Threat Researcher -Cloud & Endpoint Detection
Arctic WolfMatch Score
Against your primary resumeLogin to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Protocol Intelligence
Data-driven signals on your job's competitivenessLog in to see why each signal reads the way it does.
Job Description
Structured overview of role & requirementsAbout This Role
Lead design, implementation, testing, and tuning of detection content covering endpoint, network, cloud, identity, and email telemetry within XDR integrations.
Develop and maintain high-value, generalized detections from third-party security provider data for broad Extended Detection and Response (XDR) coverage.
Provide technical guidance to developers and collaborate cross-functionally to maximize operational detection coverage and improve detection efficacy.
Minimum Requirements
4+ years experience in Detection Engineering, Threat Hunting, Security Research, SOC Engineering, or Security Analytics.
Expert-level Python skills for building detection tooling, automation, and frameworks.
Strong knowledge of diverse security telemetry sources including endpoint logs, network telemetry, cloud platform logs, identity provider logs, and email security data.
Experience with detection analytic languages (e.g., KQL, SPL, Sigma, SQL) and building detections using multi-domain telemetry from cloud, endpoint, identity, or security platforms.
Ideal Candidate Profile
Broad expertise across multiple telemetry domains (endpoint, cloud, identity, email, network) with the ability to design cross-domain, generalized detection strategies.
Comfortable analyzing new third-party integrations rapidly to develop actionable detection coverage from unfamiliar security data schemas and APIs.
Experienced in providing technical leadership, influencing detection strategies, and scaling detection content across a large XDR ecosystem.
