
Threat Researcher
2 weeks ago
About The Team
Arctica Wolf Threat Content Team is the owner and intellectual author of the telemetry and detection rules of our Aurora Focus (EDR) product, part of Aurora Endpoint Defense. Our team started 3 years ago in BlackBerry-Cylance. Since then we have developed internal tools to streamline daily tasks, defined work standards for content creation (detection/telemetry rules), and high fidelity content (fine-tune processes, reduce false positives). We have quality assurance processes (Unit Test, Regression and E2E Testing) and communication channels with Threat Intel and S2. We work with MDR, TRI, AR and CTI teams to stay ahead with latest findings and continually protect our clients. We actively participate in purple teaming exercises and maintain two MITRE accreditations (Enterprise 2023 - Turla; Managed Services 2024 - MenuPass + BlackCat) as EDR Blue Teamers.
We are on the lookout for new attacks, 0days, TTP updates, and threat intelligence to keep our clients protected.
About The Role And Responsibilities
Analyze, research, and develop new content for Aurora Focus, applying the MITRE ATT&CK framework.
Convert investigations from Threat Teams (TRI/AR/CTI) into new content (detection/telemetry rules).
Customer Escalation (BFD): collaborate with S2 on investigations regarding emerging threats to generate new detection rules.
Fine-tuning: determine true threats vs. false positives and provide solutions (exclusions, logic changes, or reducing severity).
Python scripting to automate internal tools or projects.
Manage multiple tasks simultaneously; coordinate and meet scheduled goals.
Maintain up-to-date documentation for new tools or processes.
Run regression and end-to-end testing; push production releases and notification emails.
Participate in Purple Teaming exercises.
Generate metrics over Databricks Dashboard.
Deliver regular threat briefing presentations to internal and external stakeholders on threat actor activity, novel TTPs, and emerging malware or exploits.
Utilize best practices for threat research and documentation and deliver high-quality detection rules.
About You
Relevant experience in threat intelligence or threat research roles.
Experience applying the MITRE ATT&CK framework to intelligence products and depth of analysis for each TTP and threat actor.
Experience analyzing application and infrastructure telemetry (logs, network flow, audit logs, metrics, core dumps).
Experience analyzing phishing and malware campaigns, exploited vulnerabilities, supply chain attacks, and data breaches.
Understanding of threat protection/detection tooling: SIEM, XDR/EDR.
Experience with Python scripting. Understanding of JSON and regex.
Linux and MacOS terminal usage; basic .sh/.bat scripting; Windows Sysinternals.
Experience using Git repositories; Virtual Machines (VMware).
SQL knowledge; Databricks is a plus. Lolbins/Lolbas knowledge; Sigma Rules knowledge.
Excellent written and verbal communication skills; resourceful self-starter with a positive, can-do attitude.
Nice To Have
Experience with Agile methodology.
Experience using Elastic Stack (Elasticsearch, Kibana) or Grafana.
Presented on cybersecurity or threat intelligence at industry conferences or meetups.
Participation in ISACs, trust groups, or intelligence partnerships.
CISSP, OSCP, GCTI or other relevant certifications are a plus.
Interview Process
Phone pre-screening: brief discussion of work history and overview of Arctic Wolf. Approximately 30 minutes.
Technical assessment: threat intelligence assessment to demonstrate strategic thinking, analytical skills, and technical understanding of TTPs, malware, vulnerabilities, and exploits.
Face-to-face interviews: discussions with several team members; discuss the technical assessment, collaborate on a technical problem, and review past projects and career goals. Approximately 1 hour per interview.
Security Requirements
Work in accordance with AW’s Information Security policies, standards, processes, and controls to protect information assets.
Must pass a criminal background check and employment verification as a condition of employment.
Seniority level
Entry level
Employment type
Full-time
Job function
Information Technology
Industries
Computer and Network Security
Referrals increase your chances of interviewing at Arctic Wolf by 2x
#J-18808-Ljbffr
-
Sr. Threat Research Engineer
2 weeks ago
Cork, Ireland Proofpoint Full timeOverviewJoin to apply for theSr.Threat Research Engineerrole atProofpointWe are the leader in human-centric cybersecurity.Proofpoint helps organizations protect their data and people from targeted threats across email, cloud, social media, and the web.RoleYou are a Senior CyberSecurity Analyst (email borne threats) or have a strong desire and a skill set to...
-
Lead Threat Researcher
2 weeks ago
Cork, Ireland Arctic Wolf Full timeLead Security Developer page is loaded## Lead Security Developerlocations: Cork, IRLtime type: Full timeposted on: Posted 2 Days Agojob requisition id: R25\_1291**Lead Security Developer****About the Role**A Lead Developer - Security is both a cybersecurity expert and an experienced detections developer for endpoint, network or cloud.They research and curate...
-
Principal Security Analyst | Hybrid Cork
3 weeks ago
Cork, Ireland OpenText Full timeJoin to apply for the Principal Security Analyst role at OpenText . OpenText is a global leader in information management, emphasizing innovation, creativity, and collaboration. As part of our team, you'll partner with top companies, tackle complex issues, and contribute to shaping the future of digital transformation. AI-First. Future-Driven....
-
▷ [Urgent] Security Developer
1 week ago
Cork, Ireland Arctic Wolf Full timeJoin to apply for the Security Developer role at Arctic Wolf Overview At Arctic Wolf, we're not just navigating the cybersecurity landscape - we're redefining it. Our global team of dedicated Pack members is driving innovation and setting new industry standards every day. Our impact speaks for itself: we've earned recognition on the Forbes Cloud 100,...
-
Mss Analyst
1 week ago
Cork, Ireland Malwarebytes Inc. Full timeMalwarebytes began after our founder, Marcin Kleczynski, accidentally infected his parents' computer while downloading a video game as a teenager.At the time, there was no product that could fully solve the problem, so he set out to build one.That early experience shaped our mission: to create protection that works when people need it most.About...
-
Penetration Testing Engineer
4 days ago
Cork, Ireland Mckesson Full timeOverviewMcKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare.We are known for delivering insights, products, and services that make quality care more accessible and affordable.Here, we focus on the health, happiness, and well-being of you and those we serve – we care.What you do at McKesson matters.We foster a...
-
Urgent Search! Systems Administrator
1 week ago
Cork, Ireland PFH Technology Group Full timePFH Technology are looking for a Systems Administrator to join our client's growing team in Ringaskiddy. The Systems Administrator resource will: Provide third level technical support and meet our Customer SLA's Be responsible for ensuring the IT infrastructure network systems and servers are maintained to best practice as stated in the document Recognise...
-
Payroll Co-Ordinator
4 weeks ago
Cork, Ireland TrendMicro Full timeTrend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, Trend Micro's cybersecurity platform protects hundreds of thousands of organizations and millions of individuals across clouds, networks, devices, and endpoints....
-
Retention Sales Manager Dutch speaking
1 week ago
Cork, Ireland TrendMicro Full timeRetention Sales Manager Dutch speaking page is loaded Retention Sales Manager Dutch speaking Apply locations Cork time type Full time posted on Posted Yesterday job requisition id R0007437 Discover Trend Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise,...
-
R&D Escalation Engineer
3 weeks ago
Cork, Ireland Varonis Full timeVaronis Systems is the leader in unstructured and semi-structured data governance software, which is any human-generated data that is within a company's environment.Our goal is to protect companies' most sensitive information from insider threats and cyberattacks.We do this by allowing organizations to analyze, secure, manage, and migrate their volumes of...