Threat Research Analyst
Tech Stack / Keywords
Firma i stanowisko
Are you passionate about cybersecurity research and uncovering sophisticated attack patterns? We are looking for a Threat Research Analyst to join a remote team working on advanced application protection solutions for a global Customer in the cybersecurity domain.
In this role, you will investigate suspicious activity, analyze attack vectors, and help improve detection and blocking mechanisms for modern web applications. You will work with monitoring systems, behavioral analytics, and threat intelligence data to proactively identify emerging threats and strengthen platform security.
Sigma Software offers the opportunity to work on impactful security products, collaborate with experienced professionals, and grow your expertise in modern cybersecurity technologies while working remotely within European time zones.
CUSTOMER Our Customer is a global cybersecurity company delivering comprehensive security solutions for businesses, organizations, and digital ecosystems. Operating across multiple industries, the company focuses on preventing cyber threats, identifying vulnerabilities, and protecting web applications from sophisticated automated attacks.
PROJECT The project is focused on building a security platform that safeguards applications from automated attacks and malicious traffic. The Threat Research team investigates emerging attack techniques, analyzes suspicious behavioral patterns, and develops detection and blocking mechanisms to improve overall protection capabilities.
As part of the team, you will work with logs, dashboards, threat intelligence data, and monitoring systems to uncover new attack vectors and enhance application security in real-world environments.
Wymagania
- At least 3 years of commercial experience in cybersecurity, threat research, or related areas
- Hands-on experience in cybersecurity, threat detection, security research, threat hunting, anti-bot solutions, fraud and abuse detection, application security, or a closely related security domain
- Strong understanding of attacker tactics, techniques, and behaviors, including evasion methods
- Experience investigating suspicious or malicious activities with solid understanding of detection, alerting, and blocking
- Strong understanding of web technologies and architecture, including client-server architecture, HTTP/HTTPS protocols, REST APIs, request/response lifecycle, headers, cookies, sessions, and authentication mechanisms
- Understanding of browser technologies and investigation experience: DOM structure and manipulation, browser events, XHR, Fetch requests, WebSockets, browser APIs, and security policies
- Ability to read and analyze JavaScript code to identify application behavior and suspicious logic; deep development expertise not required
- Working knowledge of HTML and CSS to investigate web application behavior
- Strong practical experience with SQL for data analysis and investigations with large datasets
- Hands-on experience using Kibana for log analysis, monitoring, and investigations
- Solid understanding of networking fundamentals: TCP/IP, DNS, VPN technologies, proxies, basic network troubleshooting
- Ability to independently investigate complex technical issues and correlate data to build attack scenarios
- Experience using AI-powered tools and chatbots for research and investigation including writing effective prompts
- Upper-Intermediate (B2) or higher level of English
Nice to have:
- Understanding of Elasticsearch and its ecosystem
- Python scripting and automation skills
- Experience developing or investigating crawlers, scrapers, or browser automation tools
- Experience with deobfuscation or reverse engineering techniques
- Experience investigating bot traffic, automated attacks, scraping activity, credential stuffing, account takeover, abuse, or fraud
- Experience with monitoring and observability platforms such as Datadog, Imply, Splunk, Microsoft Sentinel, OpenSearch, or similar tools
Obowiązki
- Monitor existing threats and investigate suspicious activities using logs, dashboards, and detection systems
- Analyze attack patterns and build detailed threat scenarios based on collected data
- Research and respond to reported threats, Customer escalations, and security incidents
- Improve detection and blocking mechanisms for automated attacks and malicious behaviors
- Analyze intelligence from competitors, public sources, and industry trends to identify emerging threats
- Work with monitoring and analytics tools such as Kibana and Elasticsearch
- Collaborate with engineering and security teams to improve product protection capabilities
- Document findings, attack methodologies, and investigation results
Sigma Software
65 aktywnych ofert