Senior Threat Researcher - Endpoint / Cloud

Arctic Wolf

Bengaluru

On-site

INR 4,000,000 - 7,000,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Equity for all employees
Flexible annual leave
Training and career development
Private medical insurance
Parental leave

Job summary

Arctic Wolf is seeking a Senior Threat Researcher to develop high‑quality detections across endpoint, cloud, and network environments. You will research threats, design anomaly‑based detectors, and contribute to the detection engineering team to improve coverage and reduce false positives.

The role emphasizes collaboration, code quality, and scalable detection content, with opportunities to participate in hackathons and knowledge sharing across security teams. Great benefits and growth await.

Qualifications

  • 5+ years of experience authoring and maintaining security detections.
  • Expertise in endpoint, cloud, or network detection and signature development.
  • Experience with anomaly-based and behavioral-based detections.
  • Ability to tune detections to improve fidelity and reduce false positives.
  • Experience using MITRE ATT&CK, packet capture analysis, and threat intel.
  • Knowledge of cybersecurity principles and adversary behaviors.
  • Experience with MDR environments and security monitoring technologies.
  • Nice to have Sigma and YARA rules, cloud detections, and programming skills.

Responsibilities

  • Develop and maintain high-quality detection rules across endpoint, cloud, and network environments.
  • Research emerging threats and telemetry sources to improve coverage.
  • Design and improve anomaly-based and behavioral detections.
  • Conduct code reviews to ensure quality, maintainability, and scalability.
  • Troubleshoot and enhance existing detection codebases.
  • Participate in the full SDLC for detection content.
  • Collaborate to develop innovative detections and tune capabilities.
  • Propose improvements to detection coverage and security visibility.
  • Build runbooks, reports, and documentation for detection surfaces.
  • Document research findings and share knowledge across teams.
  • Communicate complex security concepts to technical and non-technical audiences.
  • Stay current with industry best practices and participate in innovation initiatives.

Skills

Threat detections
Endpoint detections
Cloud detections
Threat intelligence
Sigma rules
YARA rules
Python
Go
Java
C++
DevOps
AWS
Azure
GCP
Kubernetes

Tools

Sigma
YARA

Job description

At Arctic Wolf, you will not just watch the cybersecurity industry evolve – you will help lead the change. Our global team is made up of people who thrive on solving complex problems, moving quickly, and building technology that protects organizations around the world. We are proud to be recognized by Forbes, CNBC, Fortune, CRN, Gartner Peer Insights, and International Data Corporation MarketScape. What matters most is the work behind these recognitions: delivering real outcomes for customers through award-winning innovation such as our Aurora Platform. If you are looking for meaningful work, smart teammates, and the opportunity to make a real impact in a high-growth company that is redefining security operations, Arctic Wolf is the right place for you. Our mission is simple: End Cyber Risk.

We are looking for a Senior Threat Researcher Endpoint/Cloud - Detections to help achieve this mission.

The Senior Threat Researcher Endpoint/Cloud - Detections will contribute to our Detection Engineering organization by developing, maintaining, and enhancing advanced security detections across endpoint, cloud, and network environments.

This role will focus on building high-quality detection content, improving detection efficacy, researching emerging threats, and delivering actionable intelligence that helps protect Arctic Wolf customers from evolving cyber threats.

IN THIS ROLE, YOU WILL:
  • Develop and maintain high-quality custom detection rules across endpoint, cloud, and network environments
  • Research emerging threats, attack techniques, and telemetry sources to improve detection coverage and effectiveness
  • Design, develop, and continuously improve anomaly-based and behavioral-based detections
  • Conduct code reviews and provide constructive feedback to ensure code quality, maintainability, and scalability
  • Troubleshoot, debug, and enhance existing detection and signature codebases
  • Participate in the full software development life cycle by building secure, efficient, testable, and maintainable detection content
  • Collaborate with team members to develop innovative detections and continuously tune existing detection capabilities
  • Propose improvements to detection coverage, efficacy, and overall security visibility
  • Build runbooks, reports, documentation, and supporting materials for detection surfaces
  • Document research findings and share knowledge across engineering, security operations, and research teams
  • Communicate technical concepts and security findings effectively to both technical and non-technical audiences
  • Continuously learn and adopt industry best practices in software development, detection engineering, and cybersecurity
  • Participate in research and development demonstrations, innovation initiatives, and annual hackathon events that contribute to future product capabilities
YOU WILL BE SUCCESSFUL IN THIS ROLE IF:
  • You have 5 or more years of experience authoring and maintaining security detections
  • You have strong expertise in endpoint, cloud, or network detection and signature development
  • You have experience developing anomaly-based and behavioral-based detections
  • You have extensive experience tuning and optimizing detections to improve fidelity and reduce false positives
  • You have experience using MITRE ATT&CK, packet capture analysis, and threat intelligence sources to drive detection development
  • You have strong knowledge of cybersecurity principles, threat detection methodologies, and adversary behaviors
  • You have experience working with security monitoring and detection technologies within Managed Detection and Response environments
  • You are passionate about solving complex security challenges and continuously improving detection capabilities
Helpful to Have:
  • Experience developing Security Information and Event Management detections
  • Experience creating Endpoint Detection and Response detections and signatures
  • You possess knowledge of networking concepts, protocols, and authentication technologies including Transmission Control Protocol/Internet Protocol, Domain Name System, Lightweight Directory Access Protocol, and New Technology LAN Manager
  • You have proven experience researching and developing detections related to network-based threat vectors
  • Experience authoring Sigma and YARA rules
  • Experience developing cloud security detections
  • Experience with programming languages such as Python, Go, Java, or C++
  • Experience with Test Driven Development methodologies
  • Experience using DevOps practices, tooling, and automation frameworks
  • Experience applying secure software development practices
  • Experience building and deploying solutions in cloud environments including Amazon Web Services, Microsoft Azure, and Google Cloud Platform
  • Experience working with Kubernetes, containers, infrastructure-as-a-service, and platform-as-a-service technologies
  • Experience working within Agile software development methodologies including Scrum and Kanban
  • Experience with Next Generation Firewall technologies from vendors such as Palo Alto Networks, Cisco, or Fortinet
  • Experience using open-source intrusion detection, intrusion prevention, and network security monitoring technologies such as Zeek or Suricata

Do not meet all the requirements? That is okay. We have many opportunities and are always looking for strong talent.

On-Camera Policy

To support a fair, transparent, and engaging interview experience, candidates interviewing remotely are expected to be on camera during all video interviews. Being on camera fosters authentic connection, improves communication, and allows for full engagement from both candidates and interviewers. We understand that technical, bandwidth, or location-related challenges may occasionally prevent video use. If this applies, candidates are required to notify us in advance so we can explore appropriate accommodations.

At Arctic Wolf, we foster a collaborative and inclusive work environment that thrives on diversity of thought, background, and culture. This is reflected in our multiple awards, including Top Workplace United States, Best Places to Work United States, Great Place to Work Canada, Great Place to Work United Kingdom, and Kununu Top Company Germany. Our commitment to bold growth and shaping the future of security operations is matched by our dedication to customer satisfaction, with over 10,000 customers worldwide and more than 2,000 channel partners globally. As we continue to expand and enhance our technology, Arctic Wolf remains a trusted name in the industry.

Our Values

Arctic Wolf recognizes that success comes from delighting our customers, so we work together to ensure that happens every day. We believe in diversity and inclusion and value the unique perspectives all employees bring to the organization. By protecting sensitive data and working to end cyber risk, we contribute to an industry that serves the greater good. We celebrate diverse perspectives through our Pack Unity program and encourage employees to participate in or create new alliances. We also believe in corporate responsibility and have joined the Pledge One Percent movement to give back to our communities.

All employees receive compelling compensation and benefits packages, including:

  • Equity for all employees
  • Flexible annual leave, paid holidays, and volunteer days
  • Training and career development programs
  • Comprehensive private benefits plan including medical insurance for you and your family, life insurance equal to three times compensation, and personal accident insurance
  • Fertility support and paid parental leave

Arctic Wolf is an equal opportunity employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under applicable law. We are committed to fostering a welcoming, accessible, and inclusive environment.

Security Requirements
  • Conduct duties in accordance with Arctic Wolf information security policies, standards, and controls
  • Background checks are required for this position
  • This role may require access to information protected under United States export control laws and regulations

Arctic Wolf is focused on building a workforce that is diverse and inclusive.

We review all applications.

Arctic Wolf is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetics, or any other basis forbidden under federal, provincial, or local law.

Arctic Wolf is committed to fostering a welcoming, accessible, respectful and inclusive environment ensuring equal access and participation for people with disabilities. As such, we strive to make our recruitment, assessment and selection processes as accessible as possible and provide accommodations as required for applicants with disabilities.

If you require a reasonable accommodation for any part of the application or hiring process, you may make a request by calling the Arctic Wolf general contact number at 1-888-272-8429 and asking to speak to Recruiting, or by emailing recruiting@arcticwolf.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Manager Threat Research (Integration-Detections)
Manager Threat Research (Integration-Detections)

Arctic Wolf Networks India Private Limited • Bengaluru

Hybrid
INR 4,000,000 - 7,000,000
Equity
Flexible leave
Medical insurance
+2
Senior Staff Developer - AI
Senior Staff Developer - AI

Arctic Wolf • Bengaluru

On-site
INR 4,500,000 - 7,500,000
Equity for all employees
Flexible annual leave and holidays
Training and career development
Senior Staff Developer - AI
Senior Staff Developer - AI

Arctic Wolf Networks India Private Limited • Bengaluru

On-site
INR 4,000,000 - 8,000,000
Equity for all employees
Flexible annual leave
Training and career development
+2
Senior Staff Developer - AI SOC Automation
Senior Staff Developer - AI SOC Automation

Arctic Wolf • India

On-site
INR 4,000,000 - 8,000,000
Equity for all
Flexible leave and holidays
Training and career development
+1
Manager Threat Research (Integration-Detections)
Manager Threat Research (Integration-Detections)

Arctic Wolf • Karnataka

On-site
INR 350,000 - 600,000
Equity for all employees
Flexible annual leave
Training and career development
+2
Threat Intelligence Researcher
Threat Intelligence Researcher

Arctic Wolf • Bengaluru

On-site
INR 1,800,000 - 2,600,000
Equity for all employees
Private medical insurance
Life insurance
Senior Threat Researcher (Integrations Team)
Senior Threat Researcher (Integrations Team)

Arctic Wolf Networks India Private Limited • Bengaluru

On-site
INR 2,800,000 - 6,000,000
Equity for all employees
Comprehensive private benefits plan
Fertility support and paid parental le
Staff Developer
Staff Developer

Arctic Wolf Networks India Private Limited • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Equity for all employees
Flexible annual leave
Training and career development
+1
Staff Developer-Vulnerability Detection
Staff Developer-Vulnerability Detection

Arctic Wolf • Bengaluru

On-site
INR 2,600,000 - 4,800,000
Equity for all employees
Flexible annual leave
Training and career development
+2
Senior Threat Researcher (Integrations Team)
Senior Threat Researcher (Integrations Team)

Arctic Wolf • Bengaluru

On-site
INR 3,500,000 - 5,200,000