Security Research Engineer - (Member of Security Staff)
Compensation: ₨56k – ₨56k • 0.3% – 0.5%
Team: Security / Detection & Intelligence Location: Remote (Pakistan) - Gulf/USA timezone overlap required Level: Early-career / Associate (0–2 years)
About Himaya
Himaya is an AI-native email and SaaS security platform built for organizations in the Gulf region. We protect enterprises against phishing, BEC, malware, and data loss across email, SaaS applications, and cloud data stores -combining threat intelligence, LLM-based classification, sandbox detonation, and data security posture management (DSPM) in one platform.
**The Role **
We're hiring an early-career Security Research Engineer to help build the detection brain of Himaya. You'll work on intelligence and detection logic across three pillars -SaaS security, email threat analysis, and DLP -turning real-world attacker behavior into detections that ship to production. You'll also assist with our SOC 2 certification effort and ongoing audit upkeep. High ownership, direct mentorship, and your research becomes product.
What You'll Do
- Build and tune detection logic for email threats — phishing, BEC, credential harvesting, malware, lookalike domains, and impersonation.
- Develop SaaS security detections — OAuth app risk, posture/misconfiguration drift, anomalous admin actions, risky-user signals (M365/Google).
- Improve DLP detections — sensitive-data classification, exfiltration patterns, and policy logic that balances recall with low noise.
- Curate and operationalize threat intelligence — feeds, IOC packs, domain/IP reputation, and enrichment for the detection pipeline.
- Analyze real samples and sandbox output to close detection gaps and reduce false positives.
- Assist with SOC 2 readiness — control-evidence collection, remediation tracking, and security documentation.
What We're Looking For
- 0–2 years in security, detection engineering, threat research, or a related area — internships, CTFs, and self-taught projects count.
- Understanding of email security fundamentals (SPF/DKIM/DMARC, header analysis, phishing/BEC tradecraft).
- Some exposure to SaaS/cloud security and/or DLP concepts.
- Comfortable writing Python and working with data.
- Analytical, evidence-driven mindset; clear written communication.
Nice to Have
- Exposure to SOC 2 / ISO 27001, YARA, malware triage, or sandboxing.
- Familiarity with LLM-based classification.
- Arabic and Gulf-region threat-landscape awareness.
**Compensation & Equity **
Salary: $200/month (≈ PKR 56,000/month). Equity: 0.5%, vesting over 4 years.
Why Himaya
- Ground-floor security hire -your research ships to production and protects real organizations.
- Wide surface area across email, SaaS, DLP, and DSPM, with real ownership.