Lead threat hunting operations against emergent threat activity involving platform misuse — to determine impact and drive resolution
Design and implement monitoring solutions to detect anomalies and potential abuse across external-facing services, APIs, and authentication surfaces
Lead technical aspects of incident response, including attack vector analysis, countermeasure implementation, and post-incident review
Develop automation and purpose-built tooling to streamline detection, mitigation, and reporting workflows
Instrument event-driven tooling to drive hunting efficiency and proactive prevention of evolving TTPs
Conduct regular security assessments and testing simulations targeting external attack surfaces and abuse vectors
Advocate for and drive product security enhancements across the Falcon platform, influencing engineering teams to build abuse resistance into the product
Implement and refine logging strategies to enhance visibility into potential abuse scenarios across cloud-native infrastructure
Contribute to roadmap and strategic planning for abuse prevention, balancing proactive and reactive capabilities
Support follow-the-sun operational coverage as part of a globally distributed team
Requirements
Motivated self-starter with 7+ years of experience in a cybersecurity engineering or threat intelligence environment, with a significant focus on threat hunting, attack mitigation, and tooling
Proficiency in security automation and tool development
Practical experience with cloud computing platform security services — particularly as they relate to infrastructure protection, identity and access management, and continuous monitoring
Deep familiarity with abuse-relevant attack patterns including credential stuffing, account takeover, API abuse, trial fraud, and adversarial misuse of security tooling
Ability to identify when external-facing services are exceeding baselines and correlate deviations with potential attack indicators
Comprehensive understanding of TTPs employed by threat actors and the evolving threat landscape, including nation-state and eCrime actors
Passionate about taking initiative to identify and develop enrichments and enhanced visibility
Enthusiasm for collaboration across functional teams — including Product & Engineering — to drive platform-wide abuse resistance
Tech Stack
Cloud
Cyber Security
Benefits
Market leader in compensation and equity awards
Comprehensive physical and mental wellness programs
Competitive vacation and holidays for recharge
Paid parental and adoption leaves
Professional development opportunities for all employees regardless of level or role
Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections