Senior Threat Researcher - NDR/IPS/IDS
ExternalPrepare for this interview
EliteAI-generated questions, company research, and talking points tailored to this role
About the role
You'll be working as a Senior Security Developer on our Integration, Detection and Response Team, responsible for ensuring quality and scale of our detection base and presenting actionable detections to our Security Services teams and customers. Some of your day-to-day responsibilities will be: Developing and maintaining high quality custom detection rules (Suricata/Snort/IDS/IPS). Research and develop expertise for various threat surfaces and telemetry available for them Conducting code reviews and providing constructive feedback to ensure code quality and maintainability. Debugging and fixing issues in existing detection/signature codebases. Participate in the full software development life cycle, building well- designed, testable, efficient, secure code. Work with team members to develop novel detections and continuously tune existing ones Understand the product and how Security Services delivers the service. Propose coverage and efficacy improvements to the detection surface Build well-designed, testable, efficient, durable detections Build runbooks, reports and supporting material for detection surface Document research findings and knowledge share with team and other departments Troubleshoot, educate, and share information with non-technical people Continuously learning and adopting best practices for code quality, software development methodologies, and programming principles to enhance coding skills and stay updated with industry advancements. We value a culture of sharing, so every team has the opportunity to share their work with the entire department during our monthly R&D Demos. Once a year we hold a department-wide Hackathon, teaming up across all R&D teams over four days to collaborate and build cool ideas outside the normal project scope. While innovation is the focus, some of these ideas do make it into our products. About You 6 or more years of detection authoring experience with a focus on the following key areas: NDR/IPS/IDS detections/signatures Development of anomaly and behavioural based detections Tuning and optimization of detections Expertise on the inner workings of networking, protocols(TCP/IP, DNS, HTTP), protocol analysers, Suricata/snort rules, and other network-related threat management domain topics, e.g. LDAP, NTLM, etc Proven ability and experience to research and develop security detections related to network threat vectors Experience using MITRE ATT&CK, PCAP analysis, and threat intelligence feeds. Experience with 3rd-party firewalls, IDS/IPS and network edge devices, their capabilities and configuration is a bonus, but minimally understanding their use and vulnerabilities. We use and train a variety of technologies in MDR. You should have a strong understanding of networking, protocols, and cybersecurity. As a detection developer you bring a strong knowledge base that you use to help the team solve complex technical and security problems. Helpful to have experience in the following areas: SIEM detections EDR detections/signatures Sigma and Yara rules Cloud security detections Experience in at least two of the following Development Languages & Methodologies: Python, Go, Java, or C/C++ Test Driven Development Full understanding and use of DevOps methods/tooling Full understanding/application of secure development practices Cloud Development: AWS, Azure, and GCP using Kubernetes/Containers, IaaS, and key PaaS services Agile (SCRUM/Kanban) Experience in following security tooling is a plus: NGFW (PAN, CISCO, Fortinet, etc.) Open Source IPS/IDS/NSM (e.g. Bro/Zeek/Suricata) Why Arctic Wolf? At Arctic Wolf, we foster a collaborative and inclusive work environment that thrives on diversity of thought, background, and culture. This is reflected in our
Benefits
Additional Information
At Arctic Wolf, we're redefining the cybersecurity landscape. With our employee Pack members, spread out globally, committed to setting new industry standards. Our accomplishments speak for themselves, from our recognition in the Forbes Cloud 100 , CNBC Disruptor 50 , Fortune Future 50 , and Fortune Cyber 60 to winning the 2024 CRN Products of the Year award. We're proud to be named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services and earning a Customers' Choice distinction from Gartner Peer Insights . Our Aurora Platform also received CRN's Products of the Year award in the inaugural Security Operations Platform category. Join a company that's not only leading, but also shaping, the future of security operations. Our mission is simple: End Cyber Risk. We're looking for a Detection Developer for IDR team to be part of making this happen. A Security Developer has a clear history of successful contribution to professional detection development projects. They are driven, curious, and results oriented. They are able to manage competing priorities as they relate to improving our existing codebase of detections and constantly challenge the status quo.
Your Match
How well this role fits your profile.
Company Intel
What employees say
Worked at arcticwolf? Share your experience