Security Developer
Arctic Wolf
Software Engineering
Cork, Ireland
Posted on Aug 11, 2025
Security Developer,
At Arctic Wolf, we're not just navigating the cybersecurity landscape - we're redefining it. Our global team of dedicated Pack members is driving innovation and setting new industry standards every day. Our impact speaks for itself: we've earned recognition on the Forbes Cloud 100, CNBC Disruptor 50, Fortune Future 50, and Fortune Cyber 60 lists, and we recently took home the 2024 CRN Products of the Year award. We’re proud to be named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services and earning a Customers' Choice distinction from Gartner Peer Insights. Our Aurora Platform also received CRN’s Products of the Year award in the inaugural Security Operations Platform category. Join a company that’s not only leading, but also shaping, the future of security operations.
Our mission is simple: End Cyber Risk. We’re looking for a Security Developer to be a part of making this happen.
A Security Developer has a clear history of successful contribution to
professional security development projects. They are driven, curious, and
results oriented. They can manage competing priorities as they relate to
improving existing our existing codebase of detections and constantly
challenge the status quo.
About You
You’re a talented security developer who loves building things and cares deeply about code quality and reliability while optimizing performance. You
enjoy coordinating with distributed cross-functional teams. You are constantly
adapting to emerging technologies, trends, and best practices. You will build
productive internal/external working relationships to resolve mutual problems
by collaborating on procedures or transactions, with a focus on providing standard professional advice and creating initial reports/analyses for review by experienced team professionals.
2+ years of professional experience as a Security Developer
Experience consists of projects contributing to either Python or YAML
OS Specific Telemetry: Windows Security/Sysmon logs, Linux, MacOS
Experience with applying the MITRE ATT&CK framework to intelligence products and associated depth of analysis for each TTP and threat actor represented in this body of knowledge
Windows PowerShell Monitoring
Understanding of threat protection/detection tooling/stacks: SIEM,XDR/EDR
EDR detections/signatures
Sigma and Yara Rules
SQL Knowledge, Databricks is a plus.
Experience using Git repositories (GitHub, Git Bash, GitLab)
Experience using Virtual Machines (VMware workstation)
Development of anomaly and behavioral based detections
Tuning and optimization of detections for all the above
Professional certifications in Security and/or Cloud are required (i.e.
CISSP, GNFA, GCFA, GCFE, GREM).
Experience consists of leading a team of 3 or more Security Developers while contributing code independently
Experience leading Agile development teams, preferably with formal
Agile training
Resourceful self-starter with a positive, can-do attitude
Nice to Have
A clear history of technical influence (public conference talks, papers, etc)
A clear history of learning and skills development. Regularly helps
security developers develop their skills in a variety of ways.
B.Sc . in Computer Science
Experience using Elastic search, Kibana or Grafana.
About the Role
You’ll be working as a Security Developer on our Aurora Endpoint Defense
Team, responsible for ensuring quality and scale of our detection base and
presenting actionable detections to our Security Services teams and
customers.
About the Role and Responsibilities:
Analyze, research, and develop new detection rules for Aurora Focus,applying MITRE ATT&CK framework.
Understand the product and how Security Services delivers the service.
Convert investigations performed by our Threat Teams:TRI\AR\CTI\TIO\TRO into new content (detection/telemetry rules).
Customer Escalation (BFD), collaborate with S2 teams on investigations regarding emerging threats, to generate new detection rules.
Fine Tune/Calibration: determining true threats or false positives, and providing solutions, like exclusions, logic change or decreasingseverity.
Writing clean, efficient, and reusable code in Python.
Conducting code reviews and providing constructive feedback to ensure code quality and maintainability.
Ability to effectively manage multiple tasks simultaneously; coordinating and ensuring scheduled goals are met.
Maintain documentation up to date: new tool or process.
Run regression and end-2-end testing
Push production releases, and notification emails.
Collaborating with cross-functional teams to gather requirements and implement detections.
Participate in Purple Teaming exercises as Blue Teamer.
Generate metrics over Databricks Dashboard.
Deliver regular threat briefing presentations to internal & external stakeholders on topics ranging from threat actor campaign activity, novel TTPs, and emerging malware or exploits
Utilize best practices for threat research and documentation and deliver high-quality detection rules.
Optimizing application performance and ensuring scalability.
Participate in the full software development life cycle, building well-designed, testable, efficient, secure code.
Continuously learning and adopting best practices for code quality, software development methodologies, and programming principles to enhance coding skills and stay updated with industry advancements.