×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Threat Research Engineer

Job in Oregon, Dane County, Wisconsin, 53575, USA
Listing for: Sumo Logic
Full Time position
Listed on 2026-06-18
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 125000 - 150000 USD Yearly USD 125000.00 150000.00 YEAR
Job Description & How to Apply Below
Position: Staff Threat Research Engineer

Threat Labs’ mission is to keep our customers safe from cybersecurity attacks. We do this by advancing the art and science of detection: turning threat intelligence and threat research into practical, high‑quality detections that power the Sumo Logic SIEM platform and strengthen the broader security community.

About the Role

We’re looking for a staff‑level threat researcher who thrives at the intersection of data and adversary tradecraft. In this role, you’ll use your practitioner experience to uncover attacker behaviors, test them in realistic environments, and turn those insights into detection content that directly improves customer outcomes. You’ll explore and exploit a variety of security technologies, with an emphasis on cloud and AI environments, to build, validate, and tune detections that reflect the latest attack techniques.

In addition to applying existing research, you’ll have opportunities to conduct original investigations, from malware analysis to infrastructure tracking and honeypot monitoring, designed to uncover novel insights that shape future detection strategies.

Who You Are

You’re a seasoned security professional who’s evolved from responding to incidents to preventing them. You have a deep curiosity for how attackers operate and a passion for translating that insight into practical detections that measurably improve defenses. You thrive in a hands‑on environment: experimenting in the lab, analyzing data, and validating results. Collaboration and sharing come naturally to you: working with peers across Threat Labs and product teams, you enjoy turning research into real detections and community knowledge that protect customers everywhere.

Your

Impact
  • Conduct and lead both applied and original threat research
    , transforming intelligence, telemetry, and investigation into actionable detection logic for the Sumo Logic SIEM.
  • Collaborate closely within Threat Labs to design, build, and refine detection content and validation pipelines that raise the bar for product and customer detection quality.
  • Drive innovation in detection methodologies
    , including research activities such as malware analysis, infrastructure tracking, or honeypot operations, to discover new attacker behaviors.
  • Publish and share findings — from detection logic to behavioral analysis and practical hunting guidance — that help customers maximize SIEM outcomes.
  • Contribute to Threat Labs’ long‑term vision of a research‑driven, continuously evolving detection ecosystem built on practitioner insight and technical depth.
Responsibilities
  • Research, develop, and test threat detection logic in a lab environment, validating against real‑world attacker behaviors and ensuring technical alignment with Sumo Logic SIEM capabilities.
  • Conduct original threat research, such as analyzing malware, tracking infrastructure, or experimenting with honeypots, and translate findings into detection opportunities.
  • Investigate industry and adversary trends to identify emerging detection opportunities.
  • Collaborate with product management and fellow Threat Labs engineers to scope and prioritize detection campaigns.
  • Maintain and expand Threat Labs’ research lab infrastructure.
  • Provide practitioner feedback to engineering and product management to inform feature design and roadmap decisions.
  • Contribute to the security community through blogs, conference talks, open source projects, and public research contributions.
Requirements
  • 12+ years of cybersecurity experience that includes a mix of senior/principal SOC analyst, threat hunter, or purple team practitioner.
  • Demonstrated ability to progress threat research into actionable detections and incident response outcomes.
  • Experience conducting original or self‑directed threat research that resulted in novel findings — for example, malware or infrastructure analysis, honeypot operations, or similar investigative work leading to actionable insights.
  • Broad knowledge of multiple technology stacks and a strong curiosity to learn new platforms.
  • Deep experience with multiple major public clouds (AWS, Azure, or GCP), and familiarity with analyzing cloud‑native logs and telemetry.
  • Understanding of emerging attack techniques…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary