
Senior Threat Researcher – Endpoint/Cloud, Detections
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in India.
• Create and uphold high-quality customized detection rules for endpoint, cloud, and network environments.
• Investigate emerging threats, attack methods, and telemetry sources to enhance detection coverage and effectiveness.
• Design, develop, and consistently refine anomaly-based and behavioral-based detections.
• Perform code reviews and provide constructive feedback to ensure quality, maintainability, and scalability of the code.
• Troubleshoot, debug, and improve existing detection and signature codebases.
• Engage in the complete software development life cycle by crafting secure, efficient, testable, and maintainable detection content.
• Collaborate with team members to create innovative detections and continuously optimize existing detection capabilities.
• Suggest improvements to detection coverage, efficacy, and overall security visibility.
• Develop runbooks, reports, documentation, and supporting materials for detection surfaces.
• Document research findings and disseminate knowledge across engineering, security operations, and research teams.
• Effectively communicate technical concepts and security findings to both technical and non-technical audiences.
• Acquire and implement industry best practices in software development, detection engineering, and cybersecurity.
• Take part in research and development demonstrations, innovation initiatives, and annual hackathon events.
• A minimum of 6 years of experience in authoring and maintaining security detections.
• Strong expertise in endpoint, cloud, or network detection and signature development.
• Experience in developing anomaly-based and behavioral-based detections.
• Extensive experience in tuning and optimizing detections to enhance fidelity and minimize false positives.
• Deep understanding of networking concepts, protocols, and authentication technologies, including Transmission Control Protocol/Internet Protocol, Domain Name System, Lightweight Directory Access Protocol, and New Technology LAN Manager.
• Proven experience in researching and developing detections related to network-based threat vectors.
• Experience leveraging MITRE ATT&CK, packet capture analysis, and threat intelligence sources to inform detection development.
• Strong knowledge of cybersecurity principles, threat detection methodologies, and adversary behaviors.
• Experience with security monitoring and detection technologies in Managed Detection and Response environments.
• Experience in developing Security Information and Event Management detections.
• Experience in creating Endpoint Detection and Response detections and signatures.
• Experience in authoring Sigma and YARA rules.
• Experience in developing cloud security detections.
• Proficiency in programming languages such as Python, Go, Java, or C++.
• Familiarity with Test Driven Development methodologies.
• Experience using DevOps practices, tools, and automation frameworks.
• Knowledge of secure software development practices.
• Experience building and deploying solutions in cloud environments, including Amazon Web Services, Microsoft Azure, and Google Cloud Platform.
• Experience working with Kubernetes, containers, infrastructure-as-a-service, and platform-as-a-service technologies.
• Experience in Agile software development methodologies, including Scrum and Kanban.
• Familiarity with Next Generation Firewall technologies from vendors like Palo Alto Networks, Cisco, or Fortinet.
• Experience using open-source intrusion detection, intrusion prevention, and network security monitoring tools such as Zeek or Suricata.
• Background checks are mandatory for this position.
• The role may necessitate access to information protected under United States export control laws and regulations.
• Equity for all employees.
• Flexible annual leave, paid holidays, and volunteer days.
• Training and career development programs.
• Comprehensive private benefits plan, including medical insurance for you and your family.
• Life insurance equal to three times your compensation.
• Personal accident insurance.
• Fertility support.
• Paid parental leave.
• Volunteer days.
Pear Tree.
Interrupt Labs
Get handpicked remote jobs straight to your inbox weekly.