Threat Research Engineer

Infoblox
Remote

About The Position

At Infoblox, every breakthrough begins with a bold “what if.” What if your ideas could ignite global innovation? What if your curiosity could redefine the future? We invite you to step into the next exciting chapter of your career journey. Bring your creativity, drive, your daring spirit, and feel what it’s like to thrive on a team big enough to make an impact, yet small enough to make a difference. Our cloud-first networking and security solutions already protect 70% of the Fortune 500 , and we’re looking for creative thinkers ready to push that influence even further. Join us and discover how far your bold “what if” can take the world, your community, and your career. How we empower our people is extraordinary: we’re recognized as a Glassdoor Best Place to Work 2025, Great Place to Work-Certified in five countries, and honored by Cigna as a Healthy Workforce honors for three consecutive years; and what we build is world class: named C ybersecAsia’s Best in Critical Infrastructure 2024 — clear evidence that when first-class technology meets empowered talent, remarkable careers take shape. So, what if the next big idea, and the next great career story, comes from you? Become the force that turns every “what if” into “what’s next.” In a world where you can be anything, Be Infoblox. Threat Researcher II We have an opportunity for a Threat Researcher II to join our Threat Intelligence team in Brazil, reporting to our Supervisor, Threat Intelligence. In this pivotal role, you will help generate the original DNS-centric threat intelligence that powers Infoblox Threat Defense, protecting customers from phishing, malware, brand abuse, and other emerging attacks worldwide. Collaborating closely with fellow threat researchers, data scientists, product teams, and our Axur external threat protection experts in Brazil, you will investigate advanced threat campaigns, design and refine detection algorithms, and leverage AI-assisted tooling to accelerate hunting, enrichment, and reporting.

Requirements

  • 5+ years of experience in threat research, threat hunting, SOC analysis, incident response, or malware analysis (E06 / Threat Hunting Specialist 3 level)
  • Hands-on experience analyzing network or DNS data to detect malicious activity such as phishing domains, DGAs, fast-flux, or C2 beacons
  • Proficiency in Python and SQL for data analysis and automation; familiarity with big-data or notebook environments (Spark, Databricks) is a plus
  • Working knowledge of the DNS protocol and how attackers abuse DNS for transport, evasion, and command-and-control
  • Experience with threat intelligence platforms and research tools (Dossier, VirusTotal, URLScan, passive DNS, WHOIS, sandboxes)
  • Practical experience using AI-assisted workflows (LLMs for summarization, hunting hypotheses, code/query generation) with sound verification judgment
  • Ability to write clear technical documentation in English; Portuguese and/or Spanish strongly preferred for regional research
  • Collaborative mindset with ability to work across distributed teams and mentor junior analysts
  • Bachelor’s degree in Computer Science, Engineering, Information Security, Data Science, or equivalent practical experience; relevant certifications (GIAC, OSCP, GREM) a plus

Responsibilities

  • Analyze large-scale DNS and network telemetry to identify malicious domains, IPs, and infrastructure tied to phishing, malware, C2, and fraud campaigns
  • Engineer and tune scripted detection logic and algorithms to automatically surface high-quality threat indicators at scale
  • Use Python, SQL, and big-data environments (such as Spark or Databricks) to prototype and iterate on threat hunting workflows
  • Leverage AI-powered tools (including Infoblox Dossier, Infoblox IQ for Threat Defense, and LLM-based assistants) to accelerate investigation, enrichment, and reporting
  • Correlate DNS-based indicators with OSINT, WHOIS, passive DNS, sandboxes, and Axur brand-abuse data to map attacker infrastructure and campaigns
  • Create, validate, and maintain high-fidelity indicators in Infoblox TIDE for consumption by Threat Defense and other enforcement platforms
  • Review and tune detections based on feedback from QA, product, and customer incidents, including campaigns targeting Brazil and Latin America
  • Draft clear threat intelligence reports, campaign briefs, and contribute to public-facing blogs, conference material, or GitHub indicator releases
  • Partner with engineering to productionize detection algorithms, contributing to code reviews and data-quality metrics
  • Collaborate across time zones with global researchers and Axur’s Brazilian threat operations team to disrupt attacker infrastructure earlier

Benefits

  • Glassdoor Best Place to Work 2025
  • Great Place to Work-Certified in five countries
  • Cigna as a Healthy Workforce honors for three consecutive years
  • CybersecAsia’s Best in Critical Infrastructure 2024
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service