FluidStack
Security Engineer, Threat Intelligence
About this role
Fluidstack seeks a Security Engineer focused on threat intelligence to secure frontier AI infrastructure by tracking nation-state and advanced criminal actors, building detection pipelines, and converting threat intelligence into operational security improvements across a rapidly scaling global operation.
What you'll do
- Track and analyze nation-state and advanced criminal actors targeting frontier AI infrastructure, extracting tooling patterns and tradecraft
- Build and operate pipelines to collect, enrich, and correlate threat indicators, pushing intelligence into detection and triage systems
- Conduct intelligence-led hunts across enterprise, cloud, identity, and data center environments to identify high-fidelity detections
- Perform malware, phishing infrastructure, and attacker tooling analysis to extract indicators, TTPs, and attribution signals
- Curate inbound intelligence from commercial feeds, open source, government, and peer relationships aligned to threat model priorities
- Establish and maintain external intelligence-sharing relationships with ISACs, peer security teams, and government partners
What they're looking for
- Nation-state and advanced criminal actor tracking and analysis
- Malware analysis and reverse engineering
- Python or similar production-quality programming
- Detection logic authoring (YARA, Sigma, SIEM queries)
- Threat intelligence pipeline development and automation
- Log analysis and infrastructure investigation
- Incident response collaboration and real-time threat assessment
- Intelligence reporting and executive communication
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
FluidStack
FluidStack builds AI infrastructure at scale, developing data centers and warehouse operations designed to handle gigawatt-capacity compute deployment. The company is hiring for warehouse engineers, data center operations specialists, product engineers, and people leaders to support rapid infrastructure expansion across multiple sites.
- Website
- fluidstack.io
Likely interview questions
- Describe a specific nation-state or advanced criminal actor you've tracked and how you anticipated their next moves based on their tooling and infrastructure patterns.
- Walk us through a malware analysis or infrastructure investigation you conducted end-to-end—what indicators and TTPs did you extract and how did they feed into detections?