← Back to jobs

Intime Infotech Inc Logo
Threat Intelligence Automation Engineer

Intime Infotech Inc

 

Malvern, PA, USA

Posted On: 30+ days ago
Experience: 4+ years
Availability: Hybrid
Openings: 1
Category: Automation Engineer
Tenure: Contract - Corp-to-Corp
Related Jobs

No related jobs found

Description

 

 

Day-to-Day Responsibilities

  • Design, develop, and maintain Python-based automation workflows supporting threat intelligence operations.
  • Build integrations between the Threat Intelligence Platform (TIP), SOAR, SIEM, EDR, cloud platforms, and other security technologies.
  • Develop automated pipelines for collecting, enriching, validating, scoring, deduplicating, and distributing Indicators of Compromise (IOCs).
  • Integrate commercial, open-source, government, vendor, and internal threat intelligence feeds into the organization's intelligence platform.
  • Automate the delivery of intelligence into security tools to improve detection, response, and prevention capabilities.
  • Serve as a technical owner for the Threat Intelligence Platform, driving platform enhancements, integrations, data quality, and workflow optimization.
  • Build automation that correlates vulnerability intelligence with exploit activity, threat actors, malware campaigns, and internal asset exposure.
  • Partner with Incident Response, Threat Hunting, Detection Engineering, Vulnerability Management, and Security Operations teams to translate operational needs into scalable engineering solutions.
  • Develop and maintain data ingestion, normalization, transformation, and enrichment processes for structured and unstructured security data.
  • Identify opportunities to eliminate manual processes through automation and orchestration.
  • Evaluate emerging technologies, including AI-enabled capabilities, to improve threat intelligence operations.
  • Create metrics and reporting that measure automation effectiveness, analyst efficiency, and intelligence delivery.

 

Must-Have Qualifications

  • Min of 4+ years of cybersecurity experience with at least 1 year focused on one or more of the following:
    • Security Engineering
    • Security Automation
    • DevSecOps
    • Software Development
  • Strong Python development skills with experience building automation solutions.
  • Experience integrating applications using REST APIs, webhooks, and modern API-based architectures.
  • Experience working with structured and unstructured security data (JSON, XML, CSV).
  • Hands-on experience developing automation workflows for cybersecurity operations.
  • Understanding of threat intelligence concepts, operational workflows, and intelligence lifecycle.
  • Experience with Threat Intelligence Platforms (TIPs) or similar security platforms.
  • Knowledge of threat intelligence standards such as STIX and TAXII.
  • Experience integrating security technologies such as SIEM, SOAR, EDR, email security, cloud security, or network security platforms.
  • Strong collaboration skills with cross-functional cybersecurity teams.

 

Nice-to-Have Qualifications

  • Experience with vulnerability intelligence and vulnerability management automation.
  • Experience integrating data from sources such as NVD, CISA KEV, vendor advisories, ISACs, or commercial threat intelligence providers.
  • Experience correlating vulnerabilities with threat actors, malware, exploit intelligence, and enterprise asset data.
  • Experience with cloud security environments (AWS, Azure, or GCP).
  • Experience with data engineering, ETL pipelines, or large-scale data ingestion.
  • Familiarity with detection engineering, threat hunting, or incident response workflows.
  • Experience implementing orchestration and workflow automation within SOAR platforms.
  • Exposure to AI/ML technologies or generative AI used to improve security operations and threat intelligence.

Experience measuring automation effectiveness through operational metrics and reporting

Education

Bachelor's degree

Related Jobs

No related jobs found

← Back to jobs