Threat Intelligence Researcher (Cloud)

5 days, 2 hours ago
Full-time
Senior
Cybersecurity
Wiz

Wiz

Wiz is a leading cloud security platform trusted by Fortune 100 companies to prevent data breaches and vulnerabilities, enabling faster and secure cloud development.

IT Services
251-1K
Founded 2020
$900M raised

Description

  • Identify, analyze, and track advanced state-backed and financially motivated attackers targeting cloud ecosystems.
  • Hunt across a wide range of data sources to identify malicious campaigns affecting Wiz customers.
  • Leverage open and closed data to track attacker infrastructure and malware.
  • Investigate and attribute incidents, campaigns, and threat actors to understand attacker behavior and motivation.
  • Communicate novel threat findings to customers and the public.
  • Build out actor tracking efforts and take on multiple roles as needed.
  • Report on advanced threats targeting cloud environments.

Requirements

  • 5+ years of experience in security or threat research, with a focus on advanced state-backed actors or sophisticated financially motivated campaigns.
  • Proven track record of tracking sophisticated threat actors.
  • Ability to find novel and durable ways to identify and track threat actors across multiple datasets.
  • Deep subject matter expertise in at least one actor-tracking mechanism, such as malware or infrastructure.
  • Experience working with large-scale telemetry, especially infrastructure hunting, query languages, and scripting.
  • Familiarity with malware analysis and using YARA to hunt for malware.
  • Willingness to take on multiple roles to build out actor tracking.
  • Knowledge of how attackers target AWS, GCP, Azure, Kubernetes, and modern cloud-native architectures (preferred).
  • Experience building tools to exploit data sources in a repeatable and scalable manner (preferred).
  • Track record of public communication of novel and newsworthy findings (preferred).
  • Background in incident response, threat intelligence, or threat hunting (preferred).
  • Applicants must have the legal right to work in the country where the position is based without visa sponsorship.

Benefits

  • Medical, dental, and vision insurance.
  • Home office setup reimbursement.
  • Flexible spending accounts.
  • Monthly connectivity reimbursement.
  • Employee Assistance Program (EAP).
  • Short- and long-term disability insurance.
  • Life and accident insurance.
  • 401(k) retirement savings plan with employer match.
  • Flexible paid time off plus 11 paid holidays.
  • Paid leave programs including parental, pregnancy health, medical, and bereavement leave.
  • Competitive base salary of $160,000 to $220,000 USD annually.
  • Potential incentive compensation.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Data Protection Operations Lead

Airbnb 5K-10K Hotels, Restaurants & Leisure

Airbnb is hiring a Canada-remote Risk and Compliance Operations professional to shape privileged access management governance, controls, and reporting for Community Support and related teams.

Active Directory AWS Azure GCP OAuth OpenID Connect SAML SQL
1 hour, 20 minutes ago

Cyber Security Analyst

Centorrino Technologies 51-250 Internet Software & Services

Centorrino Technologies is seeking a Cyber Analyst in Melbourne and/or Perth to monitor and strengthen customer security operations and incident response, with NV1 security clearance required.

SIEM
21 hours, 5 minutes ago

Senior Data Protection Analyst (DLP)

One Park Financial 51-250 Diversified Financial Services

One Park Financial is hiring a Senior Data Protection Analyst in Miami to lead data egress and collaboration security efforts that protect sensitive customer and company information across communications and identity systems.

Python
1 day, 4 hours ago

Incident Response Analyst III

ZoomInfo 1K-5K Professional Services

ZoomInfo is hiring a Security Incident Response Analyst to join its US-remote Threat Detection and Response team, where the role focuses on protecting the company’s people, products, and data by detecting, investigating, and responding to security threats.

Cybersecurity SIEM
1 day, 14 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers