Threat Detection Researcher
Threat Detection Researcher developing detections and tools to protect customers from cloud, AI, and malware threats. Requires 6+ years in security/threat research, deep OS internals knowledge (Windows/Linux/macOS), Python proficiency, and cloud familiarity.
About the job
What You'll Do
- Develop detections and tools to protect customers from cloud threats
- Investigate attacks on cloud environments and malware targeting cloud and AI workloads
- Hunt and analyze real-world attacks and emerging cloud and AI threats
- Collaborate closely with the R&D team to transform research insights into product features
- Work with customers in response to requests related to suspicious activity or potential incidents
- Create best practices and security policies based on research findings
- Deliver external-facing content (blog posts and talks at security conferences) based on security insights and novel research
What You'll Bring
- 6+ years of experience in security or threat research in which you conducted deep research with actionable conclusions and impacts
- Intimate knowledge of OS internals (Windows/Linux/MacOS) and networking
- Familiarity with cloud services, Kubernetes, cloud environment architecture, and the major cloud providers (AWS, GCP, Azure)
- Proficiency in Python for tool development and automation (knowledge of Go, Rust, or C/C++ – an advantage)
- Experience delivering security detections in customer-facing product(s)
- The ability to learn independently, to be self-driven and goal-oriented
- Excellent communication and teamwork skills
Advantage
- Hands-on experience with malware analysis/reverse engineering/vulnerability research
- Familiarity with notable threat actors and threat intelligence analysis
- IR/red-team/threat-hunting experience
- Experience leveraging AI to supercharge research and detection workflows
- Deep knowledge of modern threat classes (Supply Chain, CI/CD, or threats targeting AI infrastructure and agentic frameworks)
Skills
Threat Research, Os Internals, Windows, Linux, macOS, Networking, Kubernetes, AWS, GCP, Azure, Python, Malware Analysis, Reverse Engineering, Vulnerability Research
Similar jobs
Security Engineering jobsBuild secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.
Own and advance the security of Anyscale’s production and multi-cloud infrastructure, including hardening, segmentation, Kubernetes runtime protection, and access controls. Requires 8+ years of security engineering experience and hands-on expertise with AWS, Azure, Kubernetes, and cloud security tooling.
Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.