Sumo Logic
Staff Threat Research Engineer
Remote, USA · Staff+
No sponsorship$162k-$190kDetected 7 days ago
PythonPowerShellAWSGCPAzureMachine LearningAgentic AICybersecuritySIEMSOARDetection EngineeringIncident ResponseResearchLeadershipCollaboration
About the role
- We're looking for a staff‑level threat researcher who thrives at the intersection of data and adversary tradecraft.
- In this role, you'll use your practitioner experience to uncover attacker behaviors, test them in realistic environments, and turn those insights into detection content that directly improves customer outcomes.
- You're a seasoned security professional who's evolved from responding to incidents to preventing them.
Responsibilities
- Research, develop, and test threat detection logic in a lab environment, validating against real‑world attacker behaviors and ensuring technical alignment with Sumo Logic SIEM capabilities.
- Collaborate with product management and fellow Threat Labs engineers to scope and prioritize detection campaigns.
- Maintain and expand Threat Labs' research lab infrastructure.
- Provide practitioner feedback to engineering and product management to inform feature design and roadmap decisions.
- Conduct and lead both applied and original threat research, transforming intelligence, telemetry, and investigation into actionable detection logic for the Sumo Logic SIEM.
- Collaborate closely within Threat Labs to design, build, and refine detection content and validation pipelines that raise the bar for product and customer detection quality.
- Drive innovation in detection methodologies, including research activities such as malware analysis, infrastructure tracking, or honeypot operations, to discover new attacker behaviors.
Requirements
- 12+ years of cybersecurity experience that includes a mix of:
- Demonstrated ability to progress threat research into actionable detections and incident response outcomes.
- Broad knowledge of multiple technology stacks and a strong curiosity to learn new platforms.
- Deep experience with multiple major public clouds (AWS, Azure, or GCP), and familiarity with analyzing cloud‑native logs and telemetry.
- Proven history of thought leadership through blogs, LinkedIn articles, or conference presentations.
- Background in the cybersecurity vendor space, with experience providing expert feedback to product and engineering teams.
- Must be authorized to work in the United States at the time of hire and for the duration of employment.
Compensation
- In addition to base pay, certain roles are eligible to participate in our bonus or commission plans, as well as our benefits offerings.
Benefits
- Contribute to Threat Labs' long‑term vision of a research‑driven, continuously evolving detection ecosystem built on practitioner insight and technical depth.
Company info
- Sumo Logic, Inc. helps make the digital world secure, fast, and reliable by unifying critical security and operational data through its Intelligent Operations Platform. Built to address the increasing complexity of modern cybersecurity and cloud operations challenges, we empower digital teams to move from reaction to readiness-combining agentic AI-powered SIEM and log analytics into a single platform to detect, investigate, and resolve modern challenges. Customers around the world rely on Sumo Logic for trusted insights to protect against security threats, ensure reliability, and gain powerful insights into their digital environments. For more information, visit www.sumologic.com.
- The expected annual base salary range for this position is $162,000 - $190,000. Compensation varies based on a variety of factors which include (but aren't limited to) role level, skills and competencies, qualifications, knowledge, location, and experience. In addition to base pay, certain roles are eligible to participate in our bonus or commission plans, as well as our benefits offerings.
- Must be authorized to work in the United States at the time of hire and for the duration of employment. At this time, we are not able to offer new non-immigrant visa sponsorship or OPT hiring for this position.
- Sumo Logic, Inc. helps make the digital world secure, fast, and reliable by unifying critical security and operational data through its Intelligent Operations Platform.
- Built to address the increasing complexity of modern cybersecurity and cloud operations challenges, we empower digital teams to move from reaction to readiness-combining agentic AI-powered SIEM and log analytics into a single platform to detect, investigate, and resolve modern challenges.
- Customers around the world rely on Sumo Logic for trusted insights to protect against security threats, ensure reliability, and gain powerful insights into their digital environments.
- For more information, visit www.sumologic.com.
- Employees will be responsible for complying with applicable federal privacy laws and regulations, as well as organizational policies related to data protection.
- The expected annual base salary range for this position is $162,000 - $190,000.
- Compensation varies based on a variety of factors which include (but aren't limited to) role level, skills and competencies, qualifications, knowledge, location, and experience.
- In addition to base pay, certain roles are eligible to participate in our bonus or commission plans, as well as our benefits offerings.
- At this time, we are not able to offer new non-immigrant visa sponsorship or OPT hiring for this position.
- Threat Labs' mission is to keep our customers safe from cybersecurity attacks.
Visa & Work Authorization
- Must be authorized to work in the United States at the time of hire and for the duration of employment.
Apply directly at Sumo Logic →Create a free account for alerts like thisView Sumo Logic immigration profile
This listing is sourced directly from Sumo Logic's careers page and normalized into a canonical job model.