Full-Time

Security Developer

Aurora Endpoint Defense Team

Posted on 8/9/2025

Arctic Wolf

Arctic Wolf

1,001-5,000 employees

24x7 cloud-native cybersecurity with concierge SOC

No salary listed

Cork, Ireland

In Person

US Top Secret Clearance Required

Category
IT & Security (1)
Required Skills
Agile
Python
Git
SQL
Linux/Unix
Databricks
Requirements
  • 2+ years of professional experience as a Security Developer
  • Experience consists of projects contributing to either Python or YAML
  • OS Specific Telemetry: Windows Security/Sysmon logs, Linux, MacOS
  • Experience with applying the MITRE ATT&CK framework to intelligence products and associated depth of analysis for each TTP and threat actor represented in this body of knowledge
  • Windows PowerShell Monitoring
  • Understanding of threat protection/detection tooling/stacks: SIEM,XDR/EDR
  • EDR detections/signatures
  • Sigma and Yara Rules
  • SQL Knowledge, Databricks is a plus.
  • Experience using Git repositories (GitHub, Git Bash, GitLab)
  • Experience using Virtual Machines (VMware workstation)
  • Development of anomaly and behavioral based detections
  • Tuning and optimization of detections for all the above
  • Professional certifications in Security and/or Cloud are required (i.e. CISSP, GNFA, GCFA, GCFE, GREM).
  • Experience consists of leading a team of 3 or more Security Developers while contributing code independently
  • Experience leading Agile development teams, preferably with formal Agile training
  • Resourceful self-starter with a positive, can-do attitude
Responsibilities
  • Analyze, research, and develop new detection rules for Aurora Focus, applying MITRE ATT&CK framework.
  • Understand the product and how Security Services delivers the service.
  • Convert investigations performed by our Threat Teams: TRI\, AR\CTI\TIO\TRO into new content (detection/telemetry rules).
  • Customer Escalation (BFD), collaborate with S2 teams on investigations regarding emerging threats, to generate new detection rules.
  • Fine Tune/Calibration: determining true threats or false positives, and providing solutions, like exclusions, logic change or decreasing severity.
  • Writing clean, efficient, and reusable code in Python.
  • Conducting code reviews and providing constructive feedback to ensure code quality and maintainability.
  • Ability to effectively manage multiple tasks simultaneously; coordinating and ensuring scheduled goals are met.
  • Maintain documentation up to date: new tool or process.
  • Run regression and end-2-end testing
  • Push production releases, and notification emails.
  • Collaborating with cross-functional teams to gather requirements and implement detections.
  • Participate in Purple Teaming exercises as Blue Teamer.
  • Generate metrics over Databricks Dashboard.
  • Deliver regular threat briefing presentations to internal & external stakeholders on topics ranging from threat actor campaign activity, novel TTPs, and emerging malware or exploits.
  • Utilize best practices for threat research and documentation and deliver high-quality detection rules.
  • Optimizing application performance and ensuring scalability.
  • Participate in the full software development life cycle, building well-designed, testable, efficient, secure code.
  • Continuously learning and adopting best practices for code quality, software development methodologies, and programming principles to enhance coding skills and stay updated with industry advancements.
Desired Qualifications
  • A clear history of technical influence (public conference talks, papers, etc)
  • A clear history of learning and skills development. Regularly helps security developers develop their skills in a variety of ways.
  • B.Sc. in Computer Science
  • Experience using Elastic search, Kibana or Grafana.

Arctic Wolf provides continuous cybersecurity protection tailored to each organization. It uses a cloud-native platform paired with a dedicated concierge team to deliver around-the-clock monitoring and security operations (SOC) on a subscription basis. The platform integrates security functions to avoid tool sprawl and alert fatigue, while the concierge team works with clients to meet their specific needs. Clients pay for ongoing protection with 24x7 coverage, and Arctic Wolf offers tools like a Total Cost of Ownership Calculator to illustrate savings and ROI. This approach differentiates Arctic Wolf from competitors by combining a unified, cloud-based platform with a personalized delivery model that embeds security experts with each client. The goal is to improve clients’ security posture, reduce unnecessary security tool investments, and lower total costs while providing reliable, continuous monitoring.

Company Size

1,001-5,000

Company Stage

N/A

Total Funding

$899.2M

Headquarters

Eden Prairie, Minnesota

Founded

2012

Simplify Jobs

Simplify's Take

What believers are saying

  • Datalink partnership expands AI-led SOC to U.S. and Canada MSP customers since April 2026.
  • Chubb selects Arctic Wolf as preferred MDR for policyholders, boosting insurability.
  • Sevco Security acquisition adds Gartner Visionary exposure assessment to Aurora Platform.

What critics are saying

  • CrowdStrike erodes SMB base with superior Falcon endpoint detection in 12-24 months.
  • 250 sales layoffs delay AI iterations, losing talent to Rapid7 in 3-6 months.
  • SentinelOne's autonomous XDR captures mid-market, spiking Arctic Wolf churn in 6-12 months.

What makes Arctic Wolf unique

  • Aurora Superintelligence Platform processes 10 trillion events weekly with Swarm of Experts AI.
  • Concierge security team extends internal IT with 24/7 tailored threat response.
  • Open XDR architecture integrates 250+ tools for broad visibility without data limits.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Equity For All Employees

Diverse, equitable, & inclusive workplace

Remote Work Opportunities

Paid Parental Leave

Flexible Paid Time Off For All Employees

Professional Development

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
The Associated Press
Mar 23rd, 2026
Arctic Wolf launches world's largest commercial agentic SOC with AI-driven security operations

Arctic Wolf has launched the Aurora Agentic SOC, described as the world's largest commercial agentic security operations centre, shifting from human-led to AI-driven security operations. Built on the Aurora Superintelligence Platform, the system uses a three-tier "Swarm of Experts" model comprising oversight agents, authoritative agents and process agents. The turnkey solution addresses low AI adoption rates in cybersecurity, with only 30% of teams currently integrating AI security tools. Arctic Wolf claims the system resolves cases 15 times faster with three times higher-quality tickets and can be deployed in as little as 10 days. The Aurora Agentic SOC is available today as part of Arctic Wolf's Security Operations Bundles and Aurora Managed Endpoint Security. Existing customers will receive the new capabilities at no additional cost.

Yahoo Finance
Mar 23rd, 2026
Arctic Wolf launches Aurora Superintelligence Platform with Swarm of Experts AI framework

Arctic Wolf has launched the Aurora Superintelligence Platform, designed to address trust and reliability challenges in AI-powered cybersecurity. The platform uses a "Swarm of Experts" agentic framework that combines AI with human validation to ensure reliable performance. The system addresses industry concerns around AI hallucinations and model drift that have limited adoption, with Gartner estimating only 1–5% market penetration for AI SOC agents. Arctic Wolf's approach only deploys agents when they demonstrably outperform human-only workflows. The platform incorporates three key elements: the Swarm of Experts framework with hundreds of adaptive agents, a Security Operations Graph processing nine trillion telemetry events weekly, and validation from over 1,000 security analysts. Drawing on 14 years of security operations experience serving over 10,000 customers, the platform integrates real-world expertise whilst maintaining customer-specific business context.

IT Security News
Mar 17th, 2026
CTG unveils cyber resilience scoring dashboard for measurable risk reduction.

CTG unveils cyber resilience scoring dashboard for measurable risk reduction. 2026-03-17 17:03 Read the original article: Information security training Articles related to cyber risk quantification, cyber risk management, and cyber resilience. The post Inside the Updated AI Governance Suite Dashboard | Kovrr appeared first on Security Boulevard. This article has been indexed from Security BoulevardRead the original article: Inside the Updated AI Governance Suite Dashboard | Kovrr March 5, 2026 Arctic Wolf released the Arctic Wolf Cyber Resilience Assessment, a risk assessment tool designed to help businesses of almost any size advance their cyber resilience and improve insurability by effectively mapping their security posture against industry-standard frameworks. The release of Arctic Wolf Cyber Resilience Assessment expands Arctic Wolf's Security Journey... May 7, 2024 Barracuda Networks unveiled the BarracudaONE AI-powered cybersecurity platform. BarracudaONE maximizes threat protection and cyber resilience by unifying layered security defenses and providing deep, intelligent threat detection and response for managed service providers (MSPs), other channel partners and end users. BarracudaONE simplifies and strengthens security operations by unifying Barracuda's comprehensive portfolio... June 2, 2025

Yahoo Finance
Mar 16th, 2026
Arctic Wolf appoints Will May as chief revenue officer to drive global growth

Arctic Wolf, a global leader in security operations, has appointed Will May as Chief Revenue Officer. May will lead the company's global go-to-market organisation, overseeing sales and customer-facing teams. May brings over 15 years of go-to-market leadership experience across software and cybersecurity companies. He most recently served as Chief Revenue Officer at Pendo.io and previously held similar roles at ClickUp. He also held senior sales leadership positions at Zscaler and AppDynamics. The appointment comes as Arctic Wolf expands its security operations platform and global footprint, with growing industry adoption of AI and agentic AI. May will focus on building an AI-native revenue organisation whilst scaling the company globally and deepening customer relationships.

GlobeNewswire
Feb 23rd, 2026
Arctic Wolf acquires exposure assessment visionary Sevco Security

Arctic Wolf, a global leader in security operations, has acquired Sevco Security, an exposure assessment platform developer. Financial terms were not disclosed. Sevco was named a Visionary in the 2025 Gartner Magic Quadrant for Exposure Assessment Platforms. Sevco's cloud-native technology will integrate with Arctic Wolf's Aurora Platform, providing unified asset intelligence, vulnerability context and security control coverage. The acquisition aims to help organisations shift from reactive defence to proactive security by offering real-time visibility of assets and exposures across hybrid environments. The combined capabilities will complement Arctic Wolf Managed Risk, enabling customers to identify, prioritise and remediate security exposures more effectively. Gartner predicts that by 2027, organisations integrating exposure assessment data will experience 30% less unplanned downtime from exploited vulnerabilities.

INACTIVE