ExtraHop is on a mission to protect and propagate trust by revealing the cybertruth: the truth about the attackers already inside an organization’s network, the truth about what they’re doing, and how to stop them at top speed. We partner with every customer, every day, to reveal it. Are you ready to join us?

We are ExtraHop. We’re on a mission to provide security teams with the intelligence they need to confront and stop advanced threats like supply chain attacks, zero day exploits, and ransomware attacks. Attackers still have the advantage. We’re taking it back with creativity, intellectual curiosity, and a sense of humor. Are you ready to help us reclaim the upper hand?

Do you like securing complex networks? Want to be a part of a collaborative team that builds solutions that protect some of the biggest networks in the world? ExtraHop is seeking a Security Engineer III – Threat Research experienced with threat detection and networking to grow our world-class Detection Engineering team.

We are looking for a self-starter that enjoys investigating cyber attacks and how adversaries are traversing the network for lateral movement. You must have a strong understanding of the attack lifecycle and a deep desire to stop attackers before they can do damage.

Duties & Responsibilities

  • Reproduce and analyze network-based cyber attacks, including vulnerability exploitation and lateral movement.
  • Communicate in writing your research findings and collaborate in writing detectors to detect cyber attacks.

Required Skills & Experience

  • Bachelor’s degree or equivalent experience in cyber security, computer science, engineering, or network forensics.
  • Strong understanding of network security and networking basics, including the OSI model and excellent working knowledge of the key protocols from Layer 2 through Layer 7, including IP, TCP, UDP, and HTTP.
  • Experience in penetration testing, red teaming, or capture the flag competitions that include hands-on execution of attacks and vulnerability exploitation.
  • Good communication skills with the ability to clearly communicate in writing technical details about attacks.
  • Strong working experience in using Wireshark, TShark, or other network analysis tools.
  • Strong working experience with Python or equivalent scripting languages.

Desired Skills & Experience

  • 3+ years of professional experience as a Threat Researcher, Penetration Tester, Detection Engineering, or Vulnerability Researcher.
  • Familiarity with MITRE’s ATT&CK Framework.
  • Familiarity with VM and container technologies for setting up ephemeral environments for research.
  • Familiarity with Windows protocols and reconnaissance and lateral movement techniques in Windows environments.

All R&D Employees will be required to attend 2 mandatory in-person events every year of approx. 4 days duration.

$136,000- $180,000 + benefits

Applicants must be authorized to work for ANY employer in the U.S.  We are unable to sponsor or assume sponsorship of an employment Visa at this time.


Job Overview
Job alerts

Subscribe to our weekly job alerts below and never miss the latest jobs

Sign in

Sign Up

Forgotten Password

Job Quick Search