Skip to content

Threat Intelligence Researcher (Cloud)

160k – 220kUnited StatesRemote5+ YOE
Summary

Track and analyze advanced state-sponsored and financially motivated threat actors targeting cloud environments. Hunt through telemetry and data sources, attribute campaigns, and communicate findings to customers and the public.

About the role

What You'll Do

  • Identify, analyze, and track advanced state-backed or financially motivated attackers targeting cloud ecosystems
  • Hunt through data sources to identify malicious campaigns targeting Wiz customers
  • Leverage open and closed data to track infrastructure and malware used by advanced actors
  • Investigate and attribute incidents, campaigns, and threat actors to understand attackers and motivations
  • Communicate novel findings to customers and the public

Requirements

  • 5+ years of experience in security or threat research with focus on advanced state-backed actors or sophisticated financially motivated campaigns
  • Proven track record of tracking sophisticated threat actors
  • Ability to find novel and durable ways of identifying and tracking threat actors across multiple data sets
  • Deep subject matter expertise in at least one actor tracking mechanism (malware, infrastructure, etc.)
  • Experience working with large-scale telemetry, infrastructure hunting, pivoting through query languages and scripting
  • Familiarity with malware analysis and using YARA to hunt for malware
  • Willingness to take on multiple roles to build out actor tracking

Nice to Have

  • Knowledge of how attackers target AWS, GCP, Azure, Kubernetes, and modern cloud-native architectures
  • Experience building tools to exploit data sources in a repeatable and scalable manner
  • Track record of public communication of novel findings
  • Background in incident response, threat intelligence, or threat hunting

Benefits

  • Medical, dental, and vision insurance
  • Home Office Setup reimbursement
  • Flexible Spending Accounts
  • Monthly Connectivity reimbursement
  • Employee Assistance Program (EAP)
  • Short- and Long-term Disability Insurance
  • Life & Accident Insurance
  • 401(k) Retirement Savings Plan (with employer match)
  • Flexible paid time off + 11 paid holidays
  • Paid leave programs (parental, pregnancy health, medical, bereavement)
Skills
Threat IntelligenceMalware AnalysisYARAInfrastructure AnalysisThreat HuntingIncident ResponseAWSGCPAzureKubernetes
Similar roles at this salary range
All Security Engineering jobs →
Sigma

Senior Security Engineer

Senior Security Engineer building and scaling security platforms, AI/LLM security controls, detections-as-code, and automation across cloud and SaaS environments. Requires 5+ years hands-on security engineering experience and strong Python/cloud skills.

175k – 220kSan Francisco, CASecurity EngineeringOn-site5+ YOEAWSGCP
Sigma

Senior Security Engineer - Data Security

Senior Security Engineer building and scaling data protection platforms, DLP, DSPM, and AI-driven automation across SaaS, cloud, and data warehouse environments. Requires 5+ years in security engineering and strong software engineering skills.

175k – 220kSan Francisco, CASecurity EngineeringOn-site5+ YOEDLPDSPM
Illumio

Sr. Member of Technical Staff, Cloud Security

Develop containerized microservices in Go on Kubernetes for a distributed cloud security platform processing real-time telemetry from AWS/Azure/GCP. Own full SDLC, operations, and mentor junior engineers.

170k – 196kSunnyvale, CASecurity EngineeringOn-site5+ YOEGoSQL
Instacart

Senior Detection Engineer

Senior Detection Engineer building and operating detection systems across endpoint, cloud, container, and SaaS environments. Requires 5+ years in detection engineering or incident response, cloud platform experience, and detection-as-code expertise.

192k – 243kUnited StatesSecurity EngineeringRemote5+ YOEAWSGCP
Givebutter

Staff Engineer

Staff-level IC building fraud detection, risk decisioning, and investigation tooling for a nonprofit fundraising platform. Requires 8+ years experience in adversarial domains and strong backend fundamentals.

190k – 225kAustin, TX +9Security EngineeringRemote8+ YOEPHPAWS