Senior Capabilities Developer
About the Role:
Dragos' Capabilities Development team builds the technical foundation behind our OT threat intelligence—not just consuming data, but building the Synapse tooling, collection pipelines, and data models that turn raw threat information into an intelligence fabric for hunters, analysts, and customers. As a Senior Capabilities Developer, you'll build and maintain Synapse collection efforts that feed this fabric, writing Storm queries and automation, shaping tag hierarchies and data models, and scaling collection pipelines across threat groups and temporary activity threats (TATs). You'll partner with the Principal Capabilities Developer and cross-functional teams to resolve complex defects, close data-visibility gaps, and support recurring intelligence outputs, with the opportunity to shape how Dragos operationalizes threat intelligence at scale.
Responsibilities:
Build and maintain Synapse collection pipelines through Storm queries, automation, data models, and tag hierarchies that support accurate, on-schedule threat data flow.
Diagnose and resolve complex defects in Synapse tooling and collection systems independently, escalating architectural questions as needed.
Support threat hunting and adversary tracking using telemetry and malware analysis techniques across multiple threat groups and infrastructure assessments.
Contribute analysis to recurring intelligence deliverables (WorldView, Year in Review, Intelligence Services products) with validated, properly modeled underlying data.
Ensure data quality and close visibility gaps through validation, automation identification, and methodological improvement.
Document designs, improve processes, contribute to team coding standards and testing frameworks, and share knowledge across the team.
Collaborate across hunt, research, intelligence, product, and engineering functions; support incident response and intel-sharing relationships.
Qualifications:
3-5 years of combined experience in cyber threat intelligence, detection engineering, security operations, incident response, or a related cybersecurity discipline.
Working proficiency with Synapse/Storm query language for analytical queries, data manipulation, and collection workflows.
Experience troubleshooting and resolving moderately complex to complex defects in analytical tooling or scripts.
Understanding of Synapse's hypergraph data model, forms, properties, and tag structures.
Familiarity with telemetry and malware analysis tools in support of threat hunting or adversary tracking.
Comfortable writing design documentation and collaborating cross-functionally with hunt, intelligence, product, and engineering teams.
Ability to identify automation opportunities and data-visibility gaps and recommend practical solutions.
Experience contributing to recurring intelligence outputs (e.g., quarterly or annual reporting) is a plus.
Compensation:
Salary: $152,000
Competitive Equity Package
Comprehensive Benefits Plan
#LI-JF1 #LI-REMOTE