Apply

Senior Threat Intelligence Engineer

Our Security team supports the unwritten fourth tenet of Slack’s mission: make people’s working lives more secure. We’re serious about protecting our infrastructure, operations, and most importantly, our customers’ data. We take a systemic approach to security, and strive to ensure we provide low friction high-impact security across everything we do.

As a member of the Slack Security Detection and Response Team, you are the first line of defense for all the people and parts that together make up Slack. You get out of bed every morning thinking about new ways to make life miserable for bad actors. You get excited at the prospect of searching for your adversary, teasing out high-quality signal from the all the noise, and developing new ways to solve hard problems. Your work directly impacts the way millions of people, teams and businesses get things done.

Responsibilities:

  • Gather threat intelligence data relevant to our production environment and apply it to characterize anomalous behavior and establish new detective signal
  • Collaborate with teammates to develop new threat models and signatures based on current activities and events
  • Work closely with Data Engineering to author and develop data sets that drive security exploration
  • Use intelligence to design, optimize, and develop automated systems to detect and respond to threats
  • Research new technologies as they apply to our environment for security threats and risks, to support our security enhancement and development

Requirements:

  • Applied understanding of threat models, threat actors, TTPs, IOCs, and intelligence as applied to computer security
  • Experience hunting for adversaries and bad actors by applying threat intelligence to production data sets
  • Experience working on fast-paced Information Security Incidents with understanding of vulnerabilities, exploits, log correlation, and technical remediation techniques
  • Extensive understanding of security techniques for Cloud, Network, Infrastructure, and Server
  • Experience writing queries against production datasets in SQL/Hive, Presto, ElasticSearch, or exploration in a scripting language (Python, PHP, Ruby, etc.)
  • Hands-on experience with Big Data technologies (e.g Hadoop, Hive, Spark, ElasticSearch)
  • Experience uncovering relationships or trends using Maltego, I2 Analyst notebook, or other graphing and correlation tool

 

Slack is where work happens. It connects you with the people and apps you work with every day, no matter where you are or what you do. We believe everyone deserves to work in a welcoming, respectful, and empathetic culture. We live by our values and hire accordingly.

Launched in February 2014, Slack is the fastest growing business application ever and is used by thousands of teams and millions of users every day. We currently have eight offices worldwide, in San Francisco, Vancouver, Dublin, Melbourne, New York, London, Tokyo, and Toronto.

Ensuring a diverse and inclusive workplace where we learn from each other is core to Slack's values. We welcome people of different backgrounds, experiences, abilities and perspectives. We are an equal opportunity employer and a fun place to work. Come do the best work of your life here at Slack.

 


Slack is the collaboration hub of choice for companies of all sizes, all across the world. By using Slack, they ensure that the right people are always in the loop, that key information is always at their fingertips, and new team members can get up to speed easily. With Slack, teams are better connected.

Launched in February 2014, Slack is the fastest growing business application ever and is used by thousands of teams and millions of users every day. We currently have nine offices worldwide, in San Francisco, Vancouver, Dublin, Melbourne, New York, London, Tokyo, Toronto and Denver.

Ensuring a diverse and inclusive workplace where we learn from each other is core to Slack's values. We welcome people of different backgrounds, experiences, abilities and perspectives. We are an equal opportunity employer and a pleasant and supportive place to work. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Come do the best work of your life here at Slack.