Staff Threat Research Engineer

57 minutes ago
Full-time
Lead
Artificial Intelligence and Machine Learning
Sumo Logic

Sumo Logic

Sumo Logic offers top-tier cloud monitoring, log management, and Cloud SIEM tools for web and SaaS apps, empowering businesses with real-time insights and high-quality software delivery.

Internet Software & Services
251-1K
Founded 2010

Description

  • Conduct applied and original threat research and translate findings into actionable detection logic.
  • Design, build, and refine detection content and validation pipelines with Threat Labs teammates.
  • Test threat detection logic in lab environments against real-world attacker behaviors.
  • Analyze malware, track infrastructure, and use honeypots to uncover novel attacker behaviors.
  • Investigate industry and adversary trends to identify emerging detection opportunities.
  • Maintain and expand Threat Labs’ research lab infrastructure.
  • Collaborate with product management and engineering to scope, prioritize, and improve detection campaigns.
  • Provide practitioner feedback to product and engineering teams to inform feature design and roadmap decisions.
  • Publish research findings, detection logic, and hunting guidance through blogs, talks, open source, and other public contributions.

Requirements

  • 12+ years of cybersecurity experience in roles such as senior/principal SOC analyst, threat hunter, purple team practitioner, incident responder, or detection engineer.
  • Demonstrated ability to turn threat research into actionable detections and incident response outcomes.
  • Experience conducting original or self-directed threat research that produced novel findings and actionable insights.
  • Broad knowledge of multiple technology stacks and curiosity to learn new platforms.
  • Deep experience with major public clouds such as AWS, Azure, or GCP, including cloud-native logs and telemetry.
  • Understanding of AI-targeted attack techniques such as data poisoning, model theft, or prompt injection, with familiarity in MITRE ATLAS.
  • Proven thought leadership through blogs, LinkedIn articles, or conference presentations.
  • Background in the cybersecurity vendor space and experience giving expert feedback to product and engineering teams.
  • Prior customer-facing technical experience in consulting, remote support, or advisory roles.
  • Hands-on familiarity with offensive security tools such as Atomic Red Team, Sliver, or Cobalt Strike.
  • Scripting or automation experience with Python, PowerShell, or similar tools.
  • Experience with Security Orchestration, Automation, and Response (SOAR) technology.
  • Recognized presence or active participation in the security community through X/Twitter, conferences, or open source.
  • Experience applying AI or machine learning to improve efficiency and automation across the detection rule development lifecycle.

Benefits

  • Expected annual base salary of $162,000 to $190,000.
  • Eligibility for bonus or commission plans for certain roles.
  • Access to company benefits offerings.
  • Opportunity to work on agentic AI-powered SIEM and log analytics at a security-focused platform company.
  • Work that contributes to protecting customers and the broader security community.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Mathematical Optimisation Engineer

NEORIS 5K-10K Internet Software & Services

NEORIS, now part of EPAM Systems, is hiring an Operations Research professional to develop optimization models and production-ready scheduling and planning solutions for operations and manufacturing environments.

CI/CD Git Python
21 minutes ago

Senior Embedded Software Engineer - Cyber

STR 251-1K Aerospace & Defense

STR is hiring a Senior Embedded Software Engineer to join a multidisciplinary cyber research team developing vulnerability research technologies for national security applications.

Bash C C++ Docker Embedded Systems Git GitLab Python SVN
27 minutes ago

Principal Signal Processing Engineer (TL2)

STR 251-1K Aerospace & Defense

STR is hiring a Principal Algorithm & Signal Processing Researcher to advance space, radar, and electronic warfare capabilities through customer-facing research, prototype development, and team leadership.

Deep Learning Machine Learning MATLAB MLflow NLP Python PyTorch Reinforcement Learning TensorFlow
42 minutes ago

Ingénieur logiciel senior, Risque

Shakepay 51-250 Diversified Financial Services

Shakepay is hiring a Senior Software Engineer, Risk to help design and evolve the core risk systems that protect customers, the company, and the broader financial ecosystem in Canada.

AWS Datadog Kafka Kubernetes Node.js System Design
1 hour, 12 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers