
Staff Developer
Arctic Wolf3 days ago
Bengaluru, IndiaStaff+
Responsibilities
- Research vulnerabilities, system misconfigurations, and exposure risks and translate findings into detection capabilities.
- Develop, test, and maintain vulnerability and misconfiguration detection content across asset types and security technologies.
- Build plugins and integrations with third-party enterprise platforms and services using public APIs.
- Develop host-based and network-based vulnerability tests, attack-path queries, and exposure-related queries.
- Create configuration benchmark automation, pipeline hardening checks, and security policy content.
- Develop Python or other scripting-based automation and enrichment workflows and participate in incident management and on-call rotations.
- Partner with product, triage, security services, and operational teams to integrate intelligence into detection, triage, and response workflows.
- Use AI-powered development tools, code assistants, augmented debugging, and automated testing to improve delivery and code quality.
Requirements
- Experience in security research engineering focused on vulnerability identification, vulnerability detection, misconfiguration detection, and security content development.
- Experience using OWASP Top 10, MITRE ATT&CK, and CIS Benchmarks or comparable security methodologies and frameworks.
- Experience developing vulnerability detection content with NASL, Notus, OpenVAS Language, and Derived Exposures.
- Strong programming experience in at least one backend or scripting language such as Python, Go, Rust, or Bash.
- Experience with PostgreSQL or MongoDB and understanding of data modeling and query development.
- Experience with AWS, Docker, Kubernetes, and Infrastructure as Code.
- Strong understanding of secure software development practices and Security Development Operations methods.
- Knowledge of HTTP, SSH, SMB, SNMP, TLS/SSL, the Windows Registry, and Linux file systems.
- Ability to independently research complex security problems, develop detection solutions, and collaborate cross-functionally.
- Preferred experience with Qualys, Nessus, Rapid7, OpenVAS, Azure Security Center, AWS Security Hub, Sonrai, CloudSploit, Prisma Cloud, Nmap, Burp Suite, Metasploit, Salt, or Ansible.
- Preferred experience developing security content for large-scale security platforms or exposure management products.
- Preferred experience mentoring engineers or serving as a technical lead on security research and detection engineering initiatives.
Benefits
- Equity for all employees.
- Flexible annual leave, paid holidays, and volunteer days.
- Training and career development programs.
- Comprehensive private benefits including medical insurance for employees and families, life insurance, and personal accident insurance.
- Fertility support and paid parental leave.
- Remote interview candidates are expected to be on camera during video interviews, with accommodations available for technical, bandwidth, or location-related challenges.
- Background checks are required, and employment may be conditioned on authorization to receive technology controlled under U.S. export control laws.