Taro Logo

Software Engineer, Threat Engine

Todyl provides integrated cybersecurity solutions focusing on threat management, detection, and intelligence capabilities.
Security
Mid-Level Software Engineer
In-Person
Cybersecurity
This job posting may no longer be active. You may be interested in these related jobs instead:
Security Engineer II - AMZ9442063

Security Engineer II position at AWS focusing on information security, penetration testing, and security policy compliance in Arlington, VA.

Software Security Engineer

Software Security Engineer position at PayPal focusing on cryptography services and security software development using Java and Node.js in a hybrid work environment.

Software Engineer

Software Engineer position at Coinbase focusing on security platform engineering, building and maintaining critical security infrastructure using Golang and modern cloud technologies.

Software Engineer

Software Engineer position at Coinbase focusing on security platform engineering, building and maintaining critical security infrastructure using Golang.

Cybersecurity Developer - Assistant Vice President 2

Cybersecurity Developer position at Assistant Vice President level at State Street, focusing on security software development and implementation.

Description For Software Engineer, Threat Engine

Todyl is seeking a Software Engineer for their Threat Engine team to join their SecOps division, which forms the core of their detection, analytics, and threat intelligence capabilities. This role is central to delivering a pioneering, integrated pipeline for end-to-end threat management.

The position offers an opportunity to work on solutions that stand out in the industry due to their performance, scalability, and adaptability. You'll be part of a team responsible for providing Todyl customers with robust, real-time protection through a unified approach that combines detection, threat hunting, security analysis, and threat intelligence within a single architecture.

As a Software Engineer in the Threat Engine team, you'll be working with cutting-edge technologies including Golang, JavaScript, and Python, while handling complex systems involving Kafka, RabbitMQ, and various database technologies. You'll collaborate closely with Data Engineering, Threat Intel, and Machine Learning teams to build state-of-the-art enrichments and detections.

The ideal candidate should have strong experience in API development, messaging systems, and database engines, along with a solid understanding of security concepts and detection strategies. You'll be working on high-performance, low-latency computations and designing scalable backend architectures that support multiple integration points.

This role offers the opportunity to work on challenging problems in cybersecurity, contributing to a platform that sets new standards in threat response efficacy. You'll be part of a team that enables Todyl to safeguard customers at scale, making a real impact in the cybersecurity landscape. The position is based in Atlanta, GA, and offers a chance to work with a company that values innovation and technical excellence in cybersecurity.

Last updated 5 months ago

Responsibilities For Software Engineer, Threat Engine

  • Extend the internal platform to extend Todyl's threat management platform that allows integrations/extensions to work seamlessly with the SIEM
  • Collaborate with Data Engineering to ingest events from multiple data streams and correlate them efficiently
  • Collaborate with Threat Intel and Machine Learning teams to build state of the art enrichments and detections
  • Build out aggregations on incoming data streams to support downstream analytics
  • Drive consistency across components including detection capabilities, threat intelligence, and playbooks

Requirements For Software Engineer, Threat Engine

Go
JavaScript
Python
Kafka
RabbitMQ
  • Experience in building and managing APIs (REST, gRPC, WebSockets)
  • Experience with Kafka, RabbitMQ, or similar for data streaming
  • Experience with >1 programming languages (Golang, JavaScript and Python)
  • Knowledge of detection strategies and technologies, including SIEM, IDS/IPS
  • Experience with both relational and NoSQL databases
  • Experience working with or developing plugin/extension frameworks
  • Familiarity with ML concepts in security analytics
  • Knowledge of detection languages like EQL, Sigma, or KQL
  • Experience working with large-scale data processing

Interested in this job?