Simplify Logo

Full-Time

Head of Threat Intel & Platform Research

Posted on 7/12/2024

Abnormal Security

Abnormal Security

501-1,000 employees

AI-driven email security against cyber threats

Cybersecurity
AI & Machine Learning

Compensation Overview

$212.4k - $249.9kAnnually

+ Bonus + Restricted Stock Units (RSUs)

Senior, Expert

Remote in USA

Category
Cybersecurity
IT & Security
Required Skills
PowerShell
Microsoft Azure
Python
SQL
Salesforce
AWS
JIRA
Confluence
Google Cloud Platform
Requirements
  • Bachelor’s Degree in Information Security, Computer Science, Digital Forensics, Cyber Security, or equivalent years of professional experience to meet job requirements and expectations
  • 5+ years of experience in the security domain, including both a detailed understanding of attacker techniques and tracking the threat actors behind specific campaigns
  • 3+ years of direct experience in security research, malware analysis, or incident response
  • 2+ years working within the email threat landscape
  • Experience working with and understanding phishing kits/PhaaS providers (e.g., Caffeine)
  • Direct experience querying and analyzing large datasets (e.g., SQL, Python, KQL/Azure Data Explorer, Excel, PowerBI, etc.)
  • Experience analyzing email headers and email/web security protocols
  • Malware analysis (PE Files, Script Files, Office Files)
  • Yara, RegEx, or comparable rule-writing experience
  • Scripting languages (e.g., Python, PowerShell)
  • Understand OWASP & MITRE ATT&CK framework
  • For non-NAM candidates: must be willing to work NAM hours (around 3-5 meetings per week in NAM hours)
Responsibilities
  • Conduct research to support durable detection investments and improve customer experience. Research will include analysis of email threats, which are included but not limited to phishing attacks, Phishing as a service (PhaaS), spear phishing, business email compromise (BEC), and ransomware campaigns
  • Research and investigate account takeover (ATO) attacks impacting cloud hosted email (M365, GWS), major SaaS platforms (Salesforce, ServiceNow, Workday), and cloud infrastructure platforms ( AWS, Azure, GCP). The ability to decompose and describe the techniques, tactics, and procedures (TTPs) attackers use to successfully execute these attacks
  • Lead a matrixed team of SaaS product experts to guide and inform product development teams on attack techniques, secure posture of the platforms, and in-depth guidance on detecting and remediating attacks within each platform
  • Develop and maintain a comprehensive understanding of the evolving tactics, techniques, and procedures (TTPs) used by threat actors in email-based attacks. Stay current with industry trends, security vulnerabilities, and email security best practices to anticipate and counter emerging threats effectively
  • Identify external sources of information that could improve email understanding, including domain data, IP data, and IOC feeds. Own the process of procuring and validating the usefulness of these tools in the threat hunting use case.
  • Produce collateral and output to the Abnormal Intelligence website + Jira/Confluence on a regular cadence
  • Collaborate with Detection teams to investigate and analyze suspicious emails and campaigns, providing actionable insights and recommendations for detection and response
  • Operate and mature an iterative Threat hunting cycle, which involves searching our data for threat trends and creating reports of these trends to inform Detection investment
  • Own and operate a 30-60 minute 'threat deep dive' process in which this individual walks the members of the engineering team through threats that have been missed
  • Serve as the threat intel/email understanding expert in the room during 'FN reviews' with the Message Detection (Machine Learning Engineering) team
  • Analyze and assess platform postures and educate engineering on the risks and signals associated with risky posture settings
  • Work closely with the content marketing team to publish findings, reports, and blog posts to help establish Abnormal as a thought leader and the 'go to' spot for the latest information on sophisticated social engineering, email, and ATO attacks

Abnormal Security protects organizations from advanced cyber threats, particularly those targeting email communications. The company uses artificial intelligence and machine learning to identify and block risks like phishing, malware, and business email compromise, which often evade traditional security systems. Its services are tailored for large enterprises that need strong security measures to safeguard sensitive information. Abnormal Security operates on a subscription model, allowing clients to easily integrate its platform with their existing email systems through an API, ensuring quick setup and minimal disruption. Unlike many competitors, Abnormal Security focuses specifically on email threats and has a leadership team with deep expertise in AI and cybersecurity from major tech companies. The goal is to continuously enhance their security offerings to stay ahead of evolving cyber threats.

Company Stage

Series C

Total Funding

$374M

Headquarters

San Francisco, California

Founded

2018

Growth & Insights
Headcount

6 month growth

15%

1 year growth

31%

2 year growth

33%
Simplify Jobs

Simplify's Take

What believers are saying

  • The recent $210 million Series C funding round and a $5 billion valuation highlight strong investor confidence and significant growth potential.
  • Being named to the CNBC Disruptor 50 list underscores Abnormal Security's innovative approach and rapid market impact.
  • Expansion beyond email security to protect against cross-platform threats positions the company for broader market penetration and increased customer value.

What critics are saying

  • The rapidly evolving nature of cyber threats requires continuous innovation, posing a challenge to maintain a competitive edge.
  • High reliance on AI and ML could lead to vulnerabilities if adversaries develop countermeasures.

What makes Abnormal Security unique

  • Abnormal Security leverages AI and ML to detect sophisticated email-based threats, offering a more advanced solution compared to traditional cybersecurity measures.
  • The company's seamless API integration allows for quick deployment with minimal disruption, a significant advantage over competitors with more cumbersome implementations.
  • Abnormal Security's leadership team, with experience from tech giants like Google and Amazon, brings unparalleled expertise in AI and enterprise security.

Benefits

Competitive pay and equity

One of the most proven machine learning teams in Silicon Valley

Best-in-class customer traction and growth

Team-wide commitment to excellence, velocity, and customer-focus

Strong growth opportunities and high ownership expectations

Full medical, dental, and vision health insurance benefits

Daily catered lunches and snacks

Generous PTO

INACTIVE