Jobs › Companies › Arctic Wolf › Senior Threat Researcher (Integrations Team)

Über diese Senior Threat Researcher (Integrations Team) Stelle bei Arctic Wolf

Arctic Wolf · Vor Ort · Bengaluru, IND

At Arctic Wolf, you will not just watch the cybersecurity industry evolve – you will help lead the change. Our global team is made up of people who thrive on solving complex problems, moving quickly, and building technology that protects organizations around the world. We are proud to be recognized by Forbes, CNBC, Fortune, CRN, Gartner Peer Insights, and International Data Corporation MarketScape. What matters most is the work behind these recognitions: delivering real outcomes for customers through award-winning innovation such as our Aurora Platform.

If you are looking for meaningful work, smart teammates, and the opportunity to make a real impact in a high-growth company that is redefining security operations, Arctic Wolf is the right place for you.


Our mission is simple: End Cyber Risk.


We are looking for a Senior Threat Researcher -Cloud & Endpoint Detection to join our Integrations Team and help achieve this mission.


We are responsible for developing high-fidelity threat detections and analytics using telemetry collected from third-party security, identity, cloud, email, and endpoint integrations.

This role sits at the intersection of security research, detection engineering, and integrations. The primary responsibility is to analyse data ingested from integrated security providers and transform that telemetry into actionable detection rules, correlation logic, and attack coverage. Initially, the role will focus heavily on detections powered by data from third-party integrations, with opportunities to expand coverage across cloud, identity, endpoint, and SaaS ecosystems as new integrations are onboarded.

The ideal candidate has a strong understanding of attacker behaviour, security telemetry, and detection engineering, with the ability to quickly learn new vendor schemas, APIs, and event models to identify meaningful detection opportunities.


IN THIS ROLE, YOU WILL:


Third-Party Integration Detection Development

  • Serve as the detection subject matter expert within the Integrations Team.
  • Develop detections, correlation rules, and analytics based on telemetry ingested from third-party integrations.
  • Analyse vendor APIs, audit logs, alerts, and event schemas to identify security detection opportunities.
  • Design detection coverage that leverages data from integrated security products, cloud providers, identity platforms, email security solutions, and endpoint security tools.
  • Partner closely with integration engineers to understand newly onboarded data sources and maximize security value from collected telemetry.

Detection Research

  • Research emerging threats, attack techniques, and adversary tactics.
  • Identify opportunities to detect malicious activity using third-party security and SaaS telemetry.
  • Map detections to the MITRE ATT&CK framework and maintain alignment with evolving threat landscapes.
  • Continuously improve existing detections by reducing false positives and increasing attack coverage.

Security Domain Coverage

  • Develop detections across multiple security domains, including:

Identity & Access Security

  • Account takeover
  • MFA abuse and bypass
  • Privilege escalation
  • Suspicious administrative activity
  • Service account misuse
  • OAuth and application abuse

Email Security

  • Business Email Compromise (BEC)
  • Phishing campaigns
  • Malicious attachment activity
  • Email forwarding rule creation
  • Suspicious mailbox access
  • Abnormal email behaviours

Endpoint Security

  • Malware and ransomware activity
  • Credential theft techniques
  • Suspicious process execution
  • Persistence mechanisms
  • Lateral movement
  • Defense evasion
  • Living-off-the-land techniques
  • Endpoint compromise indicators

Cloud Security

  • Excessive permission changes
  • Suspicious cloud administration activity
  • Data exfiltration attempts
  • Resource misconfigurations
  • Cloud account abuse
  • Workload compromise activity

Detection Validation & Quality

  • Validate detections against attack simulations, threat scenarios, and real-world telemetry.
  • Assess data quality and telemetry completeness across integrations.
  • Continuously monitor detection performance and effectiveness.
  • Identify gaps in attack coverage and recommend enhancements.

Cross-Functional Collaboration

  • Collaborate with Integration Engineers, Product Managers, Detection Engineers, Threat Researchers, and SOC teams.
  • Provide requirements and feedback for new integrations to ensure detection-readiness.
  • Help shape onboarding strategies for new vendors by identifying telemetry needed for meaningful security analytics.
  • Influence normalization and data-modelling efforts to support scalable detection development.

WE’RE LOOKING FOR SOMEONE WITH EXPERIENCE IN:

  • 6+ years of experience in Detection Engineering, Threat Hunting, Security Research, SOC Engineering, or Security Analytics.
  • Experience building detections using telemetry from cloud, endpoint, identity, email, or security platforms.
  • Ability to analyse new third-party integrations, understand vendor-specific schemas and APIs, and rapidly develop detection coverage from ingested telemetry.
  • Hands-on experience with one or more detection technologies such as KQL, SPL, Sigma, SQL, or equivalent analytics languages.
  • Strong understanding of security telemetry, event correlation, and detection tuning.
  • Experience working with data from security products, cloud platforms, identity providers, or SaaS applications.
  • Familiarity with endpoint, identity, cloud, and email security telemetry.
  • Ability to analyse unfamiliar security event schemas and rapidly build detections from new data sources.
  • Good understanding of adversary tactics, techniques, and procedures (TTPs) and the MITRE ATT&CK framework.

NICE TO HAVE:

  • Experience with SIEM, XDR, MDR, CNAPP, or Identity Threat Detection platforms.
  • Familiarity with security data normalization frameworks such as OCSF.

IDEAL CANDIDATE PROFILE

The ideal candidate is passionate about turning third-party security telemetry into actionable detections. They are comfortable diving into a newly onboarded integration, understanding the data model, identifying attacker-relevant events, and rapidly developing detection coverage. Success in this role will be measured by the ability to maximize security value from integrated data sources and deliver meaningful detection coverage across the growing integration ecosystem.

This role is ideal for professionals from Detection Engineering, Threat Hunting, Security Research, SOC Content Development, MDR/XDR Detection Teams, Endpoint Detection Engineering, or CNAPP Security Teams who are passionate about understanding attacker behaviour and transforming security telemetry from cloud, endpoint, identity, email, and third-party security integrations into actionable detections at scale.


Do not meet all the requirements? That is okay. We still encourage you to apply. We have many opportunities and are always looking for strong talent.


On-Camera Policy

To support a fair, transparent, and engaging interview experience, candidates interviewing remotely are expected to be on camera during all video interviews. Being on camera fosters authentic connection, improves communication, and allows for full engagement from both candidates and interviewers. We understand that technical, bandwidth, or location-related challenges may occasionally prevent video use. If this applies, candidates are required to notify us in advance so we can explore appropriate accommodations.

At Arctic Wolf, we foster a collaborative and inclusive work environment that thrives on diversity of thought, background, and culture. This is reflected in our multiple awards, including Top Workplace United States, Best Places to Work United States, Great Place to Work Canada, Great Place to Work United Kingdom, and Kununu Top Company Germany. Our commitment to bold growth and shaping the future of security operations is matched by our dedication to customer satisfaction, with over 10,000 customers worldwide and more than 2,000 channel partners globally. As we continue to expand and enhance our technology, Arctic Wolf remains a trusted name in the industry.


Our Values

Arctic Wolf recognizes that success comes from delighting our customers, so we work together to ensure that happens every day. We believe in diversity and inclusion and value the unique perspectives all employees bring to the organization. By protecting sensitive data and working to end cyber risk, we contribute to an industry that serves the greater good.

We celebrate diverse perspectives through our Pack Unity program and encourage employees to participate in or create new alliances.

We also believe in corporate responsibility and have joined the Pledge One Percent movement to give back to our communities.

All Employees Receive Compelling Compensation And Benefits Packages, Including

  • Equity for all employees
  • Flexible annual leave, paid holidays, and volunteer days
  • Training and career development programs
  • Comprehensive private benefits plan including medical insurance for you and your family, life insurance equal to three times compensation, and personal accident insurance
  • Fertility support and paid parental leave

Arctic Wolf is an equal opportunity employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under applicable law. We are committed to fostering a welcoming, accessible, and inclusive environment.


Security Requirements

  • Conduct duties in accordance with Arctic Wolf information security policies, standards, and controls.
  • Background checks are required for this position.
  • This role may require access to information protected under United States export control laws and regulations, including the Export Administration Regulations. If applicable, an offer of employment will be conditioned upon authorization to receive software or technology controlled under these regulations.

 

Bereit, sich bei Arctic Wolf zu bewerben?
Bei Arctic Wolf bewerben

Über Arctic Wolf

At Arctic Wolf, we recognize that success comes from delighting our customers. We believe in being lean – in constantly building, measuring, and learning in all aspects of our business. We truly value people. All wolves are welcome to join the Arctic Wolf pack, with compelling compensation packages, benefits, and equity for employees. Arctic Wolf is focused on building a workforce that is diverse and inclusive. If you’re excited about this role, but do not meet all of the qualifications listed above, we encourage you to apply. We review all applications. Arctic Wolf is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, sexual o

Alle Jobs bei Arctic Wolf ansehen →

Ähnliche Jobs

Arctic Wolf
Threat Researcher -Cloud & Endpoint Detection
Arctic Wolf
⚡ Früh bewerben Bengaluru, IND Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
Arctic Wolf
Threat Researcher
Arctic Wolf
⚡ Früh bewerben Bengaluru, IND Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.
Arctic Wolf
Senior Threat Researcher Endpoint/Cloud - Detections
Arctic Wolf
⚡ Früh bewerben Bengaluru, IND Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Mon.
SJ
Postdoctoral Research Fellow — Mechanisms of Pediatric Cancer Dependencies
St. Jude Children's Research Hospital
⚡ Früh bewerben Memphis, TN Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 7 Std.
SJ
Researcher or Senior Researcher - Geeleher Lab (Wet Lab)
St. Jude Children's Research Hospital
⚡ Früh bewerben Memphis, TN Vor Ort $54,080–$94,640
● Neu 👁 Gesehen ✓ Beworben vor 7 Std.
Wargaming
UX Researcher
Wargaming
⚡ Früh bewerben Austin Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 8 Std.
FO
FSP Sr. Clinical Research Associate II - Colorado, Nevada, Utah - Ophthalmology
Fortrea
⚡ Früh bewerben Remote Colorado · standortgebunden $125,000–$142,000
● Neu 👁 Gesehen ✓ Beworben vor 8 Std.
FO
Clinical Research Associate II - Oncology Gynecology / Hematology / Breast Cancer - Barcelona
Fortrea
⚡ Früh bewerben Barcelona Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 8 Std.
FO
Senior Clinical Research Associate - Melbourne / Sydney
Fortrea
⚡ Früh bewerben Melbourne Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 8 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Arctic Wolf

Alle Jobs bei Arctic Wolf ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos