CyberArk Logo

CyberArk

DFIR & Threat Hunting Researcher

Sorry, this job was removed at 02:13 p.m. (GMT) on Monday, Aug 18, 2025
Be an Early Applicant
In-Office
London, England
In-Office
London, England

Similar Jobs

40 Minutes Ago
Hybrid
Rugby, Warwickshire, England, GBR
Mid level
Mid level
Artificial Intelligence • Hardware • Information Technology • Security • Software • Cybersecurity • Big Data Analytics
As a Systems Engineer, you will support emergency response providers by installing, troubleshooting, and documenting hardware/software, while collaborating with business analysts to enhance the product.
Top Skills: Amazon Web ServicesApi DesignAzureMicrosoft ServerNoSQLSipSQLVoip
43 Minutes Ago
In-Office
London, Greater London, England, GBR
Expert/Leader
Expert/Leader
Information Technology • Software • Financial Services
The Machine Learning Researcher will conduct research and development in machine learning for options trading, owning the full lifecycle from design to deployment, and leveraging large datasets to create impactful models.
Top Skills: NumpyPythonPyTorch
46 Minutes Ago
Hybrid
London, Greater London, England, GBR
Senior level
Senior level
Software
The People Business Partner will support EMEA leadership in aligning talent strategies with business goals, drive organizational effectiveness, and enhance employee experience while fostering company culture.
Company Description

About CyberArk:
CyberArk (NASDAQ: CYBR), is the global leader in Identity Security. Centered on privileged access management, CyberArk provides the most comprehensive security offering for any identity – human or machine – across business applications, distributed workforces, hybrid cloud workloads and throughout the DevOps lifecycle. The world’s leading organizations trust CyberArk to help secure their most critical assets. To learn more about CyberArk, visit our CyberArk blogs or follow us on X, LinkedIn or Facebook.

Job Description

CyberArk, the global leader in Identity Security, is looking for a skilled and passionate Senior DFIR & Threat Hunting Researcher to join its Global Information Security Team. In this role, you will conduct digital forensics and threat-hunting activities across CyberArk's global network, endpoints, and cloud environments. You will also research and develop new methods and tools to enhance the detection and response capabilities of the CyberArk Information Security team.

Responsibilities:

Digital Forensics and Incident Response (DFIR):

  • Perform digital forensics analysis on various types of evidence, such as disk, memory, network, and cloud artifacts (AWS – advantage).
  • Support incident response efforts by providing technical expertise, containment, eradication, and recovery guidance.
  • Maintain and operate forensic tools and platforms, ensuring they are up-to-date and reliable.
  • Document and report on forensic findings and recommendations, following the established procedures and standards.

Threat Hunting:

  • Proactively hunt for malicious activity and indicators of compromise across CyberArk's network, endpoints, and cloud environments using various data sources and analytical techniques.
  • Develop and refine custom threat-hunting hypotheses, queries, and dashboards based on the latest threat intelligence and trends.
  • Collaborate with the SOC team to validate, escalate, and respond to identified threats.

Research and Development:

  • Research emerging threats, attack vectors, threat actors, APTs, security technologies and CyberArk products and share insights and best practices with the team and the broader security community.
  • Develop and improve tools, scripts, correlation alerts and automation to enhance the SOC team's DFIR and threat-hunting capabilities.

#LI-CB1

Qualifications

  • Proven (5+ years) experience in digital forensics and incident response, preferably in a tech company or a security consulting firm.
  • Hands-on experience with industry standard forensic tools and platforms.
  • Hands-on experience with threat hunting tools, query languages and platforms, such as ELK, Splunk, QRadar, KQL, SQL etc.
  • Strong knowledge of network protocols, operating systems, malware analysis, and cloud security.
  • Ability to automate tasks using a scripting language such as Python & JS.
  • Excellent communication and interpersonal skills.
  • Excellent proficiency in English, both written and verbal, is a must.
  • Curious and creative mindset, with a passion for learning and solving complex problems.
  • Ability to work independently and collaboratively in a fast-paced, dynamic environment and with a multi-region team.

Certifications (a plus):

· GCFE, GCFA, GNFA, GCTI, OSCP, or equivalent.

Additional Information

We are proud to foster a diverse and inclusive workplace, where every individual's unique background, perspective, and contribution is celebrated. We believe that by embracing diversity, we drive innovation and create a stronger, more united team. Inclusion is at the heart of who we are and how we succeed. All qualified applicants will receive consideration for employment without regard to race, colour, age, religion, sex, sexual orientation, gender identity, or disability. Upon conditional offer of employment, candidates are required to complete a comprehensive background check as per our internal policy. 

CyberArk is an equal opportunities employer. If you would like any special arrangements made for your interview, please inform the EMEA Talent Acquisition team upon your application so that we may take steps to accommodate your needs.

CyberArk London, England Office

One Pear Place, 152-158 Waterloo Road, , London, United Kingdom, SE1 8BT

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account