
ThreatFabric · Amsterdam
WHO ARE WE? Want to reverse engineer mobile malware, build threat intelligence extraction pipelines, and help protect millions of banking customers from cyberc...
Want to reverse engineer mobile malware, build threat intelligence extraction pipelines, and help protect millions of banking
customers from cybercrime?
We help the world's leading banks stay ahead of fraudsters, scammers, and cybercriminals. Our technology protects millions of
users every day by detecting fraud, malware, and emerging attack techniques before damage is done. We do this by combining 15
years of extensive research with our own smart software.
At ThreatFabric, we're not just shaping the future of cybersecurity, we're defining it. With our headquarters in the vibrant city
of Amsterdam, ThreatFabric stands at the forefront of combating online fraud, mobile malware, and threat intelligence.
Position: Full-time | 40 hours per week
Location: Amsterdam, Netherlands | Hybrid (2–3 days office)
Salary Range: between 70.000,- and 90.000,- annually
About the job
As a Threat Research Engineer at ThreatFabric, you combine reverse engineering and software development skills to research threats
identified by our Threat Analysts and automate threat intelligence extraction. Your mission is to transform raw malware samples
into structured and actionable threat intelligence by creating, maintaining, and improving the tooling and analysis pipelines that
power ThreatFabric's threat intelligence capabilities.
You will play a key role in developing deobfuscation tooling, config extractors, unpackers, and scalable analysis pipelines.
Working closely with Threat Analysts within the MTI team, you will help automate intelligence extraction processes, improve
analysis workflows, and ensure ThreatFabric continues to scale its threat intelligence operations.
You will work on a combination of reverse engineering, malware analysis, research, automation, monitoring, and software
development, helping ThreatFabric stay ahead of emerging threats and provide high-quality threat intelligence to customers around
the world.
1. Performing reverse engineering of various threats, with a focus on mobile malware.
2. Identifying reliable ways to automate threat intelligence extraction from malware samples.
3. Supporting Threat Analysts in their research and investigation of threats.
4. Creating deobfuscation modules, configuration extractors, and unpackers based on your own reverse engineering efforts or
requests from Threat Analysts.
5. Designing, building, and maintaining reliable and scalable analysis pipelines.
6. Combining static analysis, dynamic analysis, and AI-powered assessments within analysis workflows.
7. Developing and maintaining threat intelligence sharing tools to support ThreatFabric customers.
8. Documenting and standardising existing and newly developed tooling to ensure maintainability by the wider team.
9. Monitoring the performance and reliability of analysis pipelines.
10. Identifying and communicating opportunities to improve analysis tooling and infrastructure.
11. Performing traffic analysis as part of malware investigations.
12. Using scripting techniques to perform decryption during malware analysis.
13. Analysing simple native code when required.
14. Contributing to the continuous improvement and scaling of ThreatFabric's threat intelligence extraction capabilities.
What We Offer
1. A 12-month employment contract with the intention to extend. Subject to mutual satisfaction, this may lead to a permanent
position.
2. A competitive salary that reflects your skills and experience with a salary range between 70.000,- to 90.000,- annually.
3. 25 holidays per year.
4. 8% holiday allowance (included in annual salary).
5. A Pension Scheme.
6. A stimulating and supportive work environment that encourages growth and development.
7. An annual personal Growth and Development budget.
8. The opportunity to make a meaningful impact in a rapidly growing tech company.
9. Flexible Remote / Hybrid work-from-home options to promote work-life balance.
10. Flexible working hours.
11. Active ThreatFabric events and FitFabric bootcamps.
12. Active knowledge-sharing huddles.
Skills & Competencies
Technical Skills
Analytical Skills
Learning Ability & Eagerness to Learn
Communication & Documentation
Continuous Improvement
Information Security, Business Continuity & Privacy
Protecting people, not just systems
At ThreatFabric, your work has a direct impact on the lives of millions of people. Every day, fraudsters, scammers, and
cybercriminals target individuals and financial institutions around the world. The technology we build helps stop these attacks
before they cause harm, protecting not only money, but also trust, confidence, and peace of mind.
Unlike many technology companies, the problems we solve are real, complex, and constantly evolving. You'll work on challenges that
make a measurable difference and see your contributions translated into solutions used by some of the world's leading financial
institutions.
Work alongside experts who love what they do
ThreatFabric brings together security researchers, engineers, data scientists, threat intelligence specialists, and fraud experts
from around the globe. We're passionate about our craft and continuously challenge each other to think differently, improve our
solutions, and stay ahead of emerging threats.
Learning is part of our DNA. Whether through knowledge-sharing sessions, technical discussions, mentoring, or simply collaborating
with highly experienced colleagues, you'll be surrounded by people who are eager to learn and equally eager to share their
expertise.
Why people stay
People join ThreatFabric because they're excited by the technology and the mission. They stay because of the people. We celebrate
successes together, learn from challenges together, and create an environment where talented individuals can do the best work of
their careers while enjoying the journey along the way.
Interested?
Looking for your next challenge? We'd love to hear your story. Apply through the Personio link below and we'll be in touch
shortly. Whether you're ready to make a move or simply want to explore the opportunity further, we're happy to answer your
questions and help you determine if ThreatFabric is the right fit for you.
What's next?
So, you've hit send - what happens now? First, we'll do a screening to ensure we're a good match. If all goes well, you'll be
invited for an initial chat with us. Then, there's a second interview, and we may include an assessment to better understand your
skills and approach to threat research. Ready to take the plunge?
Please note: Pre-employment screening is part of our selection process. We do not accept unsolicited resumes from recruiters or
employment agencies.
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. Snowflake has developed a world class cloud data platform that is effective, affordable and accessible to all data users. As we continue to scale globally, we are investing in security capabilities that help us better understand, anticipate, and mitigate threats targeting Snowflake, our customers, and our ecosystem. We are looking for a Principal Security Engineer - Threat Intelligence who will help shape the next phase of Snowflake’s Threat Intelligence program and extend the reach and impact of Threat Intelligence across Snowflake. This role will combine deep intelligence expertise with strong engineering and program leadership skills, with AI and automation as core primitives in how we collect, analyze, prioritize, and operationalize intelligence. The ideal candidate will help Snowflake leadership and security stakeholders make informed, risk-based, and data-driven decisions based on actionable threat intelligence. You will identify and track threat actors targeting cloud-native environments such as Snowflake, translate intelligence into concrete defensive outcomes, and build scalable approaches that improve how intelligence is delivered across the company. This is a principal-level individual contributor role for someone who can operate strategically and technically: driving program maturity, building durable partnerships across Security and Engineering, and engineering AI-assisted workflows that help us move faster without sacrificing quality. WHAT YOU NEED: * Deep experience in threat intelligence, with strong background in several of: adversary intelligence, intrusion intelligence, supply-chain intelligence, identity intelligence, domain intelligence, and threat-informed defense. * Strong understanding of today’s threat actor ecosystem, including nation-state actors, criminal organizations, ransomware groups, fraud ecosystems, and the platforms and communities that enable them. * Demonstrated ability to operationalize threat intelligence and influence security priorities in partnership with detection, incident response, product security, cloud security, anti-abuse, and other stakeholders. * Strong engineering skills, including experience writing code in high-level languages such as Python or Go, building automations, and working with data-heavy security workflows. * Experience building or driving AI-assisted workflows for intelligence analysis, research triage, summarization, collection, prioritization, or investigative support, and good judgment about where AI adds value versus where human analysis is required. * Ability to research threat actors’ TTPs, infrastructure, targets, and objectives, and map those risks to Snowflake’s product, enterprise, and customer environment. * Experience with OSINT tools, data sources, investigative methodologies, and intelligence reporting for technical and executive audiences. * Strong understanding of threat hunting and threat detection methodologies, and the ability to turn intelligence into hunts, detection opportunities, and control recommendations. * A risk-based approach to security, with the ability to prioritize work based on business impact and evolving threat conditions. * A humble, team-oriented mindset with a bias toward collaboration, execution, and raising the bar for the broader team. WHAT YOU WILL DO: * Help define and mature the strategy for Threat Intelligence at Snowflake, including where the program should invest in people, processes, engineering, and AI-enabled capabilities. * Identify, profile, and track threat actors targeting Snowflake, our customers, partners, and ecosystem, and translate that intelligence into relevant, actionable outcomes. * Operationalize threat intelligence to help prioritize security initiatives and drive action with the relevant security teams and stakeholders. * Produce high-quality intelligence reports, assessments, briefs, and leadership-ready communications based on external events, internal requirements, and proactive research. * Engineer solutions that improve the efficiency, scale, and impact of the Threat Intelligence program, including automations, collection pipelines, enrichment workflows, and analyst tooling. * Build and improve AI-assisted intelligence workflows for tasks such as report triage, signal enrichment, summarization, vendor/customer monitoring, and threat-informed hunts, with strong measurement and quality.. * Partner closely with Threat Detection, Incident Response, and other security teams to convert intelligence into detections, threat hunts, investigative pivots, and control recommendations. * Monitor alerts, intelligence feeds, vendor reporting, and external developments for threat events that may affect Snowflake. * Drive standards for how intelligence is curated, evaluated, delivered, and measured so the program remains high-signal, timely, and scalable. * Mentor other engineers and analysts by raising the team’s technical depth, analytic rigor, and operational maturity. MINIMUM QUALIFICATIONS: * Significant experience in threat intelligence, cyber threat research, intelligence engineering, or closely related security disciplines. * Experience researching and tracking sophisticated threat actors targeting cloud-native and SaaS environments. * Experience writing code in a high-level programming language such as Python or Go and using code to automate manual workflows or analyze security data at scale. * Experience handling data programmatically using tools such as SQL and Python, ideally against large datasets relevant to security analytics or intelligence workflows. * Experience collaborating across multiple security functions and communicating effectively with technical stakeholders and leadership. * Strong understanding of enterprise security controls, threat hunting, and detection methodologies. * Experience with one or more major cloud providers (AWS, Azure, GCP) and familiarity with the risks that impact cloud and SaaS environments. PREFERRED QUALIFICATIONS: * Experience leading or materially shaping a Threat Intelligence program at scale. * Experience building AI/ML-assisted security workflows or evaluating AI systems for security use cases. * Experience with data engineering, workflow orchestration, or production-grade systems that support intelligence or security operations at scale. * Experience with Snowflake or equivalent cloud data platforms for large-scale analysis and investigative workflows. * Experience presenting externally, publishing research, or demonstrating thought leadership in the security space. * Experience building capabilities that support intelligence-driven detection, hunting, or response at a global scale. WHY YOU SHOULD WORK WITH US: * We are laser focused on doing security better, and we do not tolerate the status quo. * We have strong demand from our customers and strong support from the business for security, giving us meaningful runway to build next-generation capabilities. * We are a great team with a diverse set of backgrounds and skills, and we care deeply about impact, collaboration, and execution. * You will help solve security problems at global scale, leveraging Snowflake’s platform and modern AI capabilities to raise the bar for defenders. * The opportunity for impact on Snowflake, our customers, and the broader security ecosystem is enormous. ABOUT THE THREAT INTELLIGENCE TEAM: The Threat Intelligence team at Snowflake operates with a vision of proactively detecting threats based on risk and data-driven decisions. Our mission is to proactively identify relevant threat actors and activity through intelligence, and to translate that intelligence into capabilities and decisions that help Snowflake identify threats early and reduce risk to the business. Every Snowflake employee is expected to follow the company’s confidentiality and security standards for handling sensitive data. Snowflake employees must abide by the company’s data security plan as an essential part of their duties. It is every employee’s duty to keep customer information secure and confidential. The application window is expected to be open until June 10, 2026. This opportunity will remain posted based on business needs, which may be before or after the specified date. Snowflake is growing fast, and we’re scaling our team to help enable and accelerate our growth. We are looking for people who share our values, challenge ordinary thinking, and push the pace of innovation while building a future for themselves and Snowflake. How do you want to make your impact? For jobs located in the United States, please visit the job posting on the Snowflake Careers Site for salary and benefits information: careers.snowflake.com
About Zscaler Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the world’s largest security data lake to power our cloud-native Zero Trust Exchange platform. This innovation protects our customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Here, impact in your role matters more than title and trust is built on results. We say, impact over activity. We seek innovators who actively use AI to amplify their impact and who thrive in an environment where we leverage intelligent systems to stay ahead of evolving threats. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership, and accountability. We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges, and want to be part of the team that’s helping to secure the AI age, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity. Role We are looking for a Staff Detection Engineer to join our team. This is a Hybrid (Pune, India) role, reporting to the Senior Manager in the Threat Hunting department. You will combine threat research and engineering expertise to build the next generation of detections across AWS and cloud infrastructures. By leveraging big data platforms like Hadoop and Athena, you will design scalable hunting logic and automated pipelines to defend our global footprint and enhance threat visibility. What you’ll do (Role Expectations) * Combine threat research and engineering expertise to develop advanced detections and hunting logic using Python and AWS infrastructure * Design, scale, and maintain engineering projects, including GitLab pipelines and repeatable deployment steps to improve hunting efficiency * Develop YAML-based detections and SIGMA-like rule technologies while migrating existing hunting detections to next-generation systems * Utilize data platforms like Hadoop, Athena, and data lakes to monitor and test new intelligence sources for enhanced threat visibility * Independently write detections and playbooks while supporting operational demands, including weekend night shifts and on-call rotations Who You Are (Success Profile) * You thrive in ambiguity. You're comfortable building the path as you walk it. You thrive in a dynamic environment, seeing ambiguity not as a hindrance, but as the raw material to build something meaningful. * You act like an owner. Your passion for the mission fuels your bias for action. You operate with integrity because you genuinely care about the outcome. True ownership involves leveraging dynamic range: the ability to navigate seamlessly between high-level strategy and hands-on execution. * You are a problem-solver. You love running towards the challenges because you are laser-focused on finding the solution, knowing that solving the hard problems delivers the biggest impact. * You are a high-trust collaborator. You are ambitious for the team, not just yourself. You embrace our challenge culture by giving and receiving ongoing feedback—knowing that candor delivered with clarity and respect is the truest form of teamwork and the fastest way to earn trust. * You are a learner. You have a true growth mindset and are obsessed with your own development, actively seeking feedback to become a better partner and a stronger teammate. You love what you do and you do it with purpose. What We’re Looking for (Minimum Qualifications) * Foundational understanding of AI/ML technologies and experience leveraging, securing, or positioning AI-driven solutions to optimize outcomes within your functional domain * Proven experience in detection engineering, threat hunting, security operations, or malware analysis * Hands-on experience developing and implementing detection rules in SIEM tools such as Splunk, Microsoft Sentinel, or ElasticSearch * Deep familiarity with the MITRE ATT&CK framework and experience translating TTPs into actionable detection logic * Bachelor’s or graduate degree in Computer Science, Engineering, or a related discipline, or equivalent security industry experience, combined with the ability to work flexible schedules, including weekend night shifts, to meet global operational demands What Will Make You Stand Out (Preferred Qualifications) * Experience leveraging AI/ML models, large language models (LLMs), or natural language processing (NLP) to automate threat intelligence synthesis, accelerate detection rule generation, or build predictive anomaly detection models within big data systems * Significant experience as a Senior Detection Engineer leading complex detection strategies and mentoring junior team members * Expertise in validating detection logic, performing root cause analysis of failures, and delivering platform improvement recommendations, paired with advanced scripting and automation skills in Python for developing and managing complex detection infrastructure #LI-Hybrid #LI-PM5 At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure. Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including: * Various health plans * Time off plans for vacation and sick time * Parental leave options * Retirement options * Education reimbursement * In-office perks, and more! Learn more about Zscaler's hybrid working model and benefits here. By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines. Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link. Pay Transparency Zscaler complies with all applicable federal, state, and local pay transparency rules. Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.
SUMMARY OF THE ROLE: As a Security Research Engineer at Maze, you'll be at the forefront of defining what constitutes real security risk in the age of AI-powered vulnerability detection. This is a unique opportunity to join our growing security research team at a well-funded startup building at the intersection of generative AI and cybersecurity, where your security expertise directly shapes how our AI models understand and prioritize cloud security threats. You'll spend the majority of your time as the expert human-in-the-loop, analyzing cloud vulnerability findings from our AI systems, conducting deep research to validate and contextualize threats, and creating the authoritative labels that train our models to distinguish critical risks from noise. Working alongside other security researchers, you'll help scale our labeling operations while providing critical input into product development decisions based on real-world threat patterns you discover. This role is perfect for a security researcher who wants to pioneer the future of AI-assisted threat detection, loves diving deep into cloud security vulnerabilities, and wants to see their security insights amplified through cutting-edge technology while contributing to a growing team. YOUR CONTRIBUTIONS TO OUR JOURNEY: * Scale Expert Data Labeling Operations: Lead high-volume vulnerability labeling and validation work as the authoritative voice on threat severity, reviewing and categorizing cloud security findings from our AI models to create the high-quality training data that powers our platform * Drive Product Development Through Research Insights: Translate patterns and insights from your labeling and research work into actionable product improvements, working directly with engineering and product teams to enhance detection capabilities and user experience * Collaborate with Security Research Team: Work closely with fellow Security Research Engineers to maintain consistency in labeling standards, share research findings, and collectively improve our vulnerability assessment methodologies * Deep Vulnerability Research: Conduct comprehensive research into cloud vulnerabilities affecting EC2 images, Docker containers, and cloud infrastructure, investigating true/false positives, analyzing business impact, and building proof-of-concepts to validate threat scenarios * Enhance AI Model Accuracy: Provide expert feedback through our labeling tools that improves our AI models' understanding of vulnerability context, helping them learn to prioritize threats like a seasoned security researcher * Technical Investigation and Analysis: Create detailed technical writeups about exploitation techniques, attack vectors, and remediation strategies for cloud vulnerabilities, turning complex security research into actionable intelligence * Leverage External Security Intelligence: Integrate insights from CVE databases, security advisory feeds, and threat intelligence sources to enrich vulnerability findings with broader context and emerging threat patterns * Contribute to Thought Leadership: Support our external presence through technical blog posts, security videos/podcasts, and occasional conference presentations, sharing insights from your research WHAT YOU NEED TO BE SUCCESSFUL: * Security Research Expertise: 5+ years of hands-on security experience with proven vulnerability research background, comfortable investigating complex security issues and building proof-of-concepts to validate findings * Cloud Security Mastery: Deep knowledge of AWS security, cloud infrastructure vulnerabilities, container security, and cloud-native attack vectors, with hands-on experience securing cloud environments at scale * Technical Investigation Skills: Strong coding and scripting abilities (Python, Go, or similar) for automating research tasks, building validation tools, and creating proof-of-concept exploits * Analytical Excellence: Proven ability to analyze complex security data, distinguish between critical threats and false positives, and communicate technical findings to both technical and business audiences * Product Mindset: Experience translating security insights into product requirements, with ability to identify patterns across vulnerabilities that inform strategic product decisions * External Intelligence Integration: Experience working with vulnerability databases, security advisory feeds, and threat intelligence sources to contextualize and prioritize security findings * Collaborative Mindset: Strong communication skills and ability to work effectively with security research peers, AI/ML teams, and product stakeholders, translating security domain knowledge into actionable improvements * High-Volume Execution: Comfort with systematic labeling work while maintaining accuracy and attention to detail, balancing speed with quality in fast-paced environments * Nice to haves: * Experience with AI/ML security or working with AI-generated security findings * Background at security tooling companies or building security products * Expertise in specific vulnerability research methodologies and frameworks * Open source contributions to security tools or research projects * Previous content creation experience in security (blogs, talks, research papers) * Industry certifications (CISSP, OSCP, AWS Security, etc.) WHY JOIN US: * Ambitious Challenge: We're using generative AI (LLMs and agents) to solve some of the most pressing challenges in cloud security today. You'll be defining how AI understands and prioritizes vulnerabilities, working at the cutting edge of AI-powered threat detection. * Expert Team: We are a team of hands-on leaders with experience in Big Tech and Scale-ups. Our team has been part of the leadership teams behind multiple acquisitions and an IPO. * Growing Security Research Function: Join a collaborative security research team where you'll work alongside other experts, share insights, and collectively shape how our AI platform understands security threats at scale. * Impactful Work: Your security research and labeling work will directly improve how thousands of organizations understand and respond to cloud security threats, scaling expert security knowledge through AI to protect the entire ecosystem. * Product Influence: Your day-to-day research insights will directly influence product strategy and development, giving you a voice in building the next generation of AI-powered security tools. * Pioneer AI-Native Security: Help establish the gold standard for AI-assisted vulnerability research, defining how human security expertise enhances machine learning models in the cybersecurity domain.