Staff Threat Research Engineer

Sumo Logic Sumo Logic · Enterprise · United States · Software Engineering

Staff Threat Research Engineer role focused on advancing threat detection by researching attacker behaviors, particularly in cloud and AI environments. The role involves turning threat intelligence into practical detections for the Sumo Logic SIEM platform, conducting original investigations, and contributing to the security community.

What you'd actually do

  1. Conduct and lead both applied and original threat research, transforming intelligence, telemetry, and investigation into actionable detection logic for the Sumo Logic SIEM.
  2. Collaborate closely within Threat Labs to design, build, and refine detection content and validation pipelines that raise the bar for product and customer detection quality.
  3. Drive innovation in detection methodologies, including research activities such as malware analysis, infrastructure tracking, or honeypot operations, to discover new attacker behaviors.
  4. Publish and share findings — from detection logic to behavioral analysis and practical hunting guidance — that help customers maximize SIEM outcomes.
  5. Contribute to Threat Labs’ long‑term vision of a research‑driven, continuously evolving detection ecosystem built on practitioner insight and technical depth.

Skills

Required

  • cybersecurity experience
  • threat research
  • detection logic
  • malware analysis
  • infrastructure tracking
  • honeypot operations
  • cloud logs and telemetry analysis
  • emerging attack techniques targeting AI infrastructure
  • machine learning pipelines
  • MITRE ATLAS
  • thought leadership
  • blogs
  • LinkedIn articles
  • conference presentations
  • cybersecurity vendor space experience
  • feedback to product and engineering teams

Nice to have

  • customer-facing technical roles
  • offensive security tools
  • Python
  • PowerShell
  • SOAR technology
  • security community presence
  • AI or machine learning techniques for detection rule development

What the JD emphasized

  • 12+ years of cybersecurity experience
  • Demonstrated ability to progress threat research into actionable detections and incident response outcomes
  • Experience conducting original or self‑directed threat research that resulted in novel findings
  • Understanding of emerging attack techniques targeting AI infrastructure and machine learning pipelines
  • Proven history of thought leadership through blogs, LinkedIn articles, or conference presentations

Other signals

  • AI infrastructure and machine learning pipelines
  • emerging attack techniques targeting AI
  • MITRE ATLAS