Senior Staff Threat Researcher
Arctic Wolf
Job Overview
Who's the hiring manager?
Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Job Description
Senior Staff Threat Researcher
At Arctic Wolf, we're not just navigating the cybersecurity landscape - we're redefining it. Our global team of dedicated Pack members is driving innovation and setting new industry standards every day. Our impact speaks for itself: we've earned recognition on the Forbes Cloud 100, CNBC Disruptor 50, Fortune Future 50, and Fortune Cyber 60 lists, and we recently took home the 2024 CRN Products of the Year award. We’re proud to be named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services and earning a Customers' Choice distinction from Gartner Peer Insights. Our Aurora Platform also received CRN’s Products of the Year award in the inaugural Security Operations Platform category. Join a company that’s not only leading, but also shaping, the future of security operations.
Our mission is simple: End Cyber Risk. We’re looking for a Senior Staff Threat Researcher to be part of making this happen.
About the Role
You’ll be working as a Senior Staff Threat Researcher within Integrations, Detection, & Response (IDR) reporting directly to the Director of Integrations, Detections, & Response while working closely with Pipeline, Platform, Threat Enablement, and AI teams. This individual will be responsible for providing multiple teams with technical direction to deliver high value, performant solutions. They will provide technical guidance and direction to multiple teams of developers through the design, implementation, and automated/integration testing of our software. This individual will have a clear history of successful contribution to professional detection development projects; they are driven, curious, and results oriented; they can manage competing priorities as they relate to improving existing our existing codebase of detections and constantly challenge the status quo.
Day-to-Day Responsibilities
- Act as a mentor to R&D technical leaders.
- Apply broad expertise and knowledge in highly specialized fields or several related disciplines.
- Lead and contribute to the development of company objectives and principles to achieve goals in creative and effective ways. Produce specifications and determine operational feasibility.
- Work on significant and unique issues where analysis of situations or data requires an evaluation of intangibles.
- Apply conceptual thinking to understand advanced issues and implications.
- Exercise independent judgment in methods, techniques, and evaluation criteria for obtaining results.
- Accountable for results, which may impact the entire function.
- Create formal networks involving coordination among groups.
- Focus on providing thought leadership and work on broader organizational projects which require understanding of wider business, by conveying advanced information and persuading several diverse stakeholders/audiences.
- Recognized internally and externally as a subject matter expert.
- May direct the work of others.
About You
You are a highly advanced developer who makes important product decisions regarding direction and scope. You make informed decisions about which team members should work on which areas of a project and provide technical and professional leadership for the developers as well as work closely with surface domain directors regarding strategic planning. You identify and collaborate with multiple teams or organizations and have a deep understanding of system internals, networking, and technical trends. In addition, you are comfortable presenting to the executive team.
Basic Qualifications
- 10+ years of professional experience as a security architect, detection developer, reverse engineer, security researcher, or CNO developer
- Expert‑level Python expertise
- OS‑specific telemetry (Windows Security/Sysmon logs, Linux, MacOS)
- Windows PowerShell monitoring
- SIEM detections
- EDR detections/signatures
- Suricata, Sigma, and Yara rules
- Development of anomaly‑ and behavioral‑based detections
- Tuning and optimization of detections for all the above
Leadership & Technical Impact
- Experience leading and mentoring groups of developers while contributing code independently
- Experience designing and building detection frameworks and processes
- Experience managing and measuring security efficacy of detections
- Experience managing and measuring cost efficiency of detection frameworks
- Deep understanding of networking security principles and flows
- Experience leading Agile development teams, preferably with formal Agile training
Nice to Have
- Understanding of the Arctic Wolf service delivery model
- Experience with the Arctic Wolf detection framework and infrastructure
- Commitment to continuous learning and skills development
- B.Sc. in a technical field (CS, CE, EE, Math, Physics, etc.) with M.Sc./PhD preferred
In addition, you have proven leadership experience from previous projects, regardless of title held. You have the ability to perform programming tasks and large engineering projects with independence and expertise. You will be responsible for guiding and mentoring other staff members and will regularly lead technical projects. You have a high level of mastery over software development best practices, security research and building reusable software based on that research. You have a history of delivering successful projects, as well as some lessons learned from failures.
Key skills/competency
- Threat Research
- Detection Engineering
- Python Programming
- OS Telemetry
- SIEM/EDR Detections
- Security Architecture
- Cybersecurity Leadership
- Anomaly Detection
- Behavioral Analysis
- Agile Development
How to Get Hired at Arctic Wolf
- Research Arctic Wolf's culture: Study their mission, values, recent news, and employee testimonials on LinkedIn and Glassdoor.
- Tailor your resume: Highlight extensive experience in threat research, detection engineering, and Python expertise for this Senior Staff Threat Researcher role.
- Showcase technical leadership: Provide examples of mentoring developers, leading technical projects, and influencing product direction.
- Prepare for deep technical discussions: Expect in-depth questions on OS telemetry (Windows, Linux, MacOS), SIEM, EDR, Suricata, Sigma, and Yara rules.
- Demonstrate problem-solving: Be ready to discuss how you analyze complex security issues and develop creative, effective detection strategies.
Frequently Asked Questions
Find answers to common questions about this job opportunity
Explore similar opportunities that match your background