Staff Threat Research Engineer

2 months, 2 weeks ago
Full-time
Lead
Artificial Intelligence and Machine Learning
Sumo Logic

Sumo Logic

Sumo Logic offers top-tier cloud monitoring, log management, and Cloud SIEM tools for web and SaaS apps, empowering businesses with real-time insights and high-quality software delivery.

Internet Software & Services
251-1K
Founded 2010

Description

  • Conduct applied and original threat research and translate findings into actionable detection logic.
  • Design, build, and refine detection content and validation pipelines with Threat Labs teammates.
  • Test threat detection logic in lab environments against real-world attacker behaviors.
  • Analyze malware, track infrastructure, and use honeypots to uncover novel attacker behaviors.
  • Investigate industry and adversary trends to identify emerging detection opportunities.
  • Maintain and expand Threat Labs’ research lab infrastructure.
  • Collaborate with product management and engineering to scope, prioritize, and improve detection campaigns.
  • Provide practitioner feedback to product and engineering teams to inform feature design and roadmap decisions.
  • Publish research findings, detection logic, and hunting guidance through blogs, talks, open source, and other public contributions.

Requirements

  • 12+ years of cybersecurity experience in roles such as senior/principal SOC analyst, threat hunter, purple team practitioner, incident responder, or detection engineer.
  • Demonstrated ability to turn threat research into actionable detections and incident response outcomes.
  • Experience conducting original or self-directed threat research that produced novel findings and actionable insights.
  • Broad knowledge of multiple technology stacks and curiosity to learn new platforms.
  • Deep experience with major public clouds such as AWS, Azure, or GCP, including cloud-native logs and telemetry.
  • Understanding of AI-targeted attack techniques such as data poisoning, model theft, or prompt injection, with familiarity in MITRE ATLAS.
  • Proven thought leadership through blogs, LinkedIn articles, or conference presentations.
  • Background in the cybersecurity vendor space and experience giving expert feedback to product and engineering teams.
  • Prior customer-facing technical experience in consulting, remote support, or advisory roles.
  • Hands-on familiarity with offensive security tools such as Atomic Red Team, Sliver, or Cobalt Strike.
  • Scripting or automation experience with Python, PowerShell, or similar tools.
  • Experience with Security Orchestration, Automation, and Response (SOAR) technology.
  • Recognized presence or active participation in the security community through X/Twitter, conferences, or open source.
  • Experience applying AI or machine learning to improve efficiency and automation across the detection rule development lifecycle.

Benefits

  • Expected annual base salary of $162,000 to $190,000.
  • Eligibility for bonus or commission plans for certain roles.
  • Access to company benefits offerings.
  • Opportunity to work on agentic AI-powered SIEM and log analytics at a security-focused platform company.
  • Work that contributes to protecting customers and the broader security community.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Principal Identity Engineer

Hasbro 5K-10K Consumer Goods

Wizards of the Coast is hiring a Principal Identity Engineer to own the technical direction of its enterprise identity architecture, supporting Zero Trust, privileged access, and identity governance across cloud and on-premises environments.

Active Directory CI/CD Git OpenID Connect PowerShell Pulumi Python REST API SAML Terraform
15 hours, 1 minute ago

Senior Device Engineer

Dragos 251-1K Professional Services

Dragos is hiring a Senior Device Engineer to build automation software that identifies, fingerprints, and interacts with network-connected devices across critical infrastructure environments.

Cybersecurity Docker Embedded Systems Go HTTP JavaScript Node.js TCP/IP TLS TypeScript
15 hours, 1 minute ago

Elastic Engineer

Jolera 251-1K Internet Software & Services

Jolera is seeking an Elastic Engineer to design and operate scalable Elasticsearch-based environments for cybersecurity analytics, threat hunting, and detection workflows.

Cybersecurity Elasticsearch Encryption Java Kibana Linux Logstash Machine Learning Python Ruby
15 hours, 31 minutes ago

Staff Software Development Engineer - Windows Endpoint

BeyondTrust 1K-5K Professional Services

BeyondTrust is hiring a Staff Software Development Engineer to own Windows kernel-mode enforcement for its Identity Security Platform, building real-time security controls that decide whether actions on Windows endpoints are permitted or denied.

Agile C C++ Rust
15 hours, 31 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers