$ cat jobs/staff-threat-research-engineer-sumo-logic-fede53d28fab.json
Staff Threat Research Engineer
Mission Threat Labs’ mission is to keep our customers safe from cybersecurity attacks. We do this by advancing the art and science of detection: turning threat intelligence and threat research into practical, high‑quality detections that power the Sumo Logic SIEM platform and strengthen the broader security community. About the Role We’re looking for a staff‑level threat researcher who thrives at the intersection of data and adversary tradecraft. In this role, you’ll use your practitioner experience to uncover attacker behaviors, test them in realistic environments, and turn those insights into detection content that directly improves customer outcomes. You’ll explore and exploit a variety of security technologies, with an emphasis on cloud and AI environments, to build, validate, and tune detections that reflect the latest attack techniques. In addition to applying existing research, you’ll have opportunities to conduct original investigations, from malware analysis to infrastructure tracking and honeypot monitoring, designed to uncover novel insights that shape future detection strategies. Who You Are You’re a seasoned security professional who’s evolved from responding to incidents to preventing them. You have a deep curiosity for how attackers operate and a passion for translating that insight into practical detections that measurably improve defenses. You thrive in a hands‑on environment: experimenting in the lab, analyzing data, and validating results. Collaboration and sharing come naturally to you: working with peers across Threat Labs and product teams, you enjoy turning research into real detections and community knowledge that protect customers everywhere. Your Impact Conduct and lead both applied and original threat research , transforming intelligence, telemetry, and investigation into actionable detection logic for the Sumo Logic SIEM. Collaborate closely within Threat Labs to design, build, and refine detection content and validation pipelines that ra