Monitor and investigate potential security threats using tools such as Kibana/OpenSearch and Snowflake.
Analyze security logs and investigate suspicious or unusual activity, including spikes in traffic, unexpected changes in attack patterns, and new or disappearing attack signals.
Determine whether detected activity is malicious or benign and identify the appropriate response, including detection engineering to block malicious activity when needed.
Develop, tune, and deploy detection rules based on traffic behavior, HTTP request attributes, headers, device fingerprints, and other indicators to mitigate malicious activity.
Monitor existing detections and known attack patterns to make sure they continue to work as expected and identify any unusual changes in volume, sources, IPs, domains, or other indicators.
Support customer onboarding by analyzing web application traffic flows and configuring baseline detection and protection rules.
Investigate customer-reported incidents and missed detections, analyze attack traffic, and implement mitigations to improve protection coverage.
Document newly discovered threats and attacks, including evidence, findings, and indicators.
Communicate findings to Engineering and other stakeholders and provide the necessary technical details to support remediation and improvements to detection and protection mechanisms.
Partner directly with counterparts through a ticketing system and support portal to investigate issues, provide updates, and resolve security-related requests.
3–5 years of experience in Cybersecurity, Threat Research, or Threat Intelligence
Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or a related field
Strong understanding of web technologies and networking fundamentals, including HTTP/HTTPS, TCP/IP, DNS, authentication, cookies, and browser-server interactions
Experience in web security research, bot management, fraud detection, or related domains
Hands-on experience with threat investigations, IOC analysis, and threat intelligence research
Experience with log analysis and investigation platforms such as Kibana/OpenSearch, Snowflake, Datadog, or similar tools
Strong SQL skills, including working with large datasets and UDFs
Basic knowledge of JavaScript for web and client-side analysis
Strong analytical and problem-solving skills
Ability to work independently and manage investigations with minimal supervision
Strong communication and collaboration skills
Passion for cybersecurity and continuous learning
NICE TO HAVE:
Knowledge of MITRE ATT&CK, malware analysis, vulnerabilities, and adversary TTPs
OSINT and cyber threat intelligence research experience
Python and Jupyter Notebook experience for investigations and automation
Experience with GitHub and version control workflows