research
Posted Jun 10Senior Threat Researcher - Endpoint/Cloud
at Arctic Wolf
Bengaluru, IndiaRemote
Responsibilities
- Research and develop expertise for various threat surfaces and telemetry available for them Conducting code reviews and providing constructive feedback to ensure code quality and maintainability.
- Propose coverage and efficacy improvements to the detection surface Build well-designed, testable, efficient, durable detections Build runbooks, reports and supporting material for detection surface Document research findings and knowledge share with team and other departments Troubleshoot, educate, and share information with non-technical people Continuously learning and adopting best practices for code quality, software development methodologies, and programming principles to enhance coding skills and
Requirements
- Our Aurora Platform also received CRN’s Products of the Year award in the inaugural Security Operations Platform category.
- experience with a focus on the following key areas: Endpoint or Cloud detections/signatures Development of anomaly and behavioural based detections Tuning and optimization of detections Expertise on the inner workings of networking, protocols(TCP/IP, DNS, threat management domain topics, e.g.
- LDAP, NTLM, etc Proven ability and
- experience to research and develop security detections related to network threat vectors
- Experience using MITRE ATT&CK, PCAP analysis, and threat intelligence feeds.
- We use and train a variety of technologies in MDR.
- You should have a strong understanding of networking, protocols, and cybersecurity.
- experience in the following areas: SIEM detections EDR detections/signatures Sigma and Yara rules Cloud security detections
- Experience in at least two of the following Development Languages & Methodologies: Python, Go, Java, or C/C++ Test Driven Development Full understanding and use of DevOps methods/tooling Full understanding/application of secure development practices Cloud Development: AWS, Azure, and GCP using Kubernetes/Containers, IaaS, and key PaaS services Agile (SCRUM/Kanban)
- Experience in following security tooling is a plus: NGFW (PAN, CISCO, Fortinet, etc.) Open Source IPS/IDS/NSM (e.g.
- And we appreciate that—by protecting people’s and organizations’ sensitive data and seeking to end cyber risk— we get to work in an industry that is fundamental to the greater good.
- If this applies, candidates are required to notify us in advance so we can explore appropriate accommodations. Security
- responsibilities in accordance with AWN’s Information Security policies, standards, processes, and controls to protect the confidentiality, integrity, and availability of AWN business information (in accordance with our employee handbook and corporate policies).
Benefits
- Experience with 3rd-party firewalls, IDS/IPS and network edge devices, their capabilities and configuration is a bonus, but minimally understanding their use and vulnerabilities.
- All wolves receive compelling compensation and benefits packages, including:
- Equity for all employees
- Flexible annual leave, paid holidays and volunteer days
- benefits plan including medical insurance for you and your family, life insurance (3x compensation), and personal accident insurance.
- Fertility support and paid parental leave Arctic Wolf is an Equal Opportunity Employer and considers applicants for employment without regard to race, colour, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, provincial, or local law.
Contact
- Please let us know if you require any accommodations by emailing recruiting@arcticwolf.com.
Additional details
- At Arctic Wolf, we're redefining the cybersecurity landscape.
- With our employee Pack members, spread out globally, committed to setting new industry standards.
- Our accomplishments speak for themselves, from our recognition in the Forbes Cloud 100 , CNBC Disruptor 50 , Fortune Future 50 , and Fortune Cyber 60 to winning the 2024 CRN Products of the Year award.
- Join a company that’s not only leading, but also shaping, the future of security operations.
- They are able to manage competing priorities as they relate to improving our existing codebase of detections and constantly challenge the status quo.
- About the role You’ll be working as a Senior Security Developer on our Integration, Detection and Response Team, responsible for ensuring quality and scale of our detection base and presenting actionable detections to our Security Services teams and customers.
- responsibilities will be: Developing and maintaining high quality custom detection rules (Endpoint/Cloud).
- Debugging and fixing issues in existing detection/signature codebases.
- Participate in the full software development life cycle, building well- designed, testable, efficient, secure code.
- Work with team members to develop novel detections and continuously tune existing ones Understand the product and how Security Services delivers the service.