Full-Time

Threat Researcher

Confirmed live in the last 24 hours

Abnormal Security

Abnormal Security

1,001-5,000 employees

AI-driven email security against cyber threats

No salary listed

Senior, Expert

Remote in UK

Category
Cybersecurity
IT & Security
Required Skills
Microsoft Azure
SQL
Data Analysis
Requirements
  • 5+ years in threat research, cyber threat intelligence, or adversary tracking.
  • 3+ years focused on Microsoft cloud security (Azure, M365, Defender, Entra ID, or Sentinel).
  • Expertise in Microsoft cloud security architecture, identity protection, SaaS security, and misconfiguration risks.
  • Strong data analysis skills with experience using SQL, PySpark, KQL, or similar tools to analyze cloud-based threats.
  • Deep knowledge of MITRE ATT&CK, Microsoft attack techniques, and adversary tradecraft.
  • Hands-on experience with Microsoft Defender for Office 365, Defender for Identity, and Microsoft Sentinel.
Responsibilities
  • Conduct in-depth research on Microsoft cloud security threats, phishing techniques, and identity-based attack vectors.
  • Track APT groups, financially motivated actors, and cloud-native threat campaigns targeting Azure and Microsoft 365 environments.
  • Analyze MFA bypass techniques, token theft, session hijacking, and adversary tactics used against Microsoft authentication mechanisms.
  • Reverse-engineer phishing kits, adversary infrastructure, and cloud-native attack methodologies to enhance security insights.
  • Develop threat models and in-depth attack reports to inform Microsoft-focused threat intelligence.
  • Research misconfigurations, security posture risks, and SaaS security gaps in Microsoft Entra ID, Azure AD, and M365 security settings.
  • Develop SSPM research insights and contribute to configuration playbooks to improve Microsoft cloud security posture.
  • Identify misconfiguration-driven threats and work with Engineering to enhance detection and mitigation strategies.
  • Analyze security posture deviations that could expose Microsoft environments to account takeovers, phishing, and privilege escalation attacks.
  • Provide deep-dive research into Microsoft cloud attack methodologies to help enhance security product capabilities.
  • Work with R&D and Engineering teams to ensure research findings translate into practical security enhancements.
  • Deliver technical briefings and intelligence reports on Microsoft threat trends, attacker tactics, and detection opportunities.
  • Partner with internal stakeholders to evaluate emerging threats and recommend security improvements for Microsoft cloud environments.
Desired Qualifications
  • Experience working with or building SSPM solutions for Microsoft cloud security posture management.
  • Security certifications (GCTI, GCFA, CISSP, or Microsoft security-related).
  • Experience in cloud-native security research, attack simulations, or misconfiguration exploitation analysis.
  • Background in SaaS security posture analysis and cloud security hardening.

Abnormal Security protects organizations from advanced cyber threats, particularly those targeting email communications. The company uses artificial intelligence and machine learning to identify and block risks like phishing, malware, and business email compromise, which often evade traditional security systems. Its services are tailored for large enterprises that need strong security measures to safeguard sensitive information. Abnormal Security differentiates itself by offering a subscription-based model that integrates easily with existing email systems, allowing for quick setup without disrupting business operations. The goal is to continuously enhance its security offerings through ongoing research and development, ensuring clients are protected against evolving cyber threats.

Company Size

1,001-5,000

Company Stage

Series D

Total Funding

$519.4M

Headquarters

San Francisco, California

Founded

2018

Simplify Jobs

Simplify's Take

What believers are saying

  • Raised $250M in Series D funding, valuing the company at $5.1 billion.
  • Expanding product line beyond email to include cross-platform security solutions.
  • Named to CNBC Disruptor 50 list, highlighting rapid growth and innovation.

What critics are saying

  • Increased competition from emerging AI-powered cybersecurity startups like Patlytics.
  • Potential market saturation in the email security sector leading to pricing pressures.
  • Regulatory scrutiny on AI technologies could increase compliance costs.

What makes Abnormal Security unique

  • Abnormal Security uses AI to model human behavior for email threat detection.
  • The platform integrates seamlessly with existing email systems via API for quick deployment.
  • Recognized as a Leader in Gartner's Magic Quadrant for Email Security Platforms 2024.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Competitive pay and equity

One of the most proven machine learning teams in Silicon Valley

Best-in-class customer traction and growth

Team-wide commitment to excellence, velocity, and customer-focus

Strong growth opportunities and high ownership expectations

Full medical, dental, and vision health insurance benefits

Daily catered lunches and snacks

Generous PTO

Growth & Insights and Company News

Headcount

6 month growth

-1%

1 year growth

-3%

2 year growth

-8%
SDxCentral
Dec 20th, 2024
Abnormal Security recognized as Leader in 2024 Gartner Magic Quadrant for Email Security Platforms

Abnormal Security has been recognized as a Leader in the inaugural Gartner Magic Quadrant for Email Security Platforms.

PR Newswire
Nov 19th, 2024
Patlytics Announces New Company Momentum For Its Genai-Powered Patent Intelligence Platform

The company has secured additional funding, expanded its customer base with leading AM100 firms and global enterprise customers, and enhanced its AI product capabilities. SAN FRANCISCO, Nov. 19, 2024 /PRNewswire/ -- Patlytics, the AI-powered patent workflow platform, today announced significant company growth, including commercial traction from AM100 firms and global enterprise customers, new product upgrades, and additional funding led by Myriad Venture Partners. Following a successful $4.5 million seed round in April, the company has seen a 20x increase in ARR and an 18x expansion in its customer base in just six months, with a sustained 300% month-over-month growth rate. This momentum underscores Patlytics' leadership in transforming the patent intelligence landscape. "We're in a pivotal moment where businesses are strategically evaluating how AI can transform their IP processes," says Paul Lee, founder and CEO of Patlytics

GovTech Insider
Nov 14th, 2024
Abnormal Security Names Lexi Cormier to Regional Account Executive Role

Lexi Cormier, a veteran technology professional with extensive private-sector experience, has joined Abnormal Security as a regional account executive overseeing Florida's market.

The CyberWire
Aug 14th, 2024
Business Briefing for 08.14.24

San Francisco-based email security firm Abnormal Security has secured $250 million in a Series D round led by Wellington Management, with participation from existing investors Greylock Partners, Menlo Ventures, Insight Partners, and CrowdStrike Falcon Fund.

Tech Startups
Aug 6th, 2024
Cybersecurity startup Abnormal Security secures $250M in funding at $5.1 billion valuation, eyes IPO

Cybersecurity startup Abnormal Security has raised $250 million in a Series D funding round that pushes the company's valuation to $5.1 billion.