our mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. In alignment with our company values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day. our mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. In alignment with our company values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.
Responsibilities
Conduct investigations of advanced threat actor activity across cloud, identity, endpoint, and on-premises environments to identify intrusion methods, attacker objectives, and operational patterns.
Identify and track emerging threats, attacker techniques, campaigns, and trends to enable proactive detection, disruption, and defence before customer impact.
Develop detections, mitigations, and security guidance by identifying attack paths, security weaknesses, and opportunities to strengthen defensive coverage.
Build investigative tooling, automations, proof-of-concepts, and research capabilities that improve the scale and effectiveness of security investigations.
Drive product, detection, and engineering improvements by translating investigation findings into actionable changes across our company security platforms and services.
Providing recommendations to improve customers cybersecurity posture going forward and performing threat intelligence knowledge transfer to prepare customers to defend against todays threat landscape
Synthesize complex technical research into clear, actionable intelligence, reports, briefings, and recommendations for technical and executive audiences.
Advance understanding of nation-state, cybercriminal, and emerging threat actors through research, attribution, capability assessments, and adversary tracking.
Share findings, influence strategy, and drive organizational change through knowledge transfer, best practices, and adoption of security improvements.
Requirements: 4+ years of experience in Threat Hunting, Incident Response (DFIR), Threat Intelligence, or Security Research.
Experience investigating sophisticated cyber threats, including APT or nation-state activity.
Experience working with security telemetry, logs, and SIEM platforms.
Familiarity with KQL or equivalent query languages (Splunk, Humio, Kibana, etc.).
Experience with EDR and security monitoring technologies such as our company Defender, Sentinel, CrowdStrike, or similar platforms.
Ability to analyze security data, investigate attacker behavior, and identify indicators of compromise (IOCs), indicators of activity (IOAs), and TTPs.
Understanding of scripting or the ability to read and interpret code and automation workflows.
Strong communication skills in English and ability to work in a global team environment.
Preffered Qualifications
Industry certifications in cybersecurity, DFIR, incident response, or threat hunting (e.g., CISSP, GIAC).
Experience identifying novel attacker techniques and translating findings into scalable detections.
Experience performing malware analysis or reverse engineering.
Experience analyzing large-scale security telemetry and hunting across enterprise environments.
This position is open to all candidates.