Senior Threat Researcher (Integrations Team)
arcticwolf · Bengaluru, IND · India · On-site
Posted Sep 29, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
At Arctic Wolf , you will not just watch the cybersecurity industry evolve – you will help lead the change. Our global team is made up of people who thrive on solving complex problems, moving quickly, and building technology that protects organizations around the world. We are proud to be recognized by Forbes, CNBC, Fortune, CRN, Gartner Peer Insights, and International Data Corporation MarketScape. What matters most is the work behind these recognitions: delivering real outcomes for customers through award-winning innovation such as our Aurora Platform.
If you are looking for meaningful work, smart teammates, and the opportunity to make a real impact in a high-growth company that is redefining security operations, Arctic Wolf is the right place for you.
Our mission is simple: End Cyber Risk.
We are looking for a Senior Threat Researcher -Cloud & Endpoint Detection to join our Integrations Team and help achieve this mission.
We are responsible for developing high-fidelity threat detections and analytics using telemetry collected from third-party security, identity, cloud, email, and endpoint integrations.
This role sits at the intersection of security research, detection engineering, and integrations. The primary responsibility is to analyse data ingested from integrated security providers and transform that telemetry into actionable detection rules, correlation logic, and attack coverage. Initially, the role will focus heavily on detections powered by data from third-party integrations, with opportunities to expand coverage across cloud, identity, endpoint, and SaaS ecosystems as new integrations are onboarded.
The ideal candidate has a strong understanding of attacker behaviour, security telemetry, and detection engineering, with the ability to quickly learn new vendor schemas, APIs, and event models to identify meaningful detection opportunities.
IN THIS ROLE, YOU WILL:
Third-Party Integration Detection Development
Serve as the detection subject matter expert within the Integrations Team.
Develop detections, correlation rules, and analytics based on telemetry ingested from third-party integrations.
Analyse vendor APIs, audit logs, alerts, and event schemas to identify security detection opportunities.
Design detection coverage that leverages data from integrated security products, cloud providers, identity platforms, email security solutions, and endpoint security tools.
Partner closely with integration engineers to understand newly onboarded data sources and maximize security value from collected telemetry.
Detection Research
Research emerging threats, attack techniques, and adversary tactics.
Identify opportunities to detect malicious activity using third-party security and SaaS telemetry.
Map detections to the MITRE ATT&CK framework and maintain alignment with evolving threat landscapes.
Continuously improve existing detections by reducing false positives and increasing attack coverage.
Security Domain Coverage
Devel…