Senior Developer - Managed Detection & Response

Kitchener-Waterloo, Ontario, Canada or Toronto, Ontario, Canada or Remote

Applications have closed

Arctic Wolf Networks

Arctic Wolf delivers dynamic 24x7 cybersecurity protection tailored to the specific needs of your organization. Ready to boost your security posture?

View company page

Ready to make an impact? Arctic Wolf is looking for a talented Senior Developer - Managed Detection & Response to join our pack.

Arctic Wolf, the leader in security operations, is a fast-growing company in an exciting and fast-growing industry—Cybersecurity. How fast are we growing? Well, Arctic Wolf ranks #25 on the Deloitte Fast Technology 500 for North America in 2019!  We have doubled headcount, customers, and revenue for five years running. 

We are also cultivating a collaborative and productive work environment that welcomes a diversity of backgrounds and ideas to make our teams even stronger. In fact, we are considered among the 2020 Best Places to Work by bizjournals.com.  

At Arctic Wolf, we believe in corporate responsibility. Our offices across North America participate in volunteer programs throughout their communities, and we earned distinction from TravelWise for our efforts in promoting sustainable transportation. 

About the Role

A Managed Detection & Response (MDR) Senior Developer - Security is both a cybersecurity expert and an experienced detections developer for endpoint, network or cloud. They research and curate alerts and reports for their surface area. They look at new and emerging threats to identify the investments we should be making to improve our threat detection capabilities. Their overarching goal is to help us make security better for our clients every day. This role works with team members, Product Management, Security Services and various other specialists to continuously improve the coverage and efficacy of our MDR solution.

Responsibilities Include:

  • Research and develop expertise in the various threat surfaces and telemetry available for them

  • Propose coverage and efficacy improvements to the detection surface

  • Work with team members to develop novel detections and continuously tune existing ones

  • Participate in the full software development life cycle

  • Build well-designed, testable, efficient and secure code

  • Build runbooks, reports and supporting material for detection surface

  • Document research findings and knowledge share with team and other departments

We value a culture of sharing, so every team has the opportunity to share their work with the entire department during our monthly R&D Demos. Once a year we hold a department-wide Hackathon, teaming up across all R&D teams over four days to collaborate and build cool ideas outside the normal project scope. While innovation is the focus, some of these ideas do make it into our products.

About You

We use and train a variety of technologies in MDR. Candidates who are interested in security detections/protections and have experience with the technologies below or similar are encouraged to apply for this position. Understanding the basic workings of a security operation center is preferred.

Advanced experience in the development of security products/systems with a focus on 2 or more of the following key areas:

  • SIEM detections

  • NDR/IPS/IDS detections/signatures

  • EDR detections/signatures

  • Sigma and Yara rules

  • Cloud security detections

  • Development of anomaly and behavioural based detections

  • Tuning and optimization of detections for all the above

Advanced experience with the at least two of the following Development Languages & Methodologies:

  • Python, Go, Java, and C/C++

  • Test Driven Development

  • Full understanding and use of DevOps methods/tooling

  • Full understanding/application of secure development practices

  • Cloud Development: AWS, Azure, and GCP using Kubernetes/Containers, IaaS, and key PaaS services

  • Agile (SCRUM/Kanban)

Advanced experience with the following security tooling:

  • NGFW (PAN, CISCO, Fortinet, etc.)

  • Open Source IPS/IDS/NSM (e.g. Bro/Zeek/Suricata)

  • SIEMs and Security Analytics platforms (e.g. Elastic, Open Source Big Data Stacks, Splunk, etc.)

In addition, you may have demonstrated leadership experience from previous projects, regardless of title held. Even if you haven’t worked with all of our specific technologies, you bring a diverse knowledge base that you use to help the team solve complex technical problems. You have comprehensive knowledge of software development practices and the cybersecurity threat landscape.

Interview Process

The interview process is approximately as follows:

  • Phone pre-screening: A recruiter contacts you to briefly discuss your work history and provide an overview of Arctic Wolf. Approximately 30 minutes.

  • Technical assessment: A recruiter sends you a link to a straightforward technical assessment that is relevant to the role you are applying for. Approximately 1 hour.

  • Face-to-face interviews: Several team members conduct two interviews to learn more about you and provide more information about your potential role and team. Be prepared to collaborate on a technical problem and talk more about past projects and your career goals. Approximately 1 hour per interview.

Security Requirements:

  • Conducts duties and responsibilities in accordance with AWN’s Information Security policies, standards, processes and controls to protect the confidentiality, integrity and availability of AWN business information.
  • Background checks are required for this position

Working at Arctic Wolf: 

Arctic Wolf recognizes that success comes from delighting our customers, so we work together to ensure that happens every day. We believe in diversity and inclusion, and truly value the unique qualities all employees bring to the organization. And we appreciate that—by protecting people’s and organizations’ sensitive data and aiming to end cyber risk— we get to work in an industry that is fundamental to the greater good.

All wolves receive compelling compensation and benefits packages, including:

  • Equity for all employees
  • Paid parental leave
  • Training and career development programs

If you're excited about this role, but do not meet all of the qualifications listed above, we encourage you to apply anyway. We review all applications and still may consider you the right person for the role or have another open position where you’re the perfect fit.

Arctic Wolf is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetics, or any other basis forbidden under federal, provincial, or local law.

Arctic Wolf is committed to fostering a welcoming, accessible, respectful, and inclusive environment that ensures equal access and participation for people with disabilities. Please let us know if you require any accommodations by emailing recruiting@arcticwolf.com.

Tags: Agile Analytics AWS Azure Big Data C C++ Cloud DevOps EDR GCP IaaS IDS IPS Java Kanban Kubernetes NGFW NSM Open Source PaaS Python R&D Scrum SIEM Splunk Threat detection

Perks/benefits: Career development Equity Parental leave

Regions: Remote/Anywhere North America
Country: Canada
Job stats:  2  0  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.