at Snowflake
Location
US-USA-Remote
Compensation
$249k–$311k USD
Type
full time
Posted
4 days ago
Remote
Yes
Market range · function + seniority
p25 · target · p75 · n=626
Posted $311k · well above market
Tailor your résumé to this role in 30 seconds.
Free account · ATS keyword check · per-job bullet rewrite by Claude.
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done.
Snowflake has developed a world class cloud data platform that is effective, affordable and accessible to all data users.
As we continue to scale globally, we are investing in security capabilities that help us better understand, anticipate, and mitigate threats targeting Snowflake, our customers, and our ecosystem. We are looking for a Principal Security Engineer - Threat Intelligence who will help shape the next phase of Snowflake’s Threat Intelligence program and extend the reach and impact of Threat Intelligence across Snowflake. This role will combine deep intelligence expertise with strong engineering and program leadership skills, with AI and automation as core primitives in how we collect, analyze, prioritize, and operationalize intelligence.
The ideal candidate will help Snowflake leadership and security stakeholders make informed, risk-based, and data-driven decisions based on actionable threat intelligence. You will identify and track threat actors targeting cloud-native environments such as Snowflake, translate intelligence into concrete defensive outcomes, and build scalable approaches that improve how intelligence is delivered across the company.
This is a principal-level individual contributor role for someone who can operate strategically and technically: driving program maturity, building durable partnerships across Security and Engineering, and engineering AI-assisted workflows that help us move faster without sacrificing quality.
Deep experience in threat intelligence, with strong background in several of: adversary intelligence, intrusion intelligence, supply-chain intelligence, identity intelligence, domain intelligence, and threat-informed defense.
Strong understanding of today’s threat actor ecosystem, including nation-state actors, criminal organizations, ransomware groups, fraud ecosystems, and the platforms and communities that enable them.
Demonstrated ability to operationalize threat intelligence and influence security priorities in partnership with detection, incident response, product security, cloud security, anti-abuse, and other stakeholders.
Strong engineering skills, including experience writing code in high-level languages such as Python or Go, building automations, and working with data-heavy security workflows.
Experience building or driving AI-assisted workflows for intelligence analysis, research triage, summarization, collection, prioritization, or investigative support, and good judgment about where AI adds value versus where human analysis is required.
Ability to research threat actors’ TTPs, infrastructure, targets, and objectives, and map those risks to Snowflake’s product, enterprise, and customer environment.
Experience with OSINT tools, data sources, investigative methodologies, and intelligence reporting for technical and executive audiences.
Strong understanding of threat hunting and threat detection methodologies, and the ability to turn intelligence into hunts, detection opportunities, and control recommendations.
A risk-based approach to security, with the ability to prioritize work based on business impact and evolving threat conditions.
A humble, team-oriented mindset with a bias toward collaboration, execution, and raising the bar for the broader team.
Help define and mature the strategy for Threat Intelligence at Snowflake, including where the program should invest in people, processes, engineering, and AI-enabled capabilities.
Identify, profile, and track threat actors targeting Snowflake, our customers, partners, and ecosystem, and translate that intelligence into relevant, actionable outcomes.
Operationalize threat intelligence to help prioritize security initiatives and drive action with the relevant security teams and stakeholders.
Produce high-quality intelligence reports, assessments, briefs, and leadership-ready communications based on external events, internal requirements, and proactive research.
Engineer solutions that improve the efficiency, scale, and impact of the Threat Intelligence program, including automations, collection pipelines, enrichment workflows, and analyst tooling.
Build and improve AI-assisted intelligence workflows for tasks such as report triage, signal enrichment, summarization, vendor/customer monitoring, and threat-informed hunts, with strong measurement and quality..
Partner closely with Threat Detection, Incident Response, and other security teams to convert intelligence into detections, threat hunts, investigative pivots, and control recommendations.
Monitor alerts, intelligence feeds, vendor reporting, and external developments for threat events that may affect Snowflake.
Drive standards for how intelligence is curated, evaluated, delivered, and measured so the program remains high-signal, timely, and scalable.
Mentor other engineers and analysts by raising the team’s technical depth, analytic rigor, and operational maturity.
Significant experience in threat intelligence, cyber threat research, intelligence engineering, or closely related security disciplines.
Experience researching and tracking sophisticated threat actors targeting cloud-native and SaaS environments.
Experience writing code in a high-level programming language such as Python or Go and using code to automate manual workflows or analyze security data at scale.
Experience handling data programmatically using tools such as SQL and Python, ideally against large datasets relevant to security analytics or intelligence workflows.
Experience collaborating across multiple security functions and communicating effectively with technical stakeholders and leadership.
Strong understanding of enterprise security controls, threat hunting, and detection methodologies.
Experience with one or more major cloud providers (AWS, Azure, GCP) and familiarity with the risks that impact cloud and SaaS environments.
Experience leading or materially shaping a Threat Intelligence program at scale.
Experience building AI/ML-assisted security workflows or evaluating AI systems for security use cases.
Experience with data engineering, workflow orchestration, or production-grade systems that support intelligence or security operations at scale.
Experience with Snowflake or equivalent cloud data platforms for large-scale analysis and investigative workflows.
Experience presenting externally, publishing research, or demonstrating thought leadership in the security space.
Experience building capabilities that support intelligence-driven detection, hunting, or response at a global scale.
We are laser focused on doing security better, and we do not tolerate the status quo.
We have strong demand from our customers and strong support from the business for security, giving us meaningful runway to build next-generation capabilities.
We are a great team with a diverse set of backgrounds and skills, and we care deeply about impact, collaboration, and execution.
You will help solve security problems at global scale, leveraging Snowflake’s platform and modern AI capabilities to raise the bar for defenders.
The opportunity for impact on Snowflake, our customers, and the broader security ecosystem is enormous.
The Threat Intelligence team at Snowflake operates with a vision of proactively detecting threats based on risk and data-driven decisions. Our mission is to proactively identify relevant threat actors and activity through intelligence, and to translate that intelligence into capabilities and decisions that help Snowflake identify threats early and reduce risk to the business.
Snowflake is growing fast, and we’re scaling our team to help enable and accelerate our growth. We are looking for people who share our values, challenge ordinary thinking, and push the pace of innovation while building a future for themselves and Snowflake.
How do you want to make your impact?
For jobs located in the United States, please visit the job posting on the Snowflake Careers Site for salary and benefits information: careers.snowflake.com
More open roles at Snowflake
Hiring velocity, headcount trend, and every open posting on one page.
Open postings ranked by description similarity — useful if this role isn't quite right.