Threat Research Analyst

đŸ”„ 0 minutes ago

🌐 Germany, Poland – Remote

infoinfo

⏰ Full Time

🟡 Mid-level

🟠 Senior

🔬 Research Analyst

đŸ‘» Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Sigma Software Group

Sigma Software Group

1001 - 5000 employees

Founded 2002

đŸ’Œ Consulting

đŸ„ Healthcare

🚘 Automotive

Consulting ‱ Healthcare ‱ Automotive

Sigma Software Group is a multinational company, established in 2002, that specializes in providing high-quality software development, graphic design, testing, and support services. The company focuses on delivering solutions across various industries such as automotive, telecommunications, aviation, advertising, gaming, banking, real estate, and healthcare. Sigma Software values professional growth, offers remote work opportunities worldwide, and caters to world-renowned clients like AstraZeneca, Scania, and SAS. The company emphasizes a culture of continuous education, mentorship, and flexible work environments, making it a preferred workplace for IT specialists aiming to work on complex solutions utilizing cutting-edge technologies. Sigma Software is committed to innovative solutions and engineering the future while also contributing to social causes such as charitable work in Ukraine.

📋 Description

‱ Monitor existing threats and investigate suspicious activities using logs, dashboards, and detection systems ‱ Analyze attack patterns and build detailed threat scenarios based on collected data ‱ Research and respond to reported threats, customer escalations, and security incidents ‱ Improve detection and blocking mechanisms for automated attacks and malicious behaviors ‱ Analyze intelligence from competitors, public sources, and industry trends to identify emerging threats ‱ Work with monitoring and analytics tools such as Kibana and Elasticsearch ‱ Collaborate with engineering and security teams to improve product protection capabilities ‱ Document findings, attack methodologies, and investigation results ‱ Contribute to a security platform safeguarding applications from automated attacks and malicious traffic

🎯 Requirements

‱ At least 3 years of commercial experience in cybersecurity, threat research, or related areas ‱ Hands-on experience in cybersecurity, threat detection, security research, threat hunting, anti-bot solutions, fraud and abuse detection, application security, or a closely related security domain ‱ Strong understanding of attacker tactics, techniques, and behaviors, including evasion, bypass, and attack modification methods ‱ Experience investigating suspicious or malicious activities and understanding detection, alerting, and blocking mechanisms ‱ Strong understanding of web technologies and architecture, including client-server architecture, HTTP/HTTPS, REST APIs and web services, request/response lifecycle, headers, cookies, sessions, and authentication mechanisms ‱ Understanding of browser technologies, including DOM structure and manipulation, browser events, XHR and Fetch requests, WebSockets, Browser APIs, and browser security policies and controls ‱ Ability to read and analyze JavaScript code and identify application behavior, suspicious or incorrect logic, and remediation approaches ‱ Working knowledge of HTML and CSS ‱ Strong practical experience with SQL for data analysis, investigations, and large datasets ‱ Hands-on experience using Kibana for log analysis, monitoring, and investigations ‱ Solid understanding of networking fundamentals, including TCP/IP, DNS, VPN technologies, proxies, and basic network troubleshooting ‱ Ability to independently investigate complex technical issues and correlate multiple data points into complete attack or incident scenarios ‱ Experience using AI-powered tools and chatbots for research and technical investigations, including writing effective prompts and interpreting results ‱ Upper-Intermediate (B2) or higher level of English ‱ Preferred/plus: Understanding of Elasticsearch and its ecosystem ‱ Preferred/plus: Python scripting and automation skills ‱ Preferred/plus: Experience developing, analyzing, or investigating crawlers, scrapers, or browser automation tools ‱ Preferred/plus: Experience with deobfuscation and/or reverse engineering techniques ‱ Preferred/plus: Experience investigating bot traffic, automated attacks, scraping activity, credential stuffing, account takeover attempts, abuse, fraud, or similar threats ‱ Preferred/plus: Experience with monitoring, analytics, and observability platforms such as Datadog, Imply, Splunk, Microsoft Sentinel, OpenSearch, or similar tools

đŸ–ïž Benefits

‱ Remote work within European time zones ‱ Opportunity to work on impactful security products ‱ Collaboration with experienced professionals ‱ Opportunity to grow expertise in modern cybersecurity technologies

Apply Now