Senior Security Researcher
- Remote ()
- |4 years of exp
- |Full Time
Remote only
Not Available
About the job
Infrawatch is building the infrastructure intelligence layer for the public internet, giving security teams a continuously updated view of the infrastructure behind cyberattacks, fraud, scams, and online abuse.
We observe and process more than 23.5 billion primary-source internet events every day across IP addresses, domains, DNS, certificates, exposed services, and internet infrastructure.
This gives our research team the ability to find malicious infrastructure directly, track how it changes, and turn those observations into intelligence used by some of the world’s most advanced organisations.
At Infrawatch, you will work directly with internet-scale data and help discover what is happening across the public internet before it becomes obvious elsewhere.
This is a high-accountability environment where research is expected to lead somewhere. Findings become detections, datasets, product capabilities, customer intelligence, and published research. The work is challenging, expectations are clear, and researchers have significant freedom to follow important leads.
If you want to hunt adversaries, work with unusual datasets, and build new ways of finding malicious infrastructure at internet scale, this is the place to do it.
The Role
Infrawatch is looking for a Security Researcher focused on discovering, tracking, and understanding malicious infrastructure across the public internet.
You will use Infrawatch's visibility across internet infrastructure, proprietary primary-source telemetry, large-scale datasets, and internal research tooling to investigate cyber threats and identify infrastructure associated with malware, command-and-control frameworks, phishing, fraud, anonymisation services, abuse infrastructure, and emerging attacker tradecraft.
This role sits at the intersection of threat intelligence, internet measurement, security research, and data analysis.
You will investigate individual threats, but an important part of the role is turning research into repeatable detection. When you discover a new technique, technology, infrastructure pattern, or adversary behaviour, you should be thinking about how we can identify it systematically across the internet.
You will work closely with engineering and product to turn research into detection rules, datasets, platform capabilities, and intelligence that can be used by customers.
Location
This is a remote position, preferably within the UK or US, with occasional travel for team meetings, customers, conferences, and research events.
The Main Responsibilities
- Use large-scale internet datasets including DNS, certificates, service banners, HTTP responses, network metadata, exposed services, and other primary-source telemetry to identify and track malicious infrastructure.
- Research malware, command-and-control frameworks, phishing infrastructure, proxy and anonymisation networks, attacker tooling, exposed systems, and emerging adversary techniques.
- Develop repeatable methods for identifying malicious infrastructure rather than relying solely on individual indicators or one-off investigations.
- Build and maintain high-confidence detection rules and fingerprints that allow Infrawatch to identify technologies, infrastructure, and adversary activity across the public internet.
- Hunt across large datasets to identify relationships between IP addresses, domains, certificates, autonomous systems, hosting providers, technologies, and infrastructure behaviour.
- Investigate new threats and determine how their infrastructure can be discovered, classified, tracked, and monitored over time.
- Work with engineering to improve the datasets, tooling, enrichment, automation, and research capabilities available to the security research team.
- Use scripting and automation to accelerate research, enrichment, validation, clustering, and large-scale analysis.
- Turn research findings into useful intelligence for customers, including detections, datasets, investigations, technical analysis, and product capabilities.
- Produce clear technical research explaining what we found, how we found it, why it matters, and what defenders can do with the information.
- Continuously explore new data sources, research methods, and internet measurement techniques that can improve Infrawatch's visibility.
What We Look For in a Candidate
- Experience in security research, threat intelligence, threat hunting, malware research, internet measurement, network security, or a closely related field.
- Strong understanding of how malicious infrastructure is deployed and operated, including domains, DNS, hosting, certificates, proxies, command-and-control infrastructure, and internet-facing services.
- Ability to take a threat, tool, campaign, or infrastructure pattern and independently investigate how it can be identified across large datasets.
- Experience analysing technical indicators and infrastructure relationships rather than relying solely on finished intelligence reports or third-party feeds.
- Familiarity with attacker tactics, techniques, and procedures and how they manifest in network and internet infrastructure.
- Ability to work with large datasets and extract useful patterns from noisy or incomplete information.
- Scripting experience, preferably with Python, Go, or another language commonly used for security research and data analysis.
- Strong investigative instincts. You should be comfortable following weak signals, testing hypotheses, discarding bad leads, and continuing until you understand what the data is actually showing.
- Strong written communication and the ability to turn complex technical findings into clear intelligence for engineers, security teams, customers, and external audiences.
- A high standard of evidence. We care about research that can be reproduced, explained, and defended.
Particularly relevant experience may include:
- Malware infrastructure and command-and-control research.
- Passive or active DNS analysis.
- Internet-wide scanning or internet measurement.
- TLS certificate and certificate transparency research.
- Detection engineering and network fingerprinting.
- Phishing or fraud infrastructure research.
- Proxy, VPN, residential proxy, or anonymisation infrastructure.
- Botnets, loaders, information stealers, remote access tools, or commodity malware.
- Nation-state or advanced threat infrastructure tracking.
- Large-scale OSINT and infrastructure pivoting.
- Working with technologies such as ClickHouse, Elasticsearch, Kafka, SQL, notebooks, or large analytical datasets.
- Developing tooling that automates enrichment, clustering, fingerprinting, or threat hunting.
- Publishing original security research or contributing to public threat intelligence.
You do not need experience in every area above.
We care more about whether you can investigate difficult technical problems, recognise meaningful patterns in internet data, and turn research into something repeatable and useful.
How We Work
Infrawatch does not operate like a traditional threat intelligence team where researchers primarily consume third-party reporting and produce written summaries.
We collect the underlying internet data ourselves.
That means researchers can move from a hypothesis to querying internet-scale telemetry, identifying infrastructure, developing a detection method, validating it across historical and live data, and putting that capability into production.
Research and engineering work closely together. If you need a new dataset, enrichment, scanner capability, or analytical tool to answer an important question, you will be able to work directly with the people who can build it.
We expect researchers to be curious, technical, evidence-driven, and willing to challenge assumptions.
The goal is not to produce the largest number of indicators. It is to understand the infrastructure well enough that we can keep finding it.
Why Infrawatch?
Very few security research teams have direct access to this breadth of primary-source internet telemetry.
You will be able to investigate threats across billions of daily observations rather than being limited to individual incidents, customer environments, or third-party intelligence feeds.
Your research can directly become a new detection capability and immediately be applied across the public internet.
You will work on problems spanning malware infrastructure, phishing, fraud, internet abuse, anonymisation networks, exposed technologies, critical infrastructure, and emerging attacker tradecraft.
And because Infrawatch is still a small team, you will have significant freedom to shape what we research, how we research it, and the capabilities we build next.
Compensation
We offer a competitive salary plus meaningful equity.
Compensation will depend on experience, technical depth, and the level of ownership you are able to take.
About the company
Perks
Similar Jobs

