Nebulock, Inc. Logo

Nebulock, Inc.

Lead Threat Researcher

Reposted 9 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Lead and build the threat research function: curate intelligence knowledge bases, conduct original research on threat actors and TTPs across endpoint, cloud, and IAM, prototype AI-assisted tooling, translate findings into hunt hypotheses and detection rules, and partner with product, engineering, and customers to prioritize detections and drive strategy.
The summary above was generated by AI
About Us

Nebulock is an agentic threat hunting platform that autonomously surfaces behaviors, not just IOCs, from various data sources. Nebulock acts like a teammate: a 24/7 AI threat hunter that investigates hypotheses, reasons through telemetry, and learns from an environment. Today, threat hunting is broken. Security teams spend weeks chasing alerts, writing detections by hand, and manually validating findings often just to confirm what their existing tools already flagged. Meanwhile, attackers exploit credentials, move laterally, and operate in silence. Nebulock flips the model. We continuously and autonomously hunt across endpoint, identity, and cloud telemetry identifying the subtle behavioral signals that point to credential misuse, lateral movement, insider threats, and post-access activity. Then we turn those hunts into hardened, behavior-based detections automatically.

Position Overview

We're hiring a Lead Threat Researcher to build the system that determines what actually matters for each specific customer. Your research, opinions, and the tooling you build will help determine what both our threat hunting agents and our internal threat hunters and detection engineers choose to prioritize. You will be the authoritative voice on what actually deserves attention versus what is noise. This role is ideal for someone who wants to build and redesign the threat research function in the age of agentic AI. While you are not expected to ship customer-facing production quality code, you must be excited to experiment and prototype in order to unblock yourself and inform what Software Engineering should build.

Set the Standard for Threat Research in the Age of Agentic AI

  • Design and curate a structured and contextual knowledge base (i.e. threat actor profiles, TTPs, attack patterns etc.) for our agents and internal threat hunters

  • Measure and prove that your opinionated view of the threat landscape improves outcomes for our customers

  • Be the authoritative voice on prioritization (i.e. Should we hunt this technique? Does this threat actor target our customers? Is this exploitable in their environments? etc.)

  • Cut through daily feeds and the headlines to identify what demands attention

  • Leverage AI tooling to build the intelligence layer that helps customers answer: "what matters to me and why"

Conduct and Share Original Threat Research

  • Track active threat campaigns and adversary TTPs across endpoint, cloud, and IAM

  • Conduct original research into threat actor TTPs, malware families, and emerging attack techniques across endpoint, cloud, and identity

  • Analyze adversary infrastructure, tooling, and behavioral patterns to surface novel detection opportunities

  • Translate threat intelligence into actionable hunt hypotheses and detection rules by mapping adversary behaviors to normalized telemetry

  • Account for real-world telemetry constraints and visibility gaps

  • Represent Nebulock externally via blog posts, conference talks, published research etc.

Drive Strategy and Cross-Functional Impact

  • Partner with threat hunters and detection engineers to inform priorities based on emerging threats relevant to customer environments

  • Maintain a continuous feedback loop between what adversaries are doing in the wild and what we build in response

  • Collaborate with product + engineering to drive the product roadmap

  • Engage with customers to deliver threat briefings, analysis, and advisories tailored to their environments

  • Determine which threat intelligence partnerships Nebulock should invest in (commercial CTI vendors, ISACs, OSINT communities etc.)

Qualifications
  • 7+ years in threat intelligence or threat research with exposure across multiple industries

  • Deep expertise in mapping threat actor TTPs to observable telemetry

  • Strong understanding of adversary tradecraft across endpoint, cloud, and IAM

  • Experience and excitement about using AI-assisted development tools to build lightweight tooling, automations, and prototypes

  • Proven ability to prototype, iterate, and ultimately build your own tooling

  • Demonstrated ability to distill complex topics into something actionable and understandable

  • Active participation in threat intelligence sharing communities

What We Offer
  • Competitive salary + equity (early-stage startup with significant upside)

  • Flexible remote work (US-based, hybrid option for Boston area)

  • Autonomy to build the threat research function from scratch

  • Low-ego and high-trust environment

Similar Jobs

2 Hours Ago
In-Office or Remote
212K-286K Annually
Expert/Leader
212K-286K Annually
Expert/Leader
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Lead Java software development for Advanced Ground Architecture: design, implement, review, and maintain cloud-based non-embedded software. Provide subsystem leadership, mentor engineers, guide architecture and systems engineering, ensure compliance with standards, and monitor cost and schedule performance.
Top Skills: AngularC++Ci/CdCloudCloud EnvironmentCompilersCSSDebuggersHTMLJavaLinkersLinuxPrimavera P6PythonReactRequirements Management ToolsScaled AgileSoftware Configuration ManagementWindows
2 Hours Ago
In-Office or Remote
99K-135K Annually
Senior level
99K-135K Annually
Senior level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Support export compliance for unmanned aerial systems: draft, submit, and manage ITAR/EAR licenses and commodity jurisdiction requests; classify technical data; manage license lifecycle and documentation; coordinate with stakeholders and provide licensing guidance as an empowered official.
Top Skills: ExcelMicrosoft TeamsOcr EaseSharepoint
2 Hours Ago
In-Office or Remote
30-42 Hourly
Mid level
30-42 Hourly
Mid level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Operate and maintain Insitu unmanned aircraft systems, plan and execute missions, collect/analyze payload and video data, perform pre/post-flight checks and maintenance, support customers in field deployments, and complete inventory and mission reporting. Deployable to remote/austere locations up to 70% travel.
Top Skills: Basic NetworkingIntegratorRq21ScaneagleUas

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account