Talent Apply
Log in
All jobs
EA

Cyber Security Research Engineer

Everforth Apex
Charllotte, NC / Dallas, TX / Minneapolis, MN / Chandler, AZ / Des Moines. IA, Raleigh, NC
Hybrid

About this role

Job Description

Cyber Security Research Engineer Phishing, Threat Analytics & Incident Response Location Charllotte, NC / Dallas, TX / Minneapolis, MN / Chandler, AZ / Des Moines. IA, Raleigh, NC Job Summary The Cyber Security Research Engineer is responsible for the research, analysis, detection, disruption, and mitigation of phishing threats and advanced cyber attacks targeting employees, customers, and enterprise systems. This role serves as a key contributor within Threat Analytics, Cyber Threat Intelligence, Incident Response, and Security Operations functions. The ideal candidate will possess strong expertise in phishing detection, threat hunting, security analytics, incident response, digital forensics, and adversarial analysis. This individual will leverage enterprise security tools, develop detection logic, investigate cyber threats, and provide actionable recommendations that improve the organization's security posture. This role requires a highly analytical and investigative mindset with the ability to think like an adversary, identify emerging attack techniques, and develop scalable solutions to detect and mitigate future threats. Key Responsibilities Phishing Detection & Threat Analytics Play a key role in phishing disruption efforts impacting customers, employees, and the company brand. Develop and enhance detection logic, processes, and procedures used to identify phishing campaigns and threat actor activity. Review, analyze, and correlate security logs from multiple data sources. Create and maintain detection content including: Regular Expressions YARA Rules Threat Detection Logic Security Analytics Content Identify indicators of compromise (IOCs), malicious domains, phishing infrastructure, suspicious URLs, and threat actor patterns. Support cyber threat intelligence and threat hunting initiatives. Leverage large-scale security analytics and threat intelligence techniques to identify, investigate, and disrupt cyber threats. Develop cybersecurity reporting, threat metrics, and operational dashboards supporting security leadership. Incident Response & Digital Forensics Lead or participate in computer security incident response activities for moderately complex security events. Conduct technical investigations involving: Phishing Incidents Malware Activity Credential Theft Account Compromise Insider Threat Activity Perform post-incident digital forensics to identify attack vectors, root cause, scope, and remediation requirements. Analyze endpoint, network, email, identity, and security telemetry to support investigations. Document investigative findings and provide recommendations for future prevention. Collaborate with security operations, engineering, risk, and threat intelligence teams to improve response capabilities. Threat Hunting & Offensive Security Research Utilize offensive security methodologies and adversarial techniques to improve detection and response capabilities. Apply attacker-focused thinking to identify emerging threats and develop hunting strategies. Research threat actor tactics, techniques, and procedures (TTPs). Support vulnerability analysis, cyber threat investigations, and security research initiatives. Conduct analysis involving: Exploitation Techniques Vulnerability Research Security Assessments Adversary Emulation Threat Simulation Activities Develop proof-of-concept methodologies and custom techniques to assess security controls and improve threat detection capabilities. Security Monitoring & Detection Engineering Utilize enterprise security platforms to investigate and respond to security events, including: SIEM Platforms IDS/IPS Technologies Endpoint Security Solutions Email Security Gateways Web Security Gateways Security Detection and Mitigation Devices Develop automated detection capabilities, security analytics, YARA rules, and alerting logic. Improve phishing detection and threat monitoring through security automation and enhanced detection engineering. Identify detection gaps and recommend improvements to monitoring capabilities. Support integration and optimization of enterprise security tools and monitoring technologies. Security Risk Assessment & Security Engineering Perform security risk assessments and technical reviews to ensure compliance with corporate security standards and best practices. Identify security vulnerabilities, control gaps, and areas of elevated risk. Evaluate remediation alternatives and recommend long-term mitigation strategies. Provide security consulting and guidance to internal business and technology teams. Support enterprise security engineering programs involving: Application Security Vulnerability Management Threat Modeling Security Assessments Security Control Validation Security Monitoring Assist with design, testing, implementation, and maintenance of security solutions across networking, cloud, authentication, email, internet, application, and endpoint environments. AI Security & Emerging Threat Research Research emerging threats involving: Generative AI Large Language Models (LLMs) AI-Assisted Phishing AI-Enabled Social Engineering Support security analytics initiatives involving AI-driven threat detection and security assessment automation. Assist in evaluating AI-related security risks and developing mitigation strategies. Contribute to security research involving prompt engineering abuse, AI threat activity, and emerging cyberattack techniques. Support AI security testing and threat intelligence initiatives designed to improve organizational cyber defense capabilities. Cloud Security & Security Operations Support cloud security monitoring, investigation, and threat response activities. Assist with monitoring and threat detection across cloud platforms and hybrid enterprise environments. Support DevSecOps and modern security operations initiatives that enhance visibility, automation, and incident response effectiveness. Participate in security engineering efforts focused on platform automation and security tool integration. Collaboration & Leadership Collaborate with peers, security engineers, analysts, threat intelligence teams, and managers to resolve issues and achieve objectives. Provide guidance and mentorship to junior security engineers and analysts. Communicate complex technical findings to both technical and non-technical stakeholders. Support a fast-paced, high-demand environment while balancing multiple priorities. Drive continuous improvement of phishing detection, threat analytics, incident response, and security monitoring capabilities. Required Qualifications 4+ years of Cyber Security Research experience or equivalent demonstrated through work experience, military experience, education, or training. Advanced Information Security technical skills. Experience detecting, investigating, and disrupting phishing attacks targeting employees, customers, or enterprise brands. Experience creating and maintaining: Regular Expressions YARA Rules Detection Logic Threat Analytics Content Experience reviewing and correlating security logs from multiple security platforms. Experience supporting security investigations and incident response activities. Hands-on experience with: SIEM Platforms IDS/IPS Technologies Endpoint Security Solutions Email Security Gateways Web Security Gateways Security Detection Technologies Experience with host and network log analysis supporting incident response and threat hunting. Strong analytical, investigative, and problem-solving skills. Ability to manage complex security issues and develop long-term solutions. Preferred Qualifications Threat Analytics, Detection Engineering & Emerging Threat Research Experience leveraging security analytics, large-scale data analysis, and threat intelligence techniques to identify and disrupt cyber threats. Experience developing cybersecurity reporting, threat intelligence metrics, and operational security dashboards. Experience supporting: Threat Hunting Cyber Threat Intelligence Incident Response Digital Forensics Security Monitoring Detection Engineering Experience developing automated detection capabilities, security analytics, YARA rules, and security automation workflows. Experience integrating and optimizing enterprise security tools to improve phishing and threat detection effectiveness. Experience supporting security operations within large enterprise environments. Familiarity with AI security research, AI-driven threat detection, security analytics, and AI-related threat investigations. Offensive Security & Investigation Experience Knowledge of: Offensive Security Methodologies Penetration Testing Vulnerability Research Adversary Emulation Exploitation Techniques Red Team Methodologies Experience utilizing adversarial thinking during investigations, threat hunting, and incident response activities. Experience supporting phishing analysis, email investigations, malicious domain analysis, and cybercrime investigations. Cloud & Security Engineering Experience supporting cloud security monitoring and incident response activities. Experience with security engineering, security tool integration

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →