Logo
Karkidi

Security Research Engineer--Duo Security Job at Karkidi in San Jose

Karkidi, San Jose, CA, United States


Security Research Engineer--Duo Security

As a Security Research Engineer on the Duo AI & Security Research team, you will help keep our products on the leading edge of identity security. You will work with Data Scientists and Machine Learning Engineers to develop effective threat detection systems. You will contribute threat insights to improve our existing Duo Trust Monitor and Risk Based Authentication products, while working to identify and respond to threat actor campaigns affecting Duo customers. Your security expertise combined with a product-oriented approach will help Duo deliver best-in-class security outcomes.

Responsibilities include:

  • Serve as an internal authority on identity threats such as phishing, adversary-in-the-middle, and session hijacking attacks to aid in product development.
  • Actively hunt for identity threats in Duo customer telemetry and develop effective countermeasures.
  • Support detection engineers in designing logic to detect and remediate sophisticated identity threats, including development of AI models.
  • Establish, maintain, and monitor internal fixed intelligence repositories containing malicious IPs and device identifiers.
  • Coordinate bidirectional intelligence sharing with our security research partners in Cisco Talos, including publication of threat advisories and public blogs.
  • Keep abreast of current trends in the identity threat landscape.
  • Organize and participate in red teaming and threat emulation exercises to better understand adversarial techniques and evaluate product efficacy.

Minimum Experience for this role:

  • 6+ years professional experience in security research, threat intelligence analysis, cyber operations, or similar.
  • 4+ years querying and analyzing data using query languages like SQL.
  • 4+ years of scripting or software engineering experience with a common programming language, preferably Python.
  • Experience contributing to automated defensive systems through detection engineering or security product development.

Preferred Skills and Experience:

  • Investigation and response to identity and access threats, especially those affecting multi-factor authentication.
  • Contributions to a customer-facing defensive security or threat detection and response product.
  • Publication of research and intelligence reports such as public threat advisories.
  • Familiarity with identity security protocols such as SAML and WebAuthn.
  • Collaboration with data scientists and/or detection engineers.
  • Facilitation of red team exercises, penetration testing, or "Capture the Flag" competitions.
  • Participation in the development of machine learning and AI systems.

Why Cisco Secure:

We're global, we're adaptable, we're diverse, and our security portfolio is as extensive as it is groundbreaking. Join an enterprise security leader with a start-up culture, committed to driving innovation and giving you the opportunity to make an impact. We #InnovateToWin and we know we're better together, that's why we're dedicated to inclusivity, collaboration, and diversity in everything we do.

Cisco Systems, Inc., is a leading American multinational conglomerate specializing in digital communications technology. Headquartered in San Jose, California, the corporation engages in the development, manufacturing, and sale of networking hardware, software, telecommunications equipment, and various high-technology services and products.

#J-18808-Ljbffr