Jobs
Required Skills
Threat Detection
SIEM
Cloud Security
Log Analysis
Incident Response
Senior Threat Researcher II
Sumo Logic Threat Labs is a team of security experts responsible for developing and applying cyber threat intelligence, technology, hunting, and tradecraft to research and develop threat detections for Sumo Logic Cloud SIEM customers. Threat Labs is by design a fast-paced, demanding, and mission-focused team. Sumo Logic is in search of an experienced and visionary Senior Threat Researcher II for Threat Labs.
Threat Labs is looking for a senior-level threat researcher to join us in defending multiple organizations and technologies, by researching and creating detection content for Sumo Logic. This individual must love data (logs), and understand the role modern SIEM plays in organizations today; additionally, they must understand the importance of applying practitioner experience in helping customers do the job they need to do with SIEM. Threat Labs research includes exploration and exploitation of various cloud technologies, to create high quality practical detections. We’re looking for someone who can build out, test, and help us push the envelope on research driven detections.
Responsibilities
-
Research, Develop, and Test detection rules within lab infrastructure
-
Work with product management to identify focus of research and development campaigns
-
Maintain and expand threat research lab infrastructure
-
Provide practitioner feedback to engineering and product management regarding features and roadmap
-
Research industry trends for detection opportunities
-
Contribute to the community through blogs, conference talks, open source projects etc.
-
Align with Threat Detection Engineering on content development efforts and deployment
Requirements
-
8+ years of cybersecurity experience
-
Ideally a combination of the following:
-
Senior/Principal SOC Analyst
-
Purple Team and/or hunting
-
Incident response
-
Experience sourcing threat detections from research to deployment
-
Knowledgeable of multiple technology stacks and willingness to learn new technologies
-
Experience working in at least one public cloud (AWS, Azure, GCP)
-
Experience analyzing cloud infrastructure log telemetry
-
Contributed cybersecurity blogs or linked In posts, and conference talks
Desirable
-
Experience in customer facing technical role (consulting, IT help desk/remote support)
-
Offensive cybersecurity tool experience (Atomic Red Team, Sliver, Cobalt Strike etc)
-
Scripting experience (Python, PowerShell, etc)
-
Experience with Security Orchestration, Automation, and Response (SOAR) technology
-
Established social media presence in the cybersecurity industry/community (Twitter and the like)
-
Experience working within the cybersecurity vendor industry, with an understanding of product management and providing feedback into the process
About Us
Sumo Logic, Inc. helps make the digital world secure, fast, and reliable by unifying critical security and operational data through its Intelligent Operations Platform. Built to address the increasing complexity of modern cybersecurity and cloud operations challenges, we empower digital teams to move from reaction to readiness—combining agentic AI-powered SIEM and log analytics into a single platform to detect, investigate, and resolve modern challenges. Customers around the world rely on Sumo Logic for trusted insights to protect against security threats, ensure reliability, and gain powerful insights into their digital environments. For more information, visit www.sumologic.com.
Sumo Logic Privacy Policy. Employees will be responsible for complying with applicable federal privacy laws and regulations, as well as organizational policies related to data protection.
The expected annual base salary range for this position is $141,000 - $165,000. Compensation varies based on a variety of factors which include (but aren’t limited to) role level, skills and competencies, qualifications, knowledge, location, and experience. In addition to base pay, certain roles are eligible to participate in our bonus or commission plans, as well as our benefits offerings.
Must be authorized to work in the United States at time of hire and for duration of employment. At this time, we are not able to offer nonimmigrant visa sponsorship for this position.
Total Views
1
Apply Clicks
0
Mock Applicants
0
Scraps
0
Similar Jobs

AI Applied Scientist - PhD Intern, Next-Gen Agentic and Multi-Modal Home Exploration Experience
Zillow · Remote-USA

Tech App Scientist I
PerkinElmer · Sweden - Remote (Field Based)

Research Scientist - Patient and Provider Insights - Remote
Thermo Fisher · Remote, Maryland, USA

Research Scientist – VLM Generalist
Stability AI · Remote

PhD Research Intern, AI for Climate and Weather Simulation 2026
NVIDIA · UK, Remote
About Sumo Logic

Sumo Logic
PublicSumo Logic, Inc. is a cloud-based data analytics company, focusing on cybersecurity, security analytics and observability. It provides log management and analytics services based on artificial intelligence.
501-1,000
Employees
Redwood City
Headquarters
Reviews
4.0
1 reviews
Work Life Balance
3.0
Compensation
3.0
Culture
3.0
Career
3.0
Management
3.0
50%
Recommend to a Friend
Salary Ranges
2 data points
Junior/L3
Intern
Junior/L3 · Software Engineer
0 reports
$61,656
total / year
Base
-
Stock
-
Bonus
-
$52,410
$70,902
Interview Experience
4 interviews
Difficulty
3.0
/ 5
Duration
21-35 weeks
Interview Process
1
Application Review
2
Recruiter Screen
3
Technical Phone Screen
4
Onsite/Virtual Interviews
5
Offer
Common Questions
Coding/Algorithm
Technical Knowledge
Behavioral/STAR
Past Experience
News & Buzz
Sumo logic be like
·
6w ago
·
270
·
44
Sumo Logic named in the 2025 Gartner Critical Capabilities for Security Information and Event Management (SIEM) - iTnews
Source: iTnews
News
·
11w ago
Logically forced to discontinue their private LTD due to AppSumo?
Hey everyone, I came across a support message (attached) from Logically’s support team stating that *direct* LTD purchases made outside of AppSumo were removed because of “aligning with AppSumo policies.” I’m trying to understand whether there’s any truth to this explanation. It doesn’t sound like
·
14w ago
·
12
·
14
Sumo Logic Windows Collector registration blocked
We started using a new service that uses a Sumo Logic SIEM. While trying to install the Sumo Logic Windows Collector (SumoCollector.exe), we provide a token during the installation that's used to register the client. The install fails every time because the Palo firewall is blocking the registration
·
17w ago
·
6
·
7