Senior Threat Researcher
Hunt, cluster, and name adversaries across the DarkWatch firehose. You'll turn sensor telemetry into published threat reports and the signatures that power RuneFeed.
We're hiring across threat intelligence, detection, SOC, platform, and AI/ML — in Foster City, Austin, London, Singapore, and remote. Come work on the data that the rest of the industry only estimates.
We're a sensor-first company, which means engineers and researchers sit close to the raw truth of what's happening on the wire. We optimize for people who want to ship, to be proven wrong fast, and to never confuse a pretty dashboard for a real one.
Work from anywhere in your region, or from one of our offices in Foster City, Austin, London, or Singapore.
A rotation that lets engineers spend a quarter embedded with the threat-intel team, publishing under the NorseStar byline.
Meaningful ownership for every full-time employee, with an extended exercise window if you leave.
Annual budget for training and travel — including a seat in the SANS SEC590 course our range powers.
Premium medical, dental, and vision for you and your dependents across all four regions.
Short paths from idea to production. If your change improves the map, it ships this week — not next quarter.
Don't see your exact title? We're talent-dense and always early — reach out anyway.
Hunt, cluster, and name adversaries across the DarkWatch firehose. You'll turn sensor telemetry into published threat reports and the signatures that power RuneFeed.
Write and tune the detections that flag AI-driven and agentic attack campaigns at planet scale. Strong detection-as-code and data-pipeline instincts required.
Triage, escalate, and run point on live incidents on the NorseStar network during APAC hours. You'll be the first human eyes on a lot of novel attacker behavior.
Push Valkyrie AI forward: model the fingerprints of LLM-orchestrated attacks, and build the classifiers that separate machine-driven campaigns from human ones.
Own the Bifrost ingestion fleet end to end. Day one you'll be in our CI — experience with our Jenkins at build.norsestarsecurity.com and our Kafka + ClickHouse pipelines is a strong plus. Comfort operating services that cannot go down is non-negotiable.
Support EMEA customers and research with timely analysis of regional campaigns. You'll work the Yggdrasil graph to pivot from one indicator to a full actor profile.
Be the technical owner of our largest accounts — integrating RuneFeed into customer SIEM/SOAR stacks and making sure DarkWatch earns its place on the SOC wall.
Design the surfaces people stare at during an incident. You'll own the DarkWatch map experience and make dense, real-time data legible under pressure.
We hire for trajectory, not just checklists. Tell us what you'd want to work on across the NorseStar network.
Send an intro ▸