A
Security Research Engineer
Artemis
Contract type
Ongoing
Work mode
100% remote
Experience
Senior · 7+ years
Job description
Key details
- Develop AI-powered detection tooling and build automation that leverages AI to accelerate detection creation, tuning, and validation at scale
- Conduct security research by analyzing cloud, identity, and SaaS data sources (AWS CloudTrail, Okta, Entra ID, and more) to extract security value and identify detection opportunities
- Perform authorized attack simulations to validate detection coverage and identify gaps in defenses
- Proactively hunt for threats across customer environments using the platform and tooling
- Investigate potential cases by analyzing security incidents to demonstrate product value, refine detection logic, and deliver actionable findings
- Engage with customers on calls to present analysis results, walk through findings, and gather feedback that shapes the product
- Tune customer detections to reduce false positives and improve detection accuracy based on real-world data and customer context
- Build investigation automation by creating AI-powered tools that scale investigation and threat hunting workflows across the platform
- Company mission
- Help empower cybersecurity teams around the world to keep people safe from the most advanced cyber threats
Primary stack
Core technologies
AWSAzureGoogle Cloud Platform (GCP)
Benefits
- Make a real world impact by helping empower cybersecurity teams around the world to keep people safe from the most advanced cyber threats
- Be challenged to be better than ever before, with a team of some of the smartest and most driven people in the world
- Push the boundaries of technology by working with and building the most advanced AI capabilities in cybersecurity, including cutting-edge analytics and agentic platforms
- Innovative culture that obsesses about customers, moves fast with high quality, and values open communication, mentorship and learning
- Autonomy to drive projects and support to grow
Requirements & details
- 7+ years of hands-on cybersecurity experience
- Hands-on experience in incident response including cloud environments (AWS, Azure, GCP) and identity providers (Okta, Entra ID)
- Strong knowledge of threat actor tactics, techniques, & procedures and demonstrated understanding uncovering threat actor activity in various environments
- Strong experience with log-based analysis and demonstrated ability to identify malicious activity across a variety of log sources
- Ability to translate security research into actionable detections or threat hunt investigations
- Strong communication skills—comfortable explaining technical findings to engineers and customers
- Experience with detection engineering at scale
- Bonus: Background working in a SOC environment or Managed Detection and Response
- Bonus: Familiarity with a wide range of security tools (SIEM, EDR, SOAR)
- Bonus: Customer-facing technical experience
- Bonus: Experience with AI tools and models
- AWS, Azure, GCP, Okta, Entra ID, SIEM, EDR, SOAR, AI tools and models
- AWS
- Azure
- Google Cloud Platform (GCP)
