Senior Security Researcher - NDR/IPS/IDS

0 - 5 years

6 - 10 Lacs

Posted:3 days ago| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description

Some of your day-to-day responsibilities will be:
  • Developing and maintaining high quality custom detection rules
  • (Suricata/Snort/IDS/IPS).
  • Research and develop expertise for various threat surfaces and telemetry
  • available for them
  • Conducting code reviews and providing constructive feedback to ensure code
  • quality and maintainability.
  • Debugging and fixing issues in existing detection/signature codebases.
  • Participate in the full software development life cycle, building well-
  • designed, testable, efficient, secure code.
  • Work with team members to develop novel detections and continuously tune
  • existing ones
  • Understand the product and how Security Services delivers the service.
  • Propose coverage and efficacy improvements to the detection surface
  • Build well-designed, testable, efficient, durable detections
  • Build runbooks, reports and supporting material for detection surface
  • Document research findings and knowledge share with team and other
  • departments
  • Troubleshoot, educate, and share information with non-technical people
  • Continuously learning and adopting best practices for code quality, software development methodologies, and programming principles to enhance coding skills and stay updated with industry advancements.
  • We value a culture of sharing, so every team has the opportunity to share their work with the entire department during our monthly R&D Demos. Once a year we hold a department-wide Hackathon, teaming up across all R&D teams over four days to collaborate and build cool ideas outside the normal project scope.
  • While innovation is the focus, some of these ideas do make it into our products.
About You
6 or more years of detection authoring experience with a focus on the following key
areas:
  • NDR/IPS/IDS detections/signatures
  • Development of anomaly and behavioural based detections
  • Tuning and optimization of detections
  • Expertise on the inner workings of networking, protocols(TCP/IP, DNS,
  • HTTP), protocol analysers, Suricata/snort rules, and other network-related
  • threat management domain topics, e.g. LDAP, NTLM, etc
  • Proven ability and experience to research and develop security detections
  • related to network threat vectors
  • Experience using MITRE ATT&CK, PCAP analysis, and threat intelligence
  • feeds.
  • Experience with 3rd-party firewalls, IDS/IPS and network edge devices, their capabilities and configuration is a bonus, but minimally understanding their use and vulnerabilities.
  • We use and train a variety of technologies in MDR.
  • You should have a strong understanding of networking, protocols, and cybersecurity.
  • As a detection developer you bring a strong knowledge base that you use to help the team solve complex technical and security problems.
Helpful to have experience in the following areas:
  • SIEM detections
  • EDR detections/signatures
  • Sigma and Yara rules
  • Cloud security detections
  • Experience in at least two of the following Development Languages & Methodologies:
  • Python, Go, Java, or C/C++
  • Test Driven Development
  • Full understanding and use of DevOps methods/tooling
  • Full understanding/application of secure development practices
  • Cloud Development: AWS, Azure, and GCP using Kubernetes/Containers,
  • IaaS, and key PaaS services
  • Agile (SCRUM/Kanban)
  • Experience in following security tooling is a plus:
  • NGFW (PAN, CISCO, Fortinet, etc.)
  • Open Source IPS/IDS/NSM (e.g. Bro/Zeek/Suricata)

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
Arctic Wolf Networks logo
Arctic Wolf Networks

Computer and Network Security

Eden Prairie Minnesota