Threat Intelligence Engineer

Threat Intelligence Engineer

Entry level 45000 - 55000 £ / year (est.) Home office (partial)
Blackduck

At a Glance

  • Tasks: Support threat data research and analysis to enhance software security.
  • Company: Join Black Duck Software, a leader in application security.
  • Benefits: Competitive salary, inclusive culture, and opportunities for growth.
  • Other info: Dynamic team environment with a focus on innovation and collaboration.
  • Why this job: Make a real impact in cybersecurity while learning from industry experts.
  • Qualifications: Experience in threat intelligence or related cybersecurity roles preferred.

The predicted salary is between 45000 - 55000 £ per year.

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.

The Threat Intelligence Engineer supports the research, collection, and analysis of threat data that enables Black Duck to detect and respond to threats targeting the enterprise and its software supply chain. Working within the Threat Intelligence function under moderate supervision, you apply foundational knowledge of adversary tradecraft to assist in producing intelligence products, maintaining indicator pipelines, and contributing threat context to security workflows across the organization. This role solves moderately complex problems within defined guidelines and policies, collaborates with senior engineers on intelligence operations, and supports broader cybersecurity and security operations functions as capacity allows.

Essential Functions/Responsibilities

  • Assist with collection, processing, and analysis tasks across the intelligence requirements-to-dissemination workflow.
  • Help maintain the intelligence requirements register under guidance from senior team members.
  • Draft threat actor profiles, campaign summaries, and indicator packages for technical audiences; refine products based on senior engineer feedback.
  • Ingest, validate, and score indicators of compromise (IOCs) from commercial feeds (e.g., Recorded Future), open-source, and internal sources.
  • Support integration of IOC pipelines with SIEM and EDR platforms, including Sumo Logic and CrowdStrike Falcon/NG SIEM.
  • Apply confidence scoring and structured formats (e.g., STIX 2.1) to intelligence artifacts; elevate data quality issues to senior team members.
  • Monitor open-source package registries (npm, PyPI, Go, Maven, and others) and CI/CD pipeline integrity signals for indicators of adversarial activity including typosquatting, dependency confusion, and build-pipeline compromise.
  • Contribute to the internal supply chain threat detection program by assisting with data collection, documentation, and detection logic testing.
  • Assist broader cybersecurity and security operations functions — including CSIRT, Vulnerability Management, and PSIRT — with alert triage, threat research, and DLP investigation enrichment, as capacity allows.
  • Support security investigations by researching threat actor behaviors, identifying relevant IOCs, and providing contextual summaries.
  • Prepare threat intelligence summaries and briefing materials for internal consumers including CSIRT and Vulnerability Management.
  • Identify opportunities for workflow improvements within own area and recommend changes to senior team members.
  • Learn and follow applicable standards for intelligence data handling, sharing agreements, and governance; contribute to supporting documentation as directed.
  • Other tasks and activities as assigned.

Required Education/Experience & Skills

  • Typically at least two (2) years of experience in threat intelligence, security operations, threat hunting, or a closely related cybersecurity role; demonstrated ability to solve moderately complex problems within established guidelines.
  • Working familiarity with the intelligence production lifecycle, threat actor profiling concepts, and structured formats (e.g., STIX 2.1); ability to apply MITRE ATT&CK for basic TTP mapping.
  • Practical experience working within enterprise SIEM or EDR environments; ability to run queries, review alerts, and support detection validation (current platforms include Sumo Logic and CrowdStrike Falcon/NG SIEM).
  • Conceptual understanding of adversarial techniques targeting open-source ecosystems — including typosquatting, dependency confusion, registry abuse, and build-pipeline compromise — and the ability to identify relevant indicators.
  • Strong written and verbal English communication skills; able to explain moderately complex threat information clearly to peers and adjacent teams; comfortable escalating appropriately under moderate supervision.
  • Bachelor's degree in computer science, information security, or a related field preferred; entry-level security certified

Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.

#J-18808-Ljbffr

Threat Intelligence Engineer employer: Blackduck

At Black Duck, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration. Our Senior Vulnerability Manager role not only provides the opportunity to lead critical security initiatives but also encourages professional growth through mentorship and cross-team collaboration. With a commitment to diversity and inclusion, we ensure that every employee feels valued and empowered to make a meaningful impact in a supportive environment.

Blackduck

Contact Details:

Blackduck Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Threat Intelligence Engineer

Get Involved in the Cybersecurity Community

Dive into local and online cybersecurity meetups or forums. Engage with communities on platforms like Reddit or Discord, which often have dedicated channels for job opportunities and entry-level tips. Making yourself visible here can open doors we didn't even know existed!

Show Off Those Skills

Set up a GitHub profile where you can showcase any projects or contributions you’ve made, even if they’re just personal experiments. Potential employers love to see our work in action, and this is a great way to catch the eye of companies like Blackduck while we’re still building our experience.

Leverage Online Courses & Certifications

Consider taking some recognised cybersecurity certifications, like CompTIA Security+ or Certified Ethical Hacker. These badges give us an edge and show our commitment to the field. Plus, many courses have job boards and networking opportunities that can lead to our first gig!

Apply Early and Often

Entry-level roles in cybersecurity can fill up quickly, so keep an eye on our website for open positions at Blackduck. We should be ready to apply as soon as we see a role pop up. Tailor our applications to highlight relevant skills like problem-solving and attention to detail – these can set us apart!

We think you need these skills to ace Threat Intelligence Engineer

Threat Intelligence
Security Operations
Threat Hunting
Adversary Tradecraft
Intelligence Production Lifecycle
Threat Actor Profiling
STIX 2.1

Some tips for your application 🫡

Show off your technical skills:In the cybersecurity field, we love to see your technical know-how right from the get-go. Include any relevant coursework, certifications (like CompTIA Security+ or CEH), and tools you're familiar with. If you've dabbled in security protocols or have any hands-on experience with firewalls or threat analysis, make sure to highlight that!

Demonstrate your passion for cybersecurity:A cover letter is your chance to show your enthusiasm for cybersecurity—don’t hold back! Talk about why you’re excited about this career path, any personal projects you've been involved with, or security challenges you’ve taken on. It’s all about showing Blackduck that you’re eager to learn and contribute.

Include relevant extracurricular activities:In entry-level applications, we appreciate seeing how you’ve engaged with the cybersecurity community. Mention any clubs, competitions (like Capture The Flag), or volunteer work related to cybersecurity. This will give us insight into your dedication to growing your skills beyond academic learning!

Keep it concise and tailored:We get it—writing about yourself can be tough. But for entry-level roles like Threat Intelligence Engineer at Blackduck, we're looking for clarity and focus. Tailor your CV and application materials to highlight only what matters for this role. Avoid fluff and get straight to your strengths in the context of cybersecurity!

How to prepare for a job interview at Blackduck

Know Your Cybersecurity Basics

Make sure you’re clued up on the essential concepts of cybersecurity, like encryption, firewalls, and malware. For an entry-level role like Threat Intelligence Engineer at Blackduck, they might ask you practical questions to test your understanding of these topics, so brush up on the basics and maybe even run through some scenarios.

Familiarise Yourself with Tools

You’ll likely be working with various cybersecurity tools and platforms, so get comfortable with common ones like Wireshark and Metasploit. Mention any hands-on experience you have with these tools during your interview, as it shows you’ve taken the initiative to learn and apply your knowledge, which is key for an entry-level position.

Show Your Passion for Learning

Since this is an entry-level position, employers at Blackduck will want to see your eagerness to learn. Prepare to discuss any certifications or online courses you've completed, as well as how you stay updated on the latest threats and trends in cybersecurity. This demonstrates your commitment to growing in the field.

Prepare for Scenario-Based Questions

Expect some scenario-based questions during your interview. These might include how you'd respond to a phishing attempt or securing a network. Think through a few examples beforehand, so you can showcase your problem-solving skills and thought process, which are critical in cybersecurity.