A

Arctic Wolf

24x7 cloud-native cybersecurity with concierge SOC

Threat Researcher

Full-TimePosted on 9/29/2026
No salary listed
Mid
Bengaluru, Karnataka, India
In Person

About the job

Requirements
  • At least 4 years of professional experience as a Detection Developer or Security Developer.
  • Hands-on experience developing projects using Python or YAML.
  • Experience working with operating system telemetry, including Windows Security logs, Sysmon, and Linux telemetry.
  • Experience with Windows PowerShell monitoring and detection development.
  • Experience building Security Information and Event Management detections.
  • Experience developing endpoint detection and response detections or signatures.
  • Experience working with Sigma and YARA rules.
  • Experience developing anomaly-based and behavioral detections.
  • Experience tuning and optimizing detections across multiple telemetry sources.
  • Strong problem-solving, debugging, and analytical skills.
  • Ability to work effectively across distributed and cross-functional teams.
  • Ability to adapt to emerging technologies, security trends, and development best practices.
  • Ability to conduct duties in accordance with information security policies, standards, and controls.
  • Ability to pass required background checks.
Responsibilities
  • Develop and maintain Python- and YAML-based detections, software, and supporting systems.
  • Research and develop expertise across multiple threat surfaces and telemetry sources.
  • Design and improve behavioral, anomaly-based, and signature-based detections.
  • Continuously tune and optimize detections to improve quality, scale, and performance.
  • Propose coverage and efficacy improvements across the detection surface.
  • Collaborate with team members to develop novel detection methodologies and improve existing detections.
  • Build runbooks, reports, and supporting operational material for detection surfaces.
  • Partner with cross-functional teams to gather requirements and implement detection capabilities.
  • Write clean, efficient, reusable, and secure Python code.
  • Conduct code reviews and provide constructive feedback to improve code quality and maintainability.
  • Debug and resolve issues within existing Python codebases and detection systems.
  • Participate in the full software development life cycle by building well-designed, testable, and efficient code.
  • Optimize application and detection performance while ensuring scalability and reliability.
  • Develop an understanding of the Arctic Wolf platform and Security Services delivery model.
  • Apply company policies and procedures to resolve operational and technical issues.
  • Continuously learn and adopt best practices in software engineering, detection development, and cybersecurity operations.
  • Provide mentorship and technical guidance to team members where appropriate.
  • Develop scalable and actionable detections that improve customer protection.
  • Continuously improve detection quality, coverage, and operational efficiency.
  • Collaborate across teams to deliver reliable and effective detection capabilities.
  • Deliver high-quality, maintainable, and scalable code.
  • Participate in innovation initiatives, technical demonstrations, and collaborative development efforts.
Desired Qualifications
  • Professional certifications in security or cloud technologies, such as Certified Information Systems Security Professional, GIAC Certified Forensic Analyst, or GIAC Reverse Engineering Malware.
  • Experience leading Agile development teams or formal Agile training.
  • Familiarity with full-stack development frameworks and practices.
  • Experience contributing to operational runbooks, reporting, or technical documentation.

About the company

Arctic Wolf provides continuous cybersecurity protection tailored to each organization. It uses a cloud-native platform paired with a dedicated concierge team to deliver around-the-clock monitoring and security operations (SOC) on a subscription basis. The platform integrates security functions to avoid tool sprawl and alert fatigue, while the concierge team works with clients to meet their specific needs. Clients pay for ongoing protection with 24x7 coverage, and Arctic Wolf offers tools like a Total Cost of Ownership Calculator to illustrate savings and ROI. This approach differentiates Arctic Wolf from competitors by combining a unified, cloud-based platform with a personalized delivery model that embeds security experts with each client. The goal is to improve clients’ security posture, reduce unnecessary security tool investments, and lower total costs while providing reliable, continuous monitoring.

Company Size

1,001-5,000

Company Stage

N/A

Total Funding

$899.2M

Headquarters

Eden Prairie, Minnesota

Founded

2012

Get referred to Arctic Wolf

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Aurora MDR Connect launched September 15, 2026, opening a bigger MSP distribution channel.
  • September 2026 India expansion added 90 hires, showing sustained investment in product velocity.
  • Arctic Wolf's frequent September 2026 vulnerability guidance keeps it visible during active exploit cycles.

What critics are saying

  • May 2026 layoffs cut 250 jobs, including sales and product, signaling margin pressure.
  • Huntress and Blackpoint attack MSPs with simpler, cheaper MDR; Arctic Wolf risks channel erosion.
  • Custom-quoted pricing and concierge-heavy delivery invite commoditization if AI reduces service differentiation.

What makes Arctic Wolf unique

  • Aurora Agentic SOC pairs human concierge analysts with AI-driven detection and response.
  • Arctic Wolf processes over 10 trillion security events weekly, per September 2026 launch materials.
  • Bengaluru became Arctic Wolf's largest R&D hub in September 2026, scaling platform engineering.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Equity For All Employees

Diverse, equitable, & inclusive workplace

Remote Work Opportunities

Paid Parental Leave

Flexible Paid Time Off For All Employees

Professional Development

Growth & Insights and Company News

Headcount

6 month growth

↑ 0%

1 year growth

↑ 0%

2 year growth

↑ 1%
Malware.News
Sep 23rd, 2026
2026 KuppingerCole Leadership Compass for MDR.

2026 KuppingerCole Leadership Compass for MDR. Arctic Wolf is a Leader across all four categories of the 2026 KuppingerCole Leadership Compass for MDR - recognised for the Aurora(R) Superintelligence Platform, the concierge model, and GenAI-supported investigation. Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor. Enroll Now and Save 10%: Coupon Code MWNEWS10 Note: Affiliate link - your enrollment helps support this platform at no extra cost to you. New & unread topics.

MSSP Alert
Sep 18th, 2026
Arctic Wolf launches new MDR offering for managed service providers.

Arctic Wolf launches new MDR offering for managed service providers. September 18, 2026 Arctic Wolf announced the launch of Aurora MDR Connect, a managed detection and response offering designed for managed service providers (MSPs). This new service aims to provide a streamlined version of Arctic Wolf's cybersecurity platform to partners, enabling them to deliver enterprise-grade security to a wider range of customers more quickly, as reported by Channeldive. Aurora MDR Connect builds upon Arctic Wolf's existing managed detection and response (MDR) services, specifically targeting MSPs that serve midmarket companies and those with fewer than 100 employees. The offering simplifies deployment by eliminating the need for network sensors, relying solely on endpoint agents to collect security data. This allows for faster implementation and reduced operational complexity, catering to businesses embracing remote and hybrid work models. Arctic Wolf's strategy involves treating MSPs as their direct customers, empowering them to integrate Arctic Wolf's technology with their own services. Analysts note that this move positions Arctic Wolf to compete with other MDR providers like Huntress and Blackpoint, though the company must carefully manage its partner tiers to avoid cannibalization. The company emphasizes its channel-first approach, with its MSP program being its fastest-growing business unit.

Malware.News
Sep 15th, 2026
Arctic Wolf Launches Aurora MDR Connect, Helping MSPs Bring the Benefits of the Enterprise-Grade Aurora Agentic SOC to More Customers, Faster.

Arctic Wolf Launches Aurora MDR Connect, Helping MSPs Bring the Benefits of the Enterprise-Grade Aurora Agentic SOC to More Customers, Faster. Aurora(R) MDR Connect combines rapid deployment, broad attack surface visibility, and the Aurora Superintelligence Platform's AI-driven detection and response capabilities to help MSPs protect more customers with less operational complexity. EDEN PRAIRIE, Minn. - Sept. 15, 2026 - Arctic Wolf(R), the cybersecurity and AI company, today announced the launch of Aurora MDR Connect, a new... Arctic Wolf Launches Aurora MDR Connect, Helping MSPs Bring the Benefits of the Enterprise-Grade Aurora Agentic SOC to More Customers, Faster Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor. Enroll Now and Save 10%: Coupon Code MWNEWS10 Note: Affiliate link - your enrollment helps support this platform at no extra cost to you. New & unread topics.

CxOToday
Sep 7th, 2026
Arctic Wolf Makes Bengaluru Its Largest Global R&D Hub

Home media coverage Arctic Wolf makes Bengaluru its largest global R&D hub. Sep. 07, 2026 at 10:54 pm Expands the workforce from 46 in 2024 to more than 550in 2026. Arctic Wolf today announced the expansion of its Research and Development (R&D) centre in Bengaluru, making it the company's largest R&D centre worldwide. This marks the second expansion since Arctic Wolf launched its India operations in September 2024. The expansion grows the Arctic Wolf India workforce from 46 employees in 2024 to more than 550 today. Arctic Wolf plans to hire 90 additional employees as it continues to scale its India operations. The expansion also grows the Bengaluru facility itself. The site now spans 55,000 square feet with seating capacity for 550 employees. Located at The Helios Business Park in Marathahalli, the facility serves as Arctic Wolf's core engineering and product development hub for its cloud-native Aurora(R) Platform and plays a growing role in the company's AI-driven threat detection and response work. Bengaluru now accounts for nearly 20% of Arctic Wolf's global workforce. Teams there span engineering, IT infrastructure, product management, program management, AI and Security Operations. Nick Schneider, President and CEO of Arctic Wolf, said, "The investment reflects the company's next phase of growth. "The threat landscape is constantly evolving and staying ahead requires continuous research to anticipate emerging threats before they materialize. Our teams in India are playing an increasingly important role in that work, and this expansion is a clear step toward scaling it further." "India has moved from being a delivery centre to being central to how we build our platform," said Devendra Rath, Vice President, Engineering, Arctic Wolf India. Since it was established in 2024, Arctic Wolf's India operations have grown from a newly formed team into an integral part of the company's global R&D organization. This latest expansion reflects the depth of that capability, and the role India will play in Arctic Wolf's growth going forward.

SecurityBrief Asia
Sep 2nd, 2026
Sectigo appoints Ian Hassard as Chief Product Officer.

Sectigo appoints Ian Hassard as Chief Product Officer. Wed, 2nd Sep 2026 (Today) Sectigo has appointed Ian Hassard as Chief Product Officer, adding a senior product executive to the certificate management company's leadership team. Hassard will lead global product strategy and oversee further development of Sectigo Certificate Manager, the company's certificate lifecycle management platform. The appointment comes as companies face shorter certificate lifespans, rising numbers of non-human identities, and preparations for post-quantum cryptography. Certificate lifecycle management has become a closer focus for cyber and IT operations as businesses handle growing numbers of digital certificates used to secure websites, applications, devices, and machine-to-machine communications. Shorter certificate validity periods can increase the operational burden on internal teams, particularly when certificate inventories are fragmented or renewal processes remain manual. In the role, Hassard will work with engineering and go-to-market teams to set product direction and shape how Sectigo adapts its platform to changing customer and market requirements. The hire brings Sectigo an executive with more than 20 years of experience across identity, cybersecurity, and software-as-a-service markets. Before joining Sectigo, Hassard was Vice President of Product Management at Okta, where he led product strategy across the Auth0 and Okta Customer Identity portfolio. Earlier in his career, he co-founded RootSecure, a cybersecurity company later acquired by Arctic Wolf. He then held product leadership roles at Arctic Wolf during a period of growth for the business. Sectigo is framing the appointment as part of a broader push to expand its certificate lifecycle management platform as digital identity management becomes more complex. It says it serves more than 700,000 customers, including 65% of the Fortune 500. Digital certificates sit at the centre of secure online communications, but they also create operational risks when organisations lose visibility into where certificates are deployed and when they expire. Unmanaged certificates can lead to service outages, compliance problems, and disruption across networks, cloud systems, and connected devices. Market pressure The issue has gained prominence as machine identities proliferate across enterprise environments. As more workloads move across hybrid and cloud infrastructure, companies are managing far larger certificate inventories than in the past, making automated oversight a more important part of security operations. That backdrop has created a competitive market for vendors offering tools to discover, issue, renew, and revoke certificates across complex IT estates. Identity and access management groups, cybersecurity specialists, and certificate authorities have all sought to deepen their role in that market. Chief Executive Officer Kevin Weiss described Hassard as a product leader suited to that environment. "Ian is the kind of product leader who can turn a rapidly changing market into a clear and compelling product vision," said Kevin Weiss, Chief Executive Officer, Sectigo. "He has an impressive track record of building and scaling security and identity products through periods of significant growth and complexity, while translating major technology shifts into solutions customers can adopt and trust. Ian's leadership will strengthen our ability to deliver on our promise of Simplicity at Scale and accelerate the next phase of innovation across our CLM platform." Hassard's experience at Okta is likely to be relevant as identity products increasingly overlap with certificate and machine identity management. Businesses are under pressure to manage not only workforce and customer identities, but also the credentials used by software workloads, devices, and automated systems. His focus will include helping customers simplify certificate operations, reduce risk, and prepare for shifts in digital trust requirements, including the eventual transition to cryptographic standards designed to withstand attacks from quantum computers. Product focus Post-quantum cryptography has become a strategic planning issue for many security vendors and large enterprises, even though broad implementation remains at an early stage. For certificate management providers, that creates a need to support migration planning and lifecycle controls as cryptographic standards evolve. Hassard said certificate lifecycle management now sits at the centre of digital operations for many organisations. "Certificate Lifecycle Management is becoming foundational to how organizations secure digital operations at scale," said Hassard. "Sectigo has the market position, technology and depth of expertise to define where this category goes next. I'm excited to build on that strength and advance a platform that makes it easier for organizations to manage growing certificate complexity, reduce risk and prepare for what comes next." Hassard also brings an inventor's background to the role, with multiple patents spanning identity, security, and emerging technologies, according to Sectigo. The profile suggests the company is seeking product leadership with both commercial and technical depth as competition intensifies in digital trust and machine identity management. Sectigo has operated in the certificate authority market for more than 20 years. It remains one of the larger established providers in a sector being reshaped by automation demands, tighter security controls, and the growing volume of certificates inside modern IT environments.