Summary
What you’ll impact
Our company is seeking a Security Research Engineer to drive detection research, threat hunting, and AI-powered security automation. The role involves building AI-driven detection tools, analyzing cloud and identity data, performing attack simulations, and engaging directly with customers to deliver security value.
Responsibilities
What you'll do
- Develop AI-powered detection tooling - Build automation that leverages AI to accelerate detection creation, tuning, and validation at scale.
- Conduct security research - Analyze cloud, identity, and SaaS data sources (AWS CloudTrail, Okta, Entra ID, and more) to extract security value and identify detection opportunities.
- Perform attack simulations - Execute authorized attack simulations to validate detection coverage and identify gaps in our defenses.
- Hunt for threats - Proactively search for malicious activity across customer environments using our platform and tooling.
- Investigate potential cases - Analyze security incidents to demonstrate product value, refine detection logic, and deliver actionable findings.
- Engage with customers - Join customer calls to present analysis results, walk through findings, and gather feedback that shapes the product.
- Tune customer detections - Reduce false positives and improve detection accuracy based on real-world data and customer context.
- Build investigation automation - Create AI-powered tools that scale investigation and threat hunting workflows across our platform.
Requirements
What you’ll bring
- 7+ years of hands-on cybersecurity experience
- Hands-on experience in incident response including cloud environments (AWS, Azure, GCP) and identity providers (Okta, Entra ID)
- Strong knowledge of threat actor tactics, techniques, & procedures and demonstrated understanding uncovering threat actor activity in various environments
- Strong experience with log-based analysis and demonstrated ability to identify malicious activity across a variety of log sources
- Ability to translate security research into actionable detections or threat hunt investigations
- Strong communication skills—comfortable explaining technical findings to engineers and customers
- Experience with detection engineering at scale
- Bonus: Background working in a SOC environment or Managed Detection and Response.
- Bonus: Familiarity with a wide range of security tools (SIEM, EDR, SOAR)
- Bonus: Customer-facing technical experience
- Bonus: Experience with AI tools and models