Threat Researcher -Cloud & Endpoint Detection
- Category
- Cloud Security
- Location
- Bengaluru, IND
Quality of life
What the posting states. Hover or tap a perk to see the line it came from.
-
Paid parental leave
“…ce Fertility support and paid parental leave Arctic Wolf is an equal oppor…”
-
Flexible PTO
“…ing: Equity for all employees Flexible time off and paid volunteer days RRSP…”Company-wide policy · source
-
Retirement match
“…paid volunteer days RRSP and 401k match Training and career developme…”Company-wide policy · source
-
Learning budget
“…ge and approve conference and training budgets. Participate in helping set…”Company-wide policy · source
-
Equity
“…entive compensation, new hire equity grants, and a comprehensive b…”Company-wide policy · source
At Arctic Wolf, you will not just watch the cybersecurity industry evolve – you will help lead the change. Our global team is made up of people who thrive on solving complex problems, moving quickly, and building technology that protects organizations around the world. We are proud to be recognized by Forbes, CNBC, Fortune, CRN, Gartner Peer Insights, and International Data Corporation MarketScape. What matters most is the work behind these recognitions: delivering real outcomes for customers through award-winning innovation such as our Aurora Platform.
If you are looking for meaningful work, smart teammates, and the opportunity to make a real impact in a high-growth company that is redefining security operations, Arctic Wolf is the right place for you.
Our mission is simple: End Cyber Risk.
We are looking for a Threat Researcher - Cloud & Endpoint Detection to join our Integrations Team and help achieve this mission.
You'll be working as a Detection Engineer within Integrations, Detection, & Response (IDR), reporting directly to the Manager of Detection Engineering, XDR while working closely with Pipeline, Platform, Threat Enablement, and Artificial Intelligence teams.
This individual will be responsible for providing technical direction to deliver high-value, performant, generalized detections across many telemetry sources — endpoint, network, cloud, identity, and email — to provide broad Extended Detection and Response (XDR) coverage for customers. They will provide technical guidance and direction to developers through the design, implementation, testing, and tuning of detection content at scale.
This role sits at the intersection of security research, detection engineering, and integrations. The primary responsibility is to analyse data ingested from integrated security providers and transform that telemetry into actionable detection rules, correlation logic, and attack coverage. Initially, the role will focus heavily on detections powered by data from third-party integrations, with opportunities to expand coverage across cloud, identity, endpoint, and Software as a Service (SaaS) ecosystems as new integrations are onboarded.
The ideal candidate has a strong understanding of attacker behaviour, security telemetry, and detection engineering, with the ability to quickly learn new vendor schemas, Application Programming Interfaces (APIs), and event models to identify meaningful detection opportunities.
IN THIS ROLE, YOU WILL:
Third-Party Integration Detection Development
Serve as a detection subject matter expert within the Integrations Team.
Apply broad expertise and knowledge across multiple telemetry domains, including endpoint, network, cloud, identity, and email, to design detections that generalize across diverse customer environments.
Contribute to the development of detection strategies and principles to achieve coverage goals in creative and effective ways.
Produce detection specifications and coverage models and determine operational feasibility.
Develop detections, correlation rules, and analytics based on telemetry ingested from third-party integrations.
Analyse vendor APIs, audit logs, alerts, and event schemas to identify security detection opportunities.
Design detection coverage that leverages data from integrated security products, cloud providers, identity platforms, email security solutions, and endpoint security tools.
Partner closely with integration engineers to understand newly onboarded data sources and maximize security value from collected telemetry.
Provide technical guidance and direction to developers through the design, implementation, testing, and tuning of detection content at scale.
Detection Research
Research emerging threats, attack techniques, and adversary tactics.
Work on significant and unique detection challenges where analysis of attacker behaviour requires evaluation of complex, cross-domain signal correlation.
Apply conceptual thinking to understand advanced threats, novel attack chains, and their implications across telemetry boundaries.
Identify opportunities to detect malicious activity using third-party security and SaaS telemetry.
Map detections to the MITRE ATT&CK framework and maintain alignment with evolving threat landscapes.
Continuously improve existing detections by reducing false positives and increasing attack coverage.
Exercise independent judgment in detection methodology, technique selection, and evaluation criteria for measuring detection efficacy.
Provide thought leadership on cross-telemetry detection approaches and contribute to broader organizational projects requiring an understanding of the wider XDR ecosystem.
Security Domain Coverage- Develop detections across multiple security domains, including:
Identity & Access Security
Account takeover
MFA abuse and bypass
Privilege escalation
Suspicious administrative activity
Service account misuse
OAuth and application abuse
Email Security
Business Email Compromise (BEC)
Phishing campaigns
Malicious attachment activity
Email forwarding rule creation
Suspicious mailbox access
Abnormal email behaviours
Endpoint Security
Malware and ransomware activity
Credential theft techniques
Suspicious process execution
Persistence mechanisms
Lateral movement
Defence evasion
Living-off-the-land techniques
Endpoint compromise indicators
Cloud Security
Excessive permission changes
Suspicious cloud administration activity
Data exfiltration attempts
Resource misconfigurations
Cloud account abuse
Workload compromise activity
Network Security
Analyse network telemetry and cross-domain signals to identify attacker behaviour.
Develop detection approaches using network telemetry such as NetFlow, Domain Name System (DNS), Hypertext Transfer Protocol (HTTP), Transport Layer Security (TLS) metadata, and Intrusion Detection System (IDS) or Intrusion Prevention System (IPS) telemetry.
Correlate network activity with endpoint, cloud, identity, and email telemetry where applicable.
Detection Validation & Quality
Validate detections against attack simulations, threat scenarios, and real-world telemetry.
Assess data quality and telemetry completeness across integrations.
Continuously monitor detection performance and effectiveness.
Identify gaps in attack coverage and recommend enhancements.
Define and apply evaluation criteria for measuring detection efficacy.
Test and tune detection content to ensure high-value and performant detections at scale.
Cross-Functional Collaboration
Collaborate with Integration Engineers, Product Managers, Detection Engineers, Threat Researchers, and Security Operations Center (SOC) teams.
Work closely with Pipeline, Platform, Threat Enablement, and Artificial Intelligence teams.
Provide requirements and feedback for new integrations to ensure detection-readiness.
Help shape onboarding strategies for new vendors by identifying telemetry needed for meaningful security analytics.
Influence normalization and data-modelling efforts to support scalable detection development.
Convey advanced detection concepts and technical information to diverse stakeholders and audiences.
Contribute to broader organizational projects requiring an understanding of the wider XDR ecosystem.
WE'RE LOOKING FOR SOMEONE WITH EXPERIENCE IN:
4 years of experience in Detection Engineering, Threat Hunting, Security Research, SOC Engineering, or Security Analytics.
Expert-level Python expertise, with the ability to build detection tooling, automation, and frameworks.
Deep understanding of diverse telemetry sources and their strengths and limitations, including: Endpoint: Windows Security and Sysmon logs, Linux auditd, macOS Unified Logs, and Endpoint Detection and Response (EDR) telemetry. Network: NetFlow, DNS, HTTP/TLS metadata, and IDS/IPS such as Suricata. Cloud: Amazon Web Services (AWS) CloudTrail, Azure Activity Logs, Google Cloud Platform (GCP) Audit Logs, and Kubernetes audit logs. Identity: Identity Provider (IdP) logs such as Okta and Azure Active Directory/Entra ID, authentication, and authorization events. Email: Mail flow logs, phishing indicators, and header analysis.
Experience building detections using telemetry from cloud, endpoint, identity, email, or security platforms.
Ability to analyse new third-party integrations, understand vendor-specific schemas and APIs, and rapidly develop detection coverage from ingested telemetry.
Hands-on experience with one or more detection technologies such as Kusto Query Language (KQL), Splunk Processing Language (SPL), Sigma, Structured Query Language (SQL), or equivalent analytics languages.
Strong understanding of security telemetry, event correlation, and detection tuning.
Experience working with data from security products, cloud platforms, identity providers, or SaaS applications.
Familiarity with endpoint, identity, cloud, network, and email security telemetry.
Ability to analyse unfamiliar security event schemas and rapidly build detections from new data sources.
Good understanding of adversary tactics, techniques, and procedures (TTPs) and the MITRE ATT&CK framework.
Experience designing detection strategies, coverage models, and detection specifications.
Ability to evaluate detection effectiveness and identify opportunities to improve attack coverage.
Experience providing technical guidance, mentoring, or direction to other detection engineers or developers.
NICE TO HAVE:
Experience with Security Information and Event Management (SIEM), Extended Detection and Response (XDR), Managed Detection and Response (MDR), Cloud Native Application Protection Platform (CNAPP), or Identity Threat Detection platforms.
Familiarity with security data normalization frameworks such as Open Cybersecurity Schema Framework (OCSF).
Experience working across multiple telemetry domains and developing cross-domain or generalized detection approaches.
Experience with attack simulation and detection validation.
Experience working with third-party security integrations and vendor-specific data models.
Experience with XDR detection programs or large-scale detection content development.
IDEAL CANDIDATE PROFILE
The ideal candidate is passionate about turning third-party security telemetry into actionable detections. They are comfortable diving into a newly onboarded integration, understanding the data model, identifying attacker-relevant events, and rapidly developing detection coverage.
They bring broad expertise across endpoint, network, cloud, identity, and email telemetry and are able to think beyond individual data sources to identify complex attack chains and cross-domain detection opportunities.
They are also comfortable providing technical direction to other detection engineers and developers, contributing to detection strategy, and influencing how detection content is designed, tested, evaluated, and scaled across the XDR ecosystem.
Success in this role will be measured by the ability to maximize security value from integrated data sources and deliver meaningful detection coverage across the growing integration ecosystem.
This role is ideal for professionals from Detection Engineering, Security Research, SOC Content Development, XDR Detection Teams, Endpoint Detection Engineering, or CNAPP Security Teams who are passionate about understanding attacker behaviour and transforming security telemetry from cloud, endpoint, identity, email, network, and third-party security integrations into actionable detections at scale.
Do not meet all the requirements? That is okay. We still encourage you to apply. We have many opportunities and are always looking for strong talent.
On-Camera Policy
Continue reading the full posting on Arctic Wolf's careers page →
— Curated listing: aggregated from Arctic Wolf's public careers page. Apply directly via the link — Arctic Wolf has not paid for placement.