Sr. Security Engineer - Threat Research
Remote
ExtraHop Networks
ExtraHop provides cloud-native cybersecurity solutions to help enterprises detect and respond to advanced threats—before they compromise your business.ExtraHop is on a mission to protect and propagate trust by revealing the cybertruth: the truth about the attackers already inside an organization’s network, the truth about what they’re doing, and how to stop them at top speed. We partner with every customer, every day, to reveal it. Are you ready to join us?
We are ExtraHop. We’re on a mission to provide security teams with the intelligence they need to confront and stop advanced threats like supply chain attacks, zero day exploits, and ransomware attacks. Attackers still have the advantage. We’re taking it back with creativity, intellectual curiosity, and a sense of humor. Are you ready to help us reclaim the upper hand?
Do you like securing complex networks? Want to be a part of a collaborative team that builds solutions that protect some of the biggest networks in the world? ExtraHop is seeking a Senior Security Engineer experienced with threat detection and networking to grow our world-class Threat Research team.
We are looking for a self-starter that enjoys investigating cyber attacks and how adversaries are traversing the network for lateral movement. You must have a strong understanding of the attack lifecycle and a deep desire to stop attackers before they can do damage.
Duties & Responsibilities
- Reproduce and analyze network-based cyber attacks, including vulnerability exploitation and lateral movement.
- Communicate in writing research findings to detection engineering and collaborate in writing detectors to detect cyber attacks.
- Mentor and teach less experienced security engineers about cyber attacks, malware analysis, vulnerabilities research, or other areas of expertise.
- Work with management and other team members to improve analysis and detector development processes.
Required Skills & Experience
- Bachelor’s degree or equivalent experience in cyber security, computer science, engineering, or network forensics.
- Experience in penetration testing, red teaming, or capture the flag competitions that include hands-on execution of attacks and vulnerability exploitation.
- Experience in writing or working with signatures (Suricata or Snort) or machine learning intended to detect network-based cyber attacks.
- Strong understanding of network security and networking basics, including the OSI model and excellent working knowledge of the key protocols from Layer 2 through Layer 7, including IP, TCP, UDP, and HTTP.
- Good communication skills with the ability to clearly communicate in writing technical details about attacks.
- Strong working experience in using Wireshark, TShark or other network analysis tools.
- Strong working experience with Python or equivalent scripting languages.
Desired Skills & Experience
- 3 years of professional experience as a Threat Researcher, Penetration Tester, or Vulnerability Researcher.
- Familiarity with MITRE’s ATT&CK Framework.
- Familiarity with VM and container technologies for setting up ephemeral environments for research.
- Familiarity with Windows protocols and reconnaissance and lateral movement techniques in Windows environments.
- Knowledge of various signature frameworks, including YARA, ClamAV, JA3, and JARM.
All R&D Employees will be required to attend 2 mandatory in-person events every year of approx. 4 days duration.
$149,000- $198,000 + benefits+ options
Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or assume sponsorship of an employment Visa at this time.
#LI-CS1
#remote
ABOUT EXTRAHOP
ExtraHop is the cybersecurity partner enterprises trust to reveal the unknown and unmask the attack. We’re on a mission to protect and propagate trust by revealing the cybertruth, and we partner with every customer, every day, to uncover it. Our Reveal(x) 360 platform is the only network detection and response solution delivering the 360-degree visibility needed to see everything on the network. When organizations have full network transparency with ExtraHop, they can see more, know more, and stop more cyberattacks.
ExtraHop is recognized by leading organizations for both its innovation in the market and its commitment to building a world-class team. We’ve been recognized as a “Customer’s Choice” by Gartner Peer Insights™ Voice of the Customer, and as a Leader in the Forrester Wave®: Network Analysis and Visibility, Q2 2023. ExtraHop has won AI Breakthrough Awards four times (2018-2020, 2023) and our Channel Partner program has received a 5-star rating from CRN for our 2023 Partner Program Guide. Our flagship product, Reveal(x), has received numerous accolades, including a 2022 Edison Award for Cybersecurity. ExtraHop CEO Patrick Dennis has been featured on NYSE TV and NASDAQ to discuss how companies can monitor accidental misuse of generative AI tools.
Benefits/perks listed below may vary depending on the nature of your employment with ExtraHop and the country where you work.
- Health, dental, and vision benefits
- Honor System PTO and 9 Holidays (US only) + 3 Days of Paid Volunteer Time
- Non-Commissioned positions are eligible to participate in annual discretionary bonus plan
- FSA and Dependent Care Accounts + EAP where applicable
- Educational Reimbursement
- 401k with employer match or Pension where applicable
- Pet Insurance (US only)
- Parental Leave (US Only)
- Hybrid and Remote Work Model
*Candidates should note that the Company may modify reporting relationships, job titles and compensation, including commissions and benefits, from time to time at its sole discretion, as it deems necessary, with or without prior notice.
We are intentional about our culture, diversity, and inclusion, and we welcome everyone to come ready to participate in contributing to this truly unique environment. At ExtraHop, we believe that the best products, services, and companies are built by strong teams that include a diversity of backgrounds, perspectives, ideas, and experiences. We are committed to supporting and enabling growth and opportunity for every employee at every level. This is the foundation of our success.
We are equally committed to equal employment opportunity, and it is foundational to how we recruit and hire our talented team. Employment is determined based upon capabilities and qualifications without discrimination on the basis of race, creed, color, religion, sex, gender identification and expression, marital status, military status or status as an honorably discharge/veteran, pregnancy (including potential pregnancy, pregnancy-related conditions, and childbearing), sexual orientation, age (40 and over), national origin, ancestry, citizenship or immigration status, physical, mental, or sensory disability , HIV/AIDS or hepatitis C status, genetic information, status as an actual or perceived victim of domestic violence, sexual assault, or stalking, or any other protected class as established by law.
Our people are our most important competitive advantage, leading the charge against nation-states, cyber criminals, and insider threats.
Ready to join us? #Extrahop #Security #NDR #informationsecurity #cybersecurity #cloudsecurity #infosec #LI-Remote
Tags: C Cloud Computer Science Exploits Forensics Machine Learning Malware Network security Pentesting Python R&D Red team Scripting Snort Threat detection Threat Research Vulnerabilities Windows
Perks/benefits: 401(k) matching Career development Competitive pay Health care Insurance Parental leave Salary bonus Team events
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Senior Information Security Analyst jobs
- Open IT Security Analyst jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open Information Security Officer jobs
- Open Chief Information Security Officer jobs
- Open Security Operations Engineer jobs
- Open Ingénieur DevSecops H/F jobs
- Open Staff Security Engineer jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open Senior Security Architect jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Cybersecurity Consultant jobs
- Open Senior Security Analyst jobs
- Open o365 Security Architect jobs
- Open Principal Security Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Staff Product Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open Security Researcher jobs
- Open Product Security Engineer jobs
- Open Application security-related jobs
- Open GCP-related jobs
- Open Governance-related jobs
- Open Risk assessment-related jobs
- Open Network security-related jobs
- Open Pentesting-related jobs
- Open Analytics-related jobs
- Open ISO 27001-related jobs
- Open CISM-related jobs
- Open IAM-related jobs
- Open SaaS-related jobs
- Open Threat intelligence-related jobs
- Open Security Clearance-related jobs
- Open Malware-related jobs
- Open Vulnerability management-related jobs
- Open CISA-related jobs
- Open Java-related jobs
- Open DevOps-related jobs
- Open Kubernetes-related jobs
- Open Security assessment-related jobs
- Open DoD-related jobs
- Open Forensics-related jobs
- Open APIs-related jobs
- Open EDR-related jobs
- Open Splunk-related jobs