A

Senior Threat Researcher Endpoint/Cloud - Detections

Arctic Wolf

Remote · Full Time

Be the first to apply

Experience
6+ yrs
Salary
—
Openings
1
Posted
1 week ago
Work mode
Work from home
Resume
Required to apply

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About Arctic Wolf

At Arctic Wolf, you will be part of a pioneering cybersecurity team that leads industry innovations to protect organizations globally. Our award-winning Aurora Platform and a culture focused on customers drive impactful work recognized by Forbes, CNBC, Fortune, and others.

Role Overview

We seek a Senior Threat Researcher focused on Endpoint and Cloud Detections to enhance our Detection Engineering group. This role involves creating advanced security detection rules, improving existing capabilities, researching new threat techniques, and delivering actionable intelligence to shield our customers from cyber threats.

Key Responsibilities

  • Create and manage custom detection rules for endpoint, cloud, and network systems to spot potential threats.
  • Investigate new attack methods, threat vectors, and telemetry data to expand detection coverage and accuracy.
  • Design and refine behavioral and anomaly-based detection mechanisms.
  • Review peers' code to maintain high standards in quality, scalability, and maintainability.
  • Troubleshoot and enhance current detection code and signatures.
  • Engage actively in the software development lifecycle ensuring detection content is secure, efficient, and testable.
  • Collaborate with cross-functional teams to innovate and fine-tune detection tools.
  • Recommend improvements to detection breadth and security visibility.
  • Develop detailed runbooks, reports, and supporting documentation for detection processes.
  • Share findings and knowledge with engineering, security operations, and research teams clearly.
  • Adopt and promote cybersecurity and software engineering best practices.
  • Participate in research demos, innovative projects, and company hackathons to enhance future products.

Ideal Candidate Attributes

  • Minimum six years of experience in authoring and maintaining security detection systems.
  • Expertise in endpoint, cloud, or network detection and signature creation.
  • Practical experience in developing anomaly and behavioral detection methods.
  • Skilled in tuning detections to enhance precision and lower false positives.
  • Strong comprehension of networking protocols like TCP/IP, DNS, LDAP, and NTLM.
  • Proven capability researching and crafting network-based threat detections.
  • Familiarity with frameworks such as MITRE ATT&CK, packet capture analysis, and threat intelligence for detection development.
  • In-depth knowledge of cybersecurity principles, adversary tactics, and threat methodologies.
  • Experience in managing detection within Managed Detection and Response (MDR) environments.
  • A passion for tackling complex security puzzles and enhancing detection strategies continuously.

Desirable Skills

  • Development of Security Information and Event Management (SIEM) detections.
  • Creation of Endpoint Detection and Response (EDR) signatures and rules.
  • Writing Sigma and YARA rules for advanced detection.
  • Cloud security detection capabilities.
  • Programming experience with Python, Go, Java, or C++.
  • Employing Test Driven Development practices.
  • Applying DevOps tools and automation frameworks.
  • Secure software development expertise.
  • Building and deploying solutions across AWS, Azure, or Google Cloud environments.
  • Working knowledge of Kubernetes, containers, and cloud platform services.
  • Experience with Agile methodologies such as Scrum and Kanban.
  • Familiarity with NGFW vendors like Palo Alto Networks, Cisco, or Fortinet.
  • Use of open-source intrusion detection, prevention, and network monitoring tools like Zeek or Suricata.

Additional Information

We encourage applicants who may not meet every qualification to apply, as we value strong talent diversity.

On-Camera Interview Policy: Remote interviews require candidates to be visible on camera to foster better communication and engagement. Exceptions can be made for technical or bandwidth issues upon prior notification.

Company Values and Culture

Arctic Wolf prioritizes teamwork, inclusion, and customer satisfaction with a global presence and over 10,000 clients. We celebrate diversity through initiatives like the Pack Unity program and are committed to corporate social responsibility including joining the Pledge One Percent movement.

Compensation and Benefits

  • Equity options for all employees.
  • Flexible leave policies including holidays and volunteer days.
  • Access to training and career advancement programs.
  • Comprehensive private healthcare plans covering family members.
  • Life insurance at three times annual salary and personal accident insurance.
  • Support for fertility treatments and paid parental leave.

Equal Opportunity and Security

We are an equal opportunity employer that values diverse backgrounds and perspectives. Security requirements include adherence to company information security policies and background checks. Access to data restricted by U.S. export laws may be necessary.

Industry

Cybersecurity

How they work

Communication Teamwork & Collaboration Problem Solving Attention to Detail Learning Agility

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer