeting open-source ecosystems - including typosquatting, dependency confusion, registry abuse, and build-pipeline compromise - and the ability to identify relevant indicators.
  • Strong written and verbal English communication skills; able to explain moderately complex threat information clearly to peers and adjacent teams; comfortable escalating appropriately under moderate supervision.
  • Bachelor's degree in computer science, information security, or a related field preferred; entry-level security certified

Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.

Recommended for you based on this role

Similar stack
Same company
In your city
8+ year exp • Calgary
Go
JavaScript
Python
TypeScript
Python
Pydantic
Databases
pgvector
Pinecone
Qdrant
Weaviate
PostgreSQL
AI/ML
AI Agents
Claude
Claude Code
Copilot
Cursor
Function Calling
LangChain
LangGraph
LLM
Model Context Protocol
Prompt Engineering
Pydantic AI
RAG
Frontend
npm
DevOps
Azure
Bitbucket
CI/CD
Git
Platform Engineering
Apply
5+ year exp • Bachelor's Degree • Bengaluru
Python
DevOps
Ansible
AWS
Azure
Terraform
Apply
Sr. Server Engineer 7 days ago
5+ year exp • Bachelor's Degree • Bengaluru
PowerShell
Python
DevOps
Ansible
AWS
Azure
Hyper-V
KVM
OpenStack
Platform Engineering
Proxmox VE
Terraform
VMWare
Windows Server
Apply
5+ year exp • Master's Degree • Calgary
C#
C++
Go
JavaScript
Kotlin
Python
Rust
TypeScript
Cybersecurity
CWE
OWASP Top 10
Apply
9+ year exp • Bengaluru
C#
C++
PowerShell
C++
CMake
spdlog
TBB
DevOps
AWS
AWS Lambda
Azure
CI/CD
Docker
Git
GitLab CI
gRPC
WebSockets
Cybersecurity
OWASP Top 10
Apply
3+ year exp • Bachelor's Degree
C#
C++
Java
SQL
Databases
PostgreSQL
DevOps
Incident Management
Kubernetes
Marketing
Salesforce
Apply
6+ year exp • Bachelor's Degree • Bengaluru
Perl
Python
Ruby
DevOps
Ansible
AWS
CI/CD
Docker
Git
GitHub Actions
Jenkins
Kubernetes
QA
Postman
Robot Framework
Selenium
Apply
Software Engineer 2 20 days ago
3+ year exp • Bengaluru
Python
Python
Asyncio
Django
FastAPI
Flask
DevOps
AWS
AWS Lambda
Docker
Kubernetes
WebSockets
Cybersecurity
OWASP Top 10
QA
Pytest
Apply
7+ year exp • Belfast
DevOps
CI/CD
SLI/SLO/SLA
Cybersecurity
CVSS
EPSS
KEV
Apply
Senior SDET Engineer 20 days ago
6+ year exp • Bengaluru
Java
Python
AI/ML
LLM
Apply
Career impact
Discover how this job can transform your career
Get a personal career forecast for this job - salary uplift, next-level role, skill boost and a 3-year financial impact, all calculated from your profile.
Personal salary uplift vs. your current pay
Your 3-year career trajectory
Skills you will level up in this role
3-year financial impact in dollars
Create free account
Free forever • Less than a minute • No credit card

Work setup

Location
Belfast