Security Developer - Detection

Bengaluru, India

Arctic Wolf

Arctic Wolf delivers dynamic, 24x7 AI-driven cybersecurity protection tailored to the needs of your organization. Ready to boost your cyber resilience?

View all jobs at Arctic Wolf

Apply now Apply later

At Arctic Wolf, we're redefining the cybersecurity landscape. With our employee Pack members, spread out globally, committed to setting new industry standards. Our accomplishments speak for themselves, from our recognition in the Forbes Cloud 100, CNBC Disruptor 50, Fortune Future 50, and Fortune Cyber 60 to winning the 2024 CRN Products of the Year award. We’re proud to be named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services and earning a Customers' Choice distinction from Gartner Peer Insights. Our Aurora Platform also received CRN’s Products of the Year award in the inaugural Security Operations Platform category. Join a company that’s not only leading, but also shaping, the future of security operations. 

Our mission is simple: End Cyber Risk. We’re looking for a Senior Developer - Managed Risk Platform to be part of making this happen.

About the Role

We’re looking for a Detection Developer for IDR team to be part of making this happen.

A Security Developer has a clear history of successful contribution to professional detection development projects. They are driven, curious, and results oriented. They are able to manage competing priorities as they relate to improving our existing codebase of detections and constantly challenge the status quo. With additional experience and exposure to advanced detection development patterns and projects, they are capable of becoming a Senior Security Developer within 2 years.

Basic Qualifications

  • 2 or more years of professional experience as a Detection Developer
  • Experience consists of projects contributing in either Python or YAML (or any custom language)
  • OS Specific Telemetry (Windows Security/Sysmon logs, Linux, Mac)
  • Windows PowerShell Monitoring
  • Cloud logs, email, Oauth, Identity related attack analysis
  • SIEM Detections
  • EDR detections/signatures
  • Threat landscape awareness
  • Development of anomaly and behavioural based detections
  • Tuning and optimization of detections for all the above
  • Pen test and other attack tool awareness and analysis is definite plus
  • Professional certifications in Security and/or Cloud are desired (i.e. CISSP, GNFA, GCFA, GCFE, GREM).

More About the role

You’ll be working as a detection developer on our Integration, Detection and Response Team, responsible for ensuring quality and scale of our detection base and presenting actionable detections to our Security Services teams and customers.

Some of your day-to-day responsibilities will be:

· Developing and maintaining Python and YAML-based detections, software, and systems.

· Research and develop expertise for various threat surfaces and telemetry available for them

· Propose coverage and efficacy improvements to the detection surface

· Work with team members to develop novel detections and continuously tune existing ones

· Build runbooks, reports and supporting material for detection surfaces

· Write and test clean, efficient, and reusable code in Python/YAML

· Conducting code reviews and providing constructive feedback to ensure code quality and maintainability.

· Debugging and fixing issues in existing Python codebases.

· Participate in the full software development life cycle, building well-designed, testable, efficient, secure code.

· Understand the product and how Security Services delivers the service.

· Develop professional expertise, apply company policies and procedures to resolve a variety of issues.

· Continuously learning and adopting best practices for code quality, software development methodologies, and programming principles to enhance coding skills and stay updated with industry advancements.

We value a culture of sharing, so every team has the opportunity to share their work with the entire department during our monthly R&D Demos. Once a year we hold a department-wide Hackathon, teaming up across all R&D teams over four days to collaborate and build cool ideas outside the normal project scope. While innovation is the focus, some of these ideas do make it into our products.

About you

You’re a talented detection developer who is passionate about securing our customers and cares deeply about ending cyber risk. You enjoy learning about various attack methods and tools. You are constantly adapting to emerging technologies, trends, and best practices. You will build productive internal/external working relationships to resolve mutual problems by collaborating on procedures or transactions, with a focus on providing standard professional advice and creating initial reports/analyses for review by experienced team professionals.

Here are some of the core technologies we use and teach across our detections teams:

· Python

· Sigma

· Wazuh

· Kibana

· Git

You are not required to be an expert in any of these, but you should be excited by the opportunity to learn new things and comfortable with coming up to speed quickly. Any experience with detection development for EPP/EDR and/or pen test is relevant and transferrable.

We value a culture of sharing, so every team has the opportunity to share their work with the entire department during our monthly R&D Demos. Once a year we hold a department-wide Hackathon, teaming up across all R&D teams over four days to collaborate and build cool ideas outside the normal project scope. While innovation is the focus, some of these ideas do make it into our products.

Why Arctic Wolf?

At Arctic Wolf, we foster a collaborative and inclusive work environment that thrives on diversity of thought, background, and culture. This is reflected in our multiple awards, including Top Workplace USA (2021-2024), Best Places to Work – USA (2021-2024), Great Place to Work – Canada (2021-2024), Great Place to Work – UK (2024), and Kununu Top Company – Germany (2024). Our commitment to bold growth and shaping the future of security operations is matched by our dedication to customer satisfaction, with over 7,000 customers worldwide and more than 2,000 channel partners globally. As we continue to expand globally and enhance our technology, Arctic Wolf remains the most trusted name in the industry. 

 

Our Values  

Arctic Wolf recognizes that success comes from delighting our customers, so we work together to ensure that happens every day. We believe in diversity and inclusion, and truly value the unique qualities and unique perspectives all employees bring to the organization. And we appreciate that—by protecting people’s and organizations’ sensitive data and seeking to end cyber risk— we get to work in an industry that is fundamental to the greater good. We celebrate unique perspectives by creating a platform for all voices to be heard through our Pack Unity program. We encourage all employees to join or create a new alliance. See more about our Pack Unity here.   We also believe and practice corporate responsibility, and have recently joined the Pledge 1% Movement, ensuring that we continue to give back to our community. We know that through our mission to End Cyber Risk we will continue to engage and give back to our communities.  

All wolves receive compelling compensation and benefits packages, including:  

·       Equity for all employees 

·       Flexible annual leave, paid holidays and volunteer days 

·       Training and career development programs 

·       Comprehensive private benefits plan including medical insurance for you and your family, life insurance (3x compensation), and personal accident insurance. 

·       Fertility support and paid parental leave 

 

Arctic Wolf is an Equal Opportunity Employer and considers applicants for employment without regard to race, colour, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, provincial, or local law. Arctic Wolf is committed to fostering a welcoming, accessible, respectful, and inclusive environment ensuring equal access and participation for people with disabilities. As such, we strive to make our entire employee experience as accessible as possible and provide accommodations as required for candidates and employees with disabilities and/or other specific needs where possible. Please let us know if you require any accommodations by emailing recruiting@arcticwolf.com.  

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  2  0  0

Tags: CISSP Cloud DART EDR GCFA GCFE GNFA GREM Linux Monitoring PowerShell Python R&D SDLC SIEM Windows

Perks/benefits: Career development Equity / stock options Fertility benefits Flex hours Health care Insurance Medical leave Parental leave

Region: Asia/Pacific
Country: India

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.