Threat Research Analyst
- Monitor existing threats and investigate suspicious activities using logs, dashboards, and detection systems
- Analyze attack patterns and build detailed threat scenarios based on collected data
- Research and respond to reported threats, Customer escalations, and security incidents
- Improve detection and blocking mechanisms for automated attacks and malicious behaviors
- Analyze intelligence from competitors, public sources, and industry trends to identify emerging threats
- Work with monitoring and analytics tools such as Kibana and Elasticsearch
- Collaborate with engineering and security teams to improve product protection capabilities
- Document findings, attack methodologies, and investigation results
- At least 3 years of commercial experience in cybersecurity, threat research, or related areas
- Hands-on experience in cybersecurity, threat detection, security research, threat hunting, anti-bot solutions, fraud and abuse detection, application security, or a closely related security domain.
- Strong understanding of attacker tactics, techniques, and behaviors, including methods used to evade, bypass, or modify attacks to avoid detection.
- Experience investigating suspicious or malicious activities, with a solid understanding of detection, alerting, and blocking mechanisms.
- Strong understanding of web technologies and architecture, including:
- Client-server architecture
- HTTP/HTTPS protocols
- REST APIs and web services
- Request/response lifecycle
- Headers, cookies, sessions, and authentication mechanisms
- Understanding of browser technologies and experience investigating:
- DOM structure and manipulation
- Browser events
- XHR and Fetch requests
- WebSockets
- Browser APIs
- Browser security policies and controls
- Ability to read and analyze JavaScript code, identify application behavior, detect suspicious or incorrect logic, and understand potential remediation approaches. Deep JavaScript development expertise is not required.
- Working knowledge of HTML and CSS sufficient to investigate and understand web application behavior.
- Strong practical experience with SQL for data analysis, investigations, and working with large datasets.
- Hands-on experience using Kibana for log analysis, monitoring, and investigations.
- Solid understanding of networking fundamentals, including:
- TCP/IP
- DNS
- VPN technologies
- Proxies
- Basic network troubleshooting
- Ability to independently investigate complex technical issues and correlate multiple data points to build a complete attack or incident scenario.
- Experience using AI-powered tools and chatbots for research and technical investigations, including the ability to write effective prompts and interpret results.
- Upper-Intermediate (B2) or higher level of English.
WILL BE A PLUS
- Understanding of Elasticsearch and its ecosystem.
- Python scripting and automation skills.
- Experience developing, analyzing, or investigating crawlers, scrapers, or browser automation tools.
- Experience with deobfuscation and/or reverse engineering techniques.
- Experience investigating bot traffic, automated attacks, scraping activity, credential stuffing, account takeover attempts, abuse, fraud, or similar threats.
- Experience with monitoring, analytics, and observability platforms such as Datadog, Imply, Splunk, Microsoft Sentinel, OpenSearch, or similar tools.
PERSONAL PROFILE
- Strong analytical and investigative mindset
- Attention to detail and ability to identify unusual behavioral patterns
- Curiosity about cybersecurity threats and attacker techniques
- Ability to work independently in a fast-paced environment
- Strong communication and collaboration skills
- Proactive approach to problem-solving and continuous learning