Threat Researcher

1 hour, 11 minutes ago
Full-time
Senior
Data Science and Analytics
GreyNoise

GreyNoise

GreyNoise provides cybersecurity solutions to help SOC teams identify and prioritize relevant threats by analyzing internet noise, leading to increased efficiency and improved security posture.

Internet Software & Services
51-250
Founded 2017
$26M raised

Description

  • Conduct hypothesis- and lead-driven hunting across first-party data and telemetry to identify novel malicious activity and campaigns.
  • Cluster, track, attribute, research, and disrupt malicious cyber threats.
  • Develop and integrate intelligence sources, data, tools, systems, and tradecraft to build comprehensive threat pictures.
  • Produce and share actionable threat intelligence with customers and the public.

Requirements

  • Deep understanding of computer networking fundamentals and protocols.
  • Advanced ability to analyze network traffic, including full PCAP at macro and packet levels.
  • Expertise with offensive tooling, tradecraft, and exploitation methods targeting network edge devices.
  • Experience conducting open-source and commercial intelligence research.
  • Experience with hardware and embedded systems.
  • Experience using query languages such as SQL.
  • Experience creating and tuning detection rules using tools such as Suricata and YARA.
  • Experience with binary analysis and reverse engineering.
  • Experience with cyber threat intelligence frameworks and analytical tradecraft.
  • Experience using graph-based threat analysis tools such as Synapse.
  • Experience applying AI, including prompt engineering and harness engineering.
  • Experience presenting at relevant security or intelligence conferences.
  • US work authorization is required; US-based roles are fully remote within the United States.

Benefits

  • Equity in a high-growth, Series A startup.
  • 100% employer-covered health, dental, vision, and life insurance.
  • 6% 401(k) employer match, fully vested from day one.
  • Flexible paid time off, with a recommended minimum of 120 hours annually.
  • Remote-first work culture with optional attendance at the Washington, DC-area headquarters.
  • Apple Mac laptop and $500 equipment-accessories stipend.
  • Four months of paid parental leave, plus two months of optional unpaid leave.
  • $1,500 annual professional development budget.
  • Company offsites and monthly local team events.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Associate Principal Cyber Threat Intelligence Analyst

Dragos 251-1K Professional Services

Dragos is hiring an OT Cyber Threat Intelligence Analyst to support a Singapore government security team with threat hunting, intelligence analysis, and incident response for critical infrastructure environments.

LLM SIEM
1 day, 2 hours ago

Security Operations Analyst II

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a Security Operations Analyst II to join its fully remote Security Operations team in Canada and help triage alerts, investigate incidents, and improve detection coverage.

AWS DNS GCP SIEM TCP/IP TLS
2 days, 2 hours ago

CyberSecurity Specialist

Avertium 251-1K IT Services

Avertium is hiring a Cyber Security Specialist to support 24x7 SOC monitoring and incident response for mid-market and enterprise clients.

Cybersecurity DNS Encryption HIPAA HTTP SIEM TCP/IP
2 days, 2 hours ago

Security Operations Engineer

Mesh 51-200 financial services

Mesh is hiring a Security Ops Engineer to design, operate, and respond to security controls across its infrastructure and systems as it builds payments infrastructure for the next era of the global economy.

AWS Azure Datadog Docker GCP Kubernetes Network Security Python SIEM Splunk
3 days, 1 hour ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers