Responsibilities
- Design, build, maintain, and scale static and dynamic file analysis pipelines.
- Maintain and optimize YARA rule sets and tooling for testing, performance, and false-positive management.
- Operate and extend real-time threat indicator enrichment, metadata extraction, scanning, and enrichment systems.
- Build threat graph intelligence systems modeling relationships among indicators, malware, infrastructure, and actors.
- Design and maintain sandboxing and detonation capabilities with behavioral telemetry and safe execution environments.
- Build ingestion and normalization pipelines connecting internal Censys scan data with external threat intelligence feeds.
- Instrument systems for reliability and observability through logging, monitoring, alerting, and SLAs.
- Partner with threat research and detection engineering teams to translate analytical needs into scalable systems.
- Maintain secure handling and isolation practices for malicious samples and analysis environments.
- Document architecture, runbooks, and operational procedures for owned systems.
Requirements
- Bachelor’s degree in Computer Science, Engineering, or equivalent practical experience.
- At least 6 years of experience building security data pipelines, detection engineering systems, or threat intelligence platforms.
- Experience with Synapse or comparable graph-based threat intelligence platforms, including graph data modeling.
- Strong programming skills in Python and/or Go.
- Working knowledge of static and dynamic malware analysis tooling and pipelines, including disassemblers, sandboxes, and debuggers.
- Experience with distributed data pipelines, message queues, and data stores.
- Familiarity with Docker and Kubernetes for isolated execution environments.
- Experience designing and operating highly available production systems on AWS, GCP, or Azure.
- Demonstrated use of LLM-based coding harnesses and agent-based development workflows such as Claude Code or Copilot.
- Experien
📌 Systems Engineer (España)
🏢 Censys
📍 España