RudieSec is an external cyber threat intelligence shop. We live outside the firewall, and we are DOWN RANGE. The environment is messy, ambiguous, and constantly shifting.
If you need precision requirements, stable inputs, and a neat little queue of tickets to work on to feel alive, this might not be the right place. But, if you want to solve REAL threat intelligence problems, if your brain is wired just a little differently, and if you can thrive in environments where you can hold multiple instances of data as “true” while they are triangulated and corroborated until one piece of data becomes an intelligence signal, you might have found the right place.
For builders and technical folks, a constantly iterating environment will be the norm. Not because we can’t make up our minds on what to build, but because external threat intelligence and OSINT require that we build to the needs of the environment we work in.
Our operating ethos is this: FITK – Function Is The Key. Less theater, more output.
What it’s like to work at RudieSec:
The work is fast, but not sloppy. We move with urgency, and we stay disciplined. Threat actors have no rules, and we have to live in their neighborhood outside the firewall. Discipline, non-linear thinking, and creative problem-solving are everyday requirements.
Staff are expected to think, to communicate clearly, and to own your craft, no matter what that craft is. No one here is a passenger, and each role has a spot in serving the intelligence.
Builder Block
The Builder Block is where we build, test, and harden capability from a technical perspective. You should like iteration. You should care about accuracy. You should be comfortable working in an ever-evolving environment where priorities shift as the threat intel environment shifts.
We are building a threat intelligence engine (E-TIE), and the workflows around it. Builders will be shaping the system, not just maintaining it.
SOG
SOG is our intelligence, analysis, and production area. SOG is short for Studies and Observations Group, and that’s exactly what SOG team members are expected to do: Identify, Monitor, and Collect. SOG is the intelligence team.
The SOG team is responsible for identifying external cyber threat intelligence, monitoring threat actor behaviors, tracking evolving TTPs in the wild, and collecting supporting intel artifacts outside the client’s firewall. Triangulation, corroboration, and IoT (Indicators of Threat) analysis are components of what happens within SOG on a daily basis.
If you’re the type of person who enjoys wrestling with ambiguity, turning raw fragments of information into usable threat intel is at the heart of the SOG. If you care about delivering threat intelligence in a way that becomes actionable and justifiable to our SMB and NGO clients, you will understand SOG.
How we hire:
We hire the right people. The right people, in the right roles, for the right mission.
We do not optimize for the prettiest resume or CV. We optimize for capability, judgment, and fit. Early hires matter a lot because they help set the culture and standards at RudieSec. This is why our selection process is intentional and multi-stage, and inspired by the U.S. Army’s Special Forces Q-course and Delta selection processes – without the physical requirements. Don’t worry, though, there’s no humping a 40-pound ruck 20 miles uphill in our evaluation process.
What we value:
We value both discipline and goofiness. We value rigor, with healthy doses of adaptability. We value creative thinking and folks whose brains work differently. We value the understanding that the path from A to Z is not always a straight line, especially in cyber threat intel.
We value people who can do the work, explain the work, and improve the work without needing constant supervision.
We post open roles here when they are live. Check back regularly.
If you do not see an opening that fits you right now, keep an eye on us. We are building something real and unique, and we are doing it with people who actually care to learn and care to build.
Please note: Unless otherwise specified when a role is posted, all roles at RudieSec are 100% remote.