At a Glance
- Tasks: Support threat data analysis and contribute to cybersecurity operations.
- Company: Join Black Duck Software, a leader in application security.
- Benefits: Competitive salary, inclusive culture, and opportunities for growth.
- Other info: Dynamic team environment with a focus on innovation and collaboration.
- Why this job: Make a real impact in cybersecurity while learning from industry experts.
- Qualifications: Experience in threat intelligence or related cybersecurity roles preferred.
The predicted salary is between 40000 - 55000 £ per year.
Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity.
Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior.
With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in Dev Sec Ops and throughout the software development life cycle.
The Threat Intelligence Engineer supports the research, collection, and analysis of threat data that enables Black Duck to detect and respond to threats targeting the enterprise and its software supply chain.
Working within the Threat Intelligence function under moderate supervision, you apply foundational knowledge of adversary tradecraft to assist in producing intelligence products, maintaining indicator pipelines, and contributing threat context to security workflows across the organization.
This role solves moderately complex problems within defined guidelines and policies, collaborates with senior engineers on intelligence operations, and supports broader cybersecurity and security operations functions as capacity allows.
Essential Functions/Responsibilities
- Assist with collection, processing, and analysis tasks across the intelligence requirements-to-dissemination workflow.
- Help maintain the intelligence requirements register under guidance from senior team members.
- Draft threat actor profiles, campaign summaries, and indicator packages for technical audiences; refine products based on senior engineer feedback.
- Ingest, validate, and score indicators of compromise (IOCs) from commercial feeds (e. g., Recorded Future), open-source, and internal sources.
- Support integration of IOC pipelines with SIEM and EDR platforms, including Sumo Logic and Crowd Strike Falcon/NG SIEM.
- Apply confidence scoring and structured formats (e. g., STIX 2.1) to intelligence artifacts; escalated data quality issues to senior team members.
- Monitor open-source package registries (npm, Py PI, Go, Maven, and others) and CI/CD pipeline integrity signals for indicators of adversarial activity including typosquatting, dependency confusion, and build-pipeline compromise.
- Contribute to the internal supply chain threat detection program by assisting with data collection, documentation, and detection logic testing.
- Assist broader cybersecurity and security operations functions—including CSIRT, Vulnerability Management, and PSIRT—with alert triage, threat research, and DLP investigation enrichment, as capacity allows.
- Support security investigations by researching threat actor behaviors, identifying relevant IOCs, and providing contextual summaries.
- Prepare threat intelligence summaries and briefing materials for internal consumers including CSIRT and Vulnerability Management.
- Identify opportunities for workflow improvements within own area and recommend changes to senior team members.
- Learn and follow applicable standards for intelligence data handling, sharing agreements, and governance; contribute to supporting documentation as directed.
- Other tasks and activities as assigned.
- Required Education/Experience & Skills
- Typically at least two (2) years of experience in threat intelligence, security operations, threat hunting, or a closely related cybersecurity role; demonstrated ability to solve moderately complex problems within established guidelines.
- Working familiarity with the intelligence production lifecycle, threat actor profiling concepts, and structured formats (e. g., STIX 2.1); ability to apply MITRE ATT&CK for basic TTP mapping.
- Practical experience working within enterprise SIEM or EDR environments; ability to run queries, review alerts, and support detection validation (current platforms include Sumo Logic and Crowd Strike Falcon/NG SIEM).
- Conceptual understanding of adversarial techniques targeting open-source ecosystems - including typosquatting, dependency confusion, registry abuse, and build-pipeline compromise - and the ability to identify relevant indicators.
- Strong written and verbal English communication skills; able to explain moderately complex threat information clearly to peers and adjacent teams; comfortable escalating appropriately under moderate supervision.
- Bachelor’s degree in computer science, information security, or a related field preferred; entry-level security certified.
Black Duck is an equal opportunity employer.
We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law.
Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.
#J-18808-Ljbffr
Threat Intelligence Engineer employer: Black Duck Software
At Black Duck Software, Inc., we pride ourselves on fostering a dynamic and inclusive work environment where innovation thrives. As a DevOps Engineer 2, you'll be part of a collaborative Cloud Operations team that values your expertise in Google Cloud Platform while offering ample opportunities for professional growth and development. With a commitment to employee well-being and a culture that embraces cutting-edge technology, Black Duck is an exceptional employer for those seeking meaningful and rewarding careers in application security.
StudySmarter Expert Advice🤫
We think this is how you could land Threat Intelligence Engineer
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Black Duck Software, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Black Duck Software
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Black Duck Software. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Threat Intelligence Engineer
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Black Duck Software insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Black Duck Software that you’re committed to staying ahead in the game.
How to prepare for a job interview at Black Duck Software
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Black Duck Software to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Black Duck Software.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.