Threat Intelligence Engineer, Cybersecurity & SIEM
Overview
Threat Intelligence Engineer at Take-Two Interactive, defending global gaming systems. You will operate the cyber threat intelligence (CTI) program, manage threat feeds, and parse IOCs to protect Rockstar Games, 2K, and Zynga. You'll partner with the GSOC, Detection Engineering, and Incident Response teams to integrate intelligence into SIEM, EDR, and firewalls. This role offers direct impact on security posture in a high-profile entertainment company.
What You'll Do6
- 1Operate daily CTI program: manage threat feeds, parse IOCs, and ensure data quality across platforms.
- 2Analyze emerging threats and adversary TTPs to engineer detection and prevention mechanisms.
- 3Collaborate with GSOC, Detection Engineering, and IR to ingest and operationalize intelligence into SIEM, EDR, and firewalls.
- 4Build and maintain API integrations, scripts, and playbooks to automate indicator ingestion, correlation, and dissemination.
- 5Deploy, configure, maintain, and tune Threat Intelligence Platforms (TIP) and related security tools.
- 6Generate timely intelligence alerts, briefs, and tactical reports for technical teams with context on active threats.
Requirements10
- 12-4 years in cybersecurity, with 1-2 years focused on threat intelligence, security engineering, or SOC operations.
- 2Solid understanding of network fundamentals, OS internals, common attack vectors, and the threat landscape.
- 3Hands-on experience with API integrations, data formats (JSON, XML, STIX/TAXII), and systems integration.
- 4Analytical skills to draw conclusions from multiple sources (OSINT, reports, logs) and identify malicious activity.
- 5Familiarity with frameworks like MITRE ATT&CK and Cyber Kill Chain.
- 6Strong written and verbal communication for documenting processes and communicating threat findings.
- 7Hands-on experience with SIEM, TIP, or EDR solutions.
- 8Scripting skills in Python, PowerShell, or Bash (preferred).
- 9Relevant certifications such as CompTIA Security+, CySA+, GIAC (GSEC, GCTI) (preferred).
- 10Cloud experience with AWS, Azure, or GCP (preferred).
Salary Insight
Salary not disclosed in listing
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
Amazon.com Services LLC
VerifiedSecurity Intelligence Engineer Incident Response Threat Intelligence ACTI
Threat Intelligence Engineer leading proactive defense against advanced cyber threats for Amazon employees and assets. This role drives incident response, develops analytic techniques, and collaborates across teams to mitigate malicious activity. Candidates must analyze large datasets, create automation, and contribute to threat intelligence.

TexcelVision Inc.
VerifiedOnsite Cybersecurity Threat Intelligence Analyst Austin TX
Lead the development and execution of threat intelligence programs that protect enterprise assets. Own the end-to-end pipeline from data ingestion to actionable insights. Drive security posture through proactive analysis and stakeholder collaboration.

Belcan, LLC
VerifiedCybersecurity Operations & Communications Lead
Own the security operations and communications strategy for a global enterprise, coordinating incident response across SIEM, SOAR, and EDR platforms. You lead a team of analysts, manage threat intelligence feeds, and craft executive-level briefings. This role sits at the intersection of technical operations and stakeholder communication, reporting directly to the CISO. You will drive the adoption of MITRE ATT&CK framework and NIST guidelines, shaping the organization's cyber resilience.
Zoox
VerifiedSenior Information Security Engineer Detection Automation AI Zoox
We seek a Senior Information Security Engineer who designs detection systems and automates workflows. You will architect SIEM logic map detections to MITRE ATT&CK reduce false positives and build SOAR playbooks. Implement LLM‑powered triage pipelines and act as senior escalation point for incidents across AWS and on‑premise environments. This role drives security operations as code and shapes a fast‑moving team.
Mercor
VerifiedSecurity Operations Expert, AI Trainer & Threat Detection
Security Operations Expert builds realistic cybersecurity scenarios for AI training. You design incident response, vulnerability management, and compliance tasks that distinguish expert judgment from rote recall. Collaborate with a team at Mercor connecting elite talent with AI research labs. Own the challenge from first draft to final rubric, shaping how models learn security thinking.
CrowdStrike, Inc.
VerifiedEngineer II Threat Detection - Windows (Hybrid)
CrowdStrike seeks an Engineer II to lead threat detection on Windows endpoints. This hybrid role involves analyzing emerging threats and authoring behavioral detection rules. You will collaborate across teams to mitigate intrusions and improve detection coverage at scale.