Were looking for a Cloud Security Researcher to drive runtime threat research for our Cloud Detection and Response (CDR) capabilities – understanding how attackers behave inside live cloud workloads and turning that into detections that protect our customers. As a senior member of the team, youll also mentor our junior researcher.
On a typical day youll:
Research attacker tradecraft against live cloud workloads – compute, containers, Kubernetes, serverless – covering execution, privilege escalation, persistence, lateral movement, and evasion
Analyze telemetry from AWS CloudTrail, GCP Audit Logs, Azure Activity Logs, and runtime/sensor data to investigate threats and translate findings into detection logic
Partner with sensor and detection engineers on feasibility, coverage, and signal quality
Run threat simulations and attack emulation to validate coverage and surface gaps
Track emerging threats and CVEs across AWS, Azure, and GCP, feeding them into detection priorities
Produce externally publishable research – blog posts, whitepapers, threat reports – and represent us at conferences and webinars
Mentor our junior researcher in detection engineering, runtime analysis, and research rigor.
On a typical day youll:
Research attacker tradecraft against live cloud workloads – compute, containers, Kubernetes, serverless – covering execution, privilege escalation, persistence, lateral movement, and evasion
Analyze telemetry from AWS CloudTrail, GCP Audit Logs, Azure Activity Logs, and runtime/sensor data to investigate threats and translate findings into detection logic
Partner with sensor and detection engineers on feasibility, coverage, and signal quality
Run threat simulations and attack emulation to validate coverage and surface gaps
Track emerging threats and CVEs across AWS, Azure, and GCP, feeding them into detection priorities
Produce externally publishable research – blog posts, whitepapers, threat reports – and represent us at conferences and webinars
Mentor our junior researcher in detection engineering, runtime analysis, and research rigor.
Requirements:
About you:
4+ years in security research, threat research, or detection engineering, ideally in cloud/cloud-native environments
Strong Linux and cloud infrastructure foundation, with an attacker-oriented mindset
Deep familiarity with attacker TTPs (MITRE ATT&CK for Cloud/Containers)
Hands-on experience turning runtime, host, and network security events into detections
Proficiency in Python (Go a plus)
Track record of, or clear appetite for, mentoring
Strong written and spoken English, with the ability to explain complex topics clearly
Nice to have:
eBPF/runtime sensor experience, Linux kernel internals
Kubernetes/container, API, or application security background
Offensive security, red teaming, or vulnerability research experience
Large-scale telemetry analysis (SQL/Elastic)
AI/ML-assisted security research experience
Conference speaking, published research, CVEs, or open-source contributions.
About you:
4+ years in security research, threat research, or detection engineering, ideally in cloud/cloud-native environments
Strong Linux and cloud infrastructure foundation, with an attacker-oriented mindset
Deep familiarity with attacker TTPs (MITRE ATT&CK for Cloud/Containers)
Hands-on experience turning runtime, host, and network security events into detections
Proficiency in Python (Go a plus)
Track record of, or clear appetite for, mentoring
Strong written and spoken English, with the ability to explain complex topics clearly
Nice to have:
eBPF/runtime sensor experience, Linux kernel internals
Kubernetes/container, API, or application security background
Offensive security, red teaming, or vulnerability research experience
Large-scale telemetry analysis (SQL/Elastic)
AI/ML-assisted security research experience
Conference speaking, published research, CVEs, or open-source contributions.
This position is open to all candidates.












