
Threat Research Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Germany, +1 more country.
• Oversee current threats and examine suspicious activities utilizing logs, dashboards, and detection systems.
• Evaluate attack patterns and develop comprehensive threat scenarios based on gathered data.
• Research and address reported threats, customer escalations, and security incidents.
• Enhance detection and blocking mechanisms for automated attacks and harmful behaviors.
• Assess intelligence from competitors, public sources, and industry trends to uncover emerging threats.
• Utilize monitoring and analytics tools such as Kibana and Elasticsearch.
• Collaborate with engineering and security teams to bolster product protection capabilities.
• Document findings, attack methodologies, and results from investigations.
• Contribute to a security platform that protects applications from automated attacks and malicious traffic.
• Minimum of 3 years of professional experience in cybersecurity, threat research, or related fields.
• Practical experience in cybersecurity, threat detection, security research, threat hunting, anti-bot solutions, fraud and abuse detection, application security, or a similar security domain.
• Strong understanding of attacker tactics, techniques, and behaviors, including evasion, bypass, and modification methods.
• Experience in investigating suspicious or malicious activities and knowledge of detection, alerting, and blocking mechanisms.
• In-depth understanding of web technologies and architecture, including client-server architecture, HTTP/HTTPS, REST APIs, web services, request/response lifecycle, headers, cookies, sessions, and authentication mechanisms.
• Familiarity with browser technologies, including DOM structure and manipulation, browser events, XHR and Fetch requests, WebSockets, Browser APIs, and browser security policies and controls.
• Capability to read and analyze JavaScript code to identify application behavior, suspicious or erroneous logic, and remediation strategies.
• Proficient knowledge of HTML and CSS.
• Strong hands-on experience with SQL for data analysis, investigations, and handling large datasets.
• Practical experience using Kibana for log analysis, monitoring, and investigations.
• Solid understanding of networking fundamentals, including TCP/IP, DNS, VPN technologies, proxies, and basic network troubleshooting.
• Ability to independently investigate complex technical issues and correlate multiple data points into cohesive attack or incident scenarios.
• Experience using AI-powered tools and chatbots for research and technical investigations, including crafting effective prompts and interpreting results.
• Upper-Intermediate (B2) or higher proficiency in English.
• Preferred/plus: Knowledge of Elasticsearch and its ecosystem.
• Preferred/plus: Skills in Python scripting and automation.
• Preferred/plus: Experience in developing, analyzing, or investigating crawlers, scrapers, or browser automation tools.
• Preferred/plus: Familiarity with deobfuscation and/or reverse engineering techniques.
• Preferred/plus: Experience in investigating bot traffic, automated attacks, scraping activities, credential stuffing, account takeover attempts, abuse, fraud, or related threats.
• Preferred/plus: Experience with monitoring, analytics, and observability platforms such as Datadog, Imply, Splunk, Microsoft Sentinel, OpenSearch, or similar tools.
• Remote work within European time zones.
• Opportunity to contribute to impactful security products.
• Collaboration with seasoned professionals.
• Chance to enhance expertise in modern cybersecurity technologies.
Catholic Relief Services
Hanover Research
Chickasaw Nation Industries, Inc.
Cedars-Sinai
Get handpicked remote jobs straight to your inbox weekly.