Senior Threat Researcher Endpoint/Cloud - Detections
Arctic Wolf
IndiaremotePosted 7 days ago
Skill Required
THREAT-RESEARCHDetection-EngineeringCybersecurityEndpoint-SecurityCloud-SecuritySenior-Threat-Detection-AnalystSenior-Threat-Intelligence-SpecialistSenior-Threat-AnalystSenior-Threat-Hunting-EngineerSenior-Cyber-Threat-Intelligence-AnalystSenior-Threat-Intelligence-Subject-Matter-ExpertSenior-Security-ResearcherThreat-Detection-EngineerThreat-Intelligence-ResearcherCloudAWSAzureCloud SecurityGCPEngineeringR ProgrammingKubernetesnetworkingautomationObservabilityFirewallsecuritybuildingPythondesignDevOpsAgileC++CiscoJavaandGoFulltime
Key highlights
- Required experience: 6+ years
- Equity for all employees
- Life insurance provided at 3x compensation
- Global team presence
- Managed Detection and Response environment
Role overview
Arctic Wolf is a high-growth company dedicated to ending cyber risk through its award-winning Aurora Platform. The company is seeking a Senior Threat Researcher (Endpoint/Cloud - Detections) to contribute to its Detection Engineering organization by developing, maintaining, and enhancing advanced security detections to protect global customers.
Responsibilities
- Develop and maintain high-quality custom detection rules across endpoint, cloud, and network environments
- Research emerging threats, attack techniques, and telemetry sources to improve detection coverage and effectiveness
- Design, develop, and continuously improve anomaly-based and behavioral-based detections
- Conduct code reviews and provide constructive feedback to ensure code quality, maintainability, and scalability
- Troubleshoot, debug, and enhance existing detection and signature codebases
- Participate in the full software development life cycle by building secure, efficient, testable, and maintainable detection content
- Collaborate with team members to develop innovative detections and continuously tune existing detection capabilities
- Propose improvements to detection coverage, efficacy, and overall security visibility
- Build runbooks, reports, documentation, and supporting materials for detection surfaces
- Document research findings and share knowledge across engineering, security operations, and research teams
- Communicate technical concepts and security findings effectively to both technical and non-technical audiences
- Continuously learn and adopt industry best practices in software development, detection engineering, and cybersecurity
- Participate in research and development demonstrations, innovation initiatives, and annual hackathon events that contribute to future product capabilities
Requirements
- 6 or more years of experience authoring and maintaining security detections
- Strong expertise in endpoint, cloud, or network detection and signature development
- Experience developing anomaly-based and behavioral-based detections
- Extensive experience tuning and optimizing detections to improve fidelity and reduce false positives
- Deep knowledge of networking concepts, protocols, and authentication technologies including TCP/IP, DNS, LDAP, and NTLM
- Proven experience researching and developing detections related to network-based threat vectors
- Experience using MITRE ATT&CK, packet capture analysis, and threat intelligence sources to drive detection development
- Strong knowledge of cybersecurity principles, threat detection methodologies, and adversary behaviors
- Experience working with security monitoring and detection technologies within Managed Detection and Response environments
- Passionate about solving complex security challenges and continuously improving detection capabilities
Nice to have
- Experience developing Security Information and Event Management (SIEM) detections
- Experience creating Endpoint Detection and Response (EDR) detections and signatures
- Experience authoring Sigma and YARA rules
- Experience developing cloud security detections
- Experience with programming languages such as Python, Go, Java, or C++
- Experience with Test Driven Development methodologies
- Experience using DevOps practices, tooling, and automation frameworks
- Experience applying secure software development practices
- Experience building and deploying solutions in cloud environments including AWS, Azure, and GCP
- Experience working with Kubernetes, containers, infrastructure-as-a-service, and platform-as-a-service technologies
- Experience working within Agile software development methodologies including Scrum and Kanban
- Experience with Next Generation Firewall technologies from vendors such as Palo Alto Networks, Cisco, or Fortinet
- Experience using open-source intrusion detection, intrusion prevention, and network security monitoring technologies such as Zeek or Suricata
Benefits
- Equity for all employees
- Flexible annual leave, paid holidays, and volunteer days
- Training and career development programs
- Comprehensive private benefits plan including medical insurance for you and your family
- Life insurance equal to three times compensation
- Personal accident insurance
- Fertility support and paid parental leave
Additional details
- Mission: End Cyber Risk
- Candidates are encouraged to apply even if they do not meet all requirements
- On-Camera Policy: Candidates interviewing remotely are expected to be on camera during all video interviews; notification in advance is required if accommodations are needed
- We foster a collaborative and inclusive work environment with programs such as Pack Unity
- Corporate responsibility: Pledge One Percent movement participant
- Equal opportunity employer
- Security requirements: Conduct duties in accordance with Arctic Wolf information security policies, standards, and controls
- Background checks are required for this position
- This role may require access to information protected under United States export control laws and regulations
- Originally posted on Himalayas