You will hunt for and analyze adversary capabilities targeting ICS/OT networks.
You will develop tools and scripts for capability analysis and inform detection strategies.
Your work directly enhances Dragos' ability to defend against advanced threats.
Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The company is a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust.
Monitor the threat landscape and deliver actionable intelligence through Flash Reports.
Administer the Threat Intelligence Platform and automate intelligence collection with Python.
Support incident response and collaborate on Purple Team exercises to improve defenses.
GitLab provides an intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity and improve security. With over 50 million users and more than 50% of the Fortune 100 as customers, GitLab fosters a high-performance culture driven by values and continuous knowledge exchange.
Build and maintain SIEM for log collection and detection rules across corporate and production environments.
Design and deploy canary tokens and early warning mechanisms to detect threats before they reach critical assets.
Investigate security incidents end-to-end, including malware analysis, exfiltration assessment, and timeline reconstruction.
Quora operates two platforms: a global knowledge sharing platform with over 300M monthly unique visitors, and Poe, a platform for chatting and building with AI language models. The company is privately held, remote-first, and fosters a culture of transparency, collaboration, and experimentation.
Check Point protects over 100,000 organizations worldwide from increasingly sophisticated cyber and AI-driven threats, securing their AI transformation. We are recognized by TIME, Newsweek, and Forbes for excellence and workplace culture, with smart, curious people who take ownership and solve complex problems.
Analyze and respond to advanced threats ranging from commodity phishing to zero-day exploits.
Monitor and triage alerts from network security monitoring, EDR platforms, and other log sources.
Create detailed incident reports and collaborate with threat intelligence and incident response teams.
Volexity is a cybersecurity company specializing in threat intelligence and incident response. They have a growing, industry-leading security operations team and value diversity and equal opportunity.
Monitoring customer environments on the ERM intelligence platform and producing actionable intelligence alerts and reports.
Investigating urgent issues affecting customers, such as cyber attacks and incidents, including threat actors, attack tools, and techniques.
Resolving Tier 1 technical issues customers may experience on the ERM intelligence platform.
Cyberint is a cybersecurity company that provides external risk management solutions to reduce external cyber threats. The company culture emphasizes teamwork and continuous learning.
Manage and optimize SIEM use cases to enhance threat detection and incident response.
Analyze security events and lead threat hunting activities to identify emerging risks.
Investigate incidents and produce technical documentation for corrective actions.
Inetum is a European leader in digital services, helping businesses and public sector entities achieve digital transformation. With 28,000 consultants and specialists across 19 countries, the company generated €2.5 billion in sales in 2023 and fosters a collaborative and innovative culture.
Investigate and analyze security alerts and incidents across endpoint, network, cloud, and identity environments.
Conduct proactive threat hunting, malware analysis, and deobfuscation of suspicious scripts.
Collaborate with senior analysts, document findings, and provide remediation recommendations.
The company operates a global Managed Detection and Response environment, protecting organizations from cyber threats. It has a remote-first culture with a collaborative team and opportunities for professional growth.
Lead cross-functional efforts to re-architect or modernize core data systems.
Create sustainable data contracts that address data governance requirements.
Enable scalable, secure, and reliable data pipelines supporting both cloud and on-prem environments.
Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The company is remote-first with a mission-driven team across North America, Europe, the Middle East, and APAC, built on authenticity, transparency, and trust.
Monitor, investigate, and respond to security detections across the SIEM, driving alerts to resolution.
Develop, tune, and maintain SIEM use cases and correlation rules to improve detection coverage.
Build and deliver operational reports and dashboards from available SIEM log source data.
Authentic8 provides Silo, a cloud-native platform that enables digital analysts to conduct secure, anonymous investigations across the globe. They serve over 750 of the world's most sophisticated organizations, from government agencies to commercial entities, with a culture of integrity, collaboration, and transparency.
Own and lead building out the Insider Trust Team’s infrastructure to engineer and automate end-to-end detection and investigation workflows.
Develop, measure, and tune detection rules in Sigma to ensure effective and sustainable operations.
Drive projects with a focus on Insider Risks, ranging from access abuse and intellectual property theft, to novel risks emerging within the blockchain/Web3 space.
We are the team behind Chainlink, the industry-standard oracle platform bringing capital markets onchain and powering the majority of DeFi. We have enabled tens of trillions in transaction value and secure the vast majority of DeFi, with a culture of security and innovation.
Investigate security alerts using tools such as CrowdStrike Falcon Suite and Microsoft Sentinel to determine scope and impact.
Support incident response activities, including containment, remediation, and post-incident documentation.
Collaborate with cross-functional teams to improve detection quality, workflows, and response readiness.
Commvault is the gold standard in cyber resilience, empowering customers to uncover, take action, and rapidly recover from cyberattacks. For over 25 years, more than 100,000 organizations and a vast partner ecosystem have relied on Commvault to reduce risks and improve governance.
Lead deep-dive analysis of ICS-related malware and firmware, developing novel detection methods and Yara signatures.
Write persuasive customer-facing technical reports that translate complex malware findings into clear operational impact.
Collaborate across teams with hunters, intelligence analysts, and detection engineers to drive malware-related threat research.
Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. They have a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust.
Identify novel vulnerabilities in industrial products and control systems through strategic acquisition and rigorous analysis.
Develop detection signatures (Suricata, YARA, internal analytics) and partner with product engineering to close gaps in the Dragos Platform's vulnerability detection.
Serve as a trusted internal resource to threat intelligence and incident response teams, assessing in-the-wild exploits and integrating findings into broader threat intelligence.
Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure. The company is a remote-first, mission-driven team across North America, Europe, the Middle East, and APAC, built on authenticity, transparency, and trust.
Monitor and triage security alerts from SIEM, EDR, and other sources to identify threats.
Perform initial investigations to validate alerts, assess severity, and determine root cause.
Document findings and communicate with clients and internal teams for effective incident response.
Netrix Global provides holistic IT solutions to help businesses run and scale securely. The company is a top system integrator ranked in the CRN VAR500, with a culture focused on ownership, collaboration, and respect.
Identify, assess, and mitigate emerging threats through intelligence analysis and open-source methodologies.
Manage intelligence platform vendors and develop social media, deep web, and dark web monitoring strategies.
Conduct due diligence, threat assessments, and investigations to support security and business decisions.
We are a global technology and entertainment company safeguarding clients, content, and intellectual property. We operate as a full-time remote team offering a comprehensive benefits package.
Own, administer, and optimize SIEM and EDR platforms, including detection content and automation workflows.
Design SOAR playbooks and integrations across security tools to streamline triage, enrichment, and containment.
Investigate security events, conduct threat hunts, and support incident response alongside CSIRT Analysts.
Vultr provides high-performance cloud infrastructure for enterprises and AI innovators worldwide, with 33 global data centers. As the world's largest privately-held cloud infrastructure company, Vultr has grown significantly and values inclusion, offering comprehensive benefits and professional development.
Conduct deep technical research into malware, firmware, and adversary tools targeting industrial environments.
Develop YARA signatures and detection strategies to protect critical infrastructure.
Collaborate with analysts and engineers to transform research into actionable defenses.
The company defends critical infrastructure from advanced cyber threats. It operates with a remote-first, mission-driven culture focused on innovation and transparency.
Lead detection engineering innovation by reimagining how unlimited AI capacity transforms SOC workflows.
Partner with engineering teams to encode expert detection knowledge into product, designing scoring rubrics for AI-generated content.
Stay current on emerging threats and conduct original research to develop novel AI-assisted detection approaches.
Dropzone's mission is to scale cybersecurity beyond human limits by augmenting security engineers with AI specialists. We are an award-winning, venture-backed company disrupting the $200B+ cybersecurity market with a team experienced in cybersecurity, AI/ML, and SaaS.
Deploy and support Scout products in real customer environments, building and improving deployment automations.
Prototype integrations with customer systems and turn repeatable issues into actionable product requirements.
Communicate clearly with technical and non-technical customers while researching cybersecurity trends.
Volexity is a cybersecurity company that builds products used in real-world security environments, including incident response and threat intelligence. The company values diversity and is an equal opportunity employer, hiring based on qualifications and merit.