xelys jobs xelys jobs

Principal Security Engineer (Threat Intelligence)

Snowflake

full-remoteleadpermanentsecuritybackend Full remote 47 days ago via WTTJ

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Threat IntelligenceThreat HuntingPythonGoOSINTAI-assisted WorkflowsDetection EngineeringCloud SecuritySQLAdversary Intelligence

About the role

Role overview

Join Snowflake as a Principal Security Engineer (Threat Intelligence). You will shape Snowflake’s Threat Intelligence program, operationalize threat intelligence, and engineer solutions that increase the program’s efficiency and impact.

Key missions / responsibilities

  • Define and improve Snowflake’s threat intelligence strategy, investing in people, processes, engineering, and AI-enabled capabilities.
  • Identify, profile, and track threat actors targeting Snowflake, its clients, partners, and ecosystem; translate intelligence into actionable outputs.
  • Produce high-quality reports, evaluations, briefs, and communications driven by external events, internal needs, and proactive research.
  • Convert intelligence into threat hunts, detection opportunities, and control recommendations by collaborating with multiple security stakeholders.
  • Operationalize threat intelligence influence across security priorities with teams including detection, incident response, product security, cloud security, and anti-abuse.

Requirements

  • Strong, hands-on experience in threat intelligence, including knowledge across areas such as:
    • adversary/intrusion intelligence
    • supply-chain intelligence
    • identity/domain intelligence
    • threat-informed defense
  • Experience using OSINT tools and data sources, investigative methodologies, and delivering intelligence for both technical and executive audiences.
  • Ability to build or drive AI-assisted workflows for analysis/research triage, summarization, collection/prioritization, and investigative support—plus strong judgment on when human analysis is required.
  • Strong engineering skills, including writing code in Python or Go, and building automations for data-heavy security workflows.
  • Deep understanding of threat hunting and threat detection methodologies; experience turning intelligence into hunts and detection/control actions.
  • Risk-based approach to security prioritization based on business impact and evolving threat conditions.
  • Ability to research threat actors’ TTPs, infrastructure, targets, and objectives and map risks to Snowflake’s product and customer environment.
  • Knowledge of the threat actor ecosystem, including nation-state, criminal, ransomware, and fraud ecosystems.
  • Experience with major cloud providers (AWS, Azure, or GCP) and understanding risks affecting cloud and SaaS.
  • Experience with programming/data handling using SQL and Python, ideally on large datasets for security analytics/intelligence workflows.

Nice-to-haves (implied by description)

  • Leading or materially shaping a Threat Intelligence program at scale.
  • Building AI/ML-assisted security workflows or evaluating AI systems for security use cases.
  • Extensive experience researching threat actors targeting cloud-native and SaaS environments.

Collaboration / communication

  • Team-oriented, collaborative mindset with strong execution.
  • Effective communication with technical stakeholders and leadership across security functions.

About Snowflake

Snowflake is a leading cloud data platform that enables organizations to store, process, and analyze data in the cloud. The role sits within Snowflake’s security organization, where threat intelligence helps strengthen the company’s security posture and supports security, incident response, and product defenses.

Scraped 6/11/2026