About the Role
About The Role
As an EM Content & Integrations Developer on Arctic Wolf’s Aurora Exposure Management team, you get the opportunity to work as both a cybersecurity researcher and a Detections/Vulnerability developer. You’ll identify areas to improve the platform’s threat and vulnerability and configuration risk detection capabilities. Your overarching goal is to improve security posture for Arctic Wolf’s clients. This role works cross-functionally with Product Management, Security Services, and various other specialists to continuously improve the coverage and efficacy of their Exposure Management portfolio and solutions.
What You’ll Be Doing
- Work with team members to continuously improve coverage, efficiency and deliver customer-facing and internal services.
- Participate in the full software development lifecycle.
- Well versed in writing Plugins or Integration with Public APIs from the enterprise vendors to establish push and pull based data sharing to enhance the coverage portfolio. MUST
- Build well-designed, testable, efficient, secure vulnerability and misconfiguration detection code in the following areas: MUST
- Classic Endpoint Vulnerability and Config Management:
- Host based vulnerabilities (OVAL based)
- Network-based vulnerability tests (NVTs)
- Integration with Third Party APIs / Vendor feeds
- Configuration Benchmark automations development (i.e. CIS) GOOD TO HAVE
- Pipeline hardening checks and policy development.
- Cloud Config and Posture Management:
- Development of security policy in cloud service providers
- Assist in operational teams to resolve unexpected results, receive feedback and improve detection efficacy.
- Leverage AI-powered tools (e.g., code assistants, AI-augmented debugging, and automated testing) as a core part of your development workflow using them to accelerate delivery, improve code quality, and explore solutions faster.
What We Are Looking For
- 2-4 Yrs Experience in at least one backend language (any of Go, Python, Rust preferred) MUST
- A full understanding/application of secure development practices. MUST
- Experience with AWS, Docker, Kubernetes, IaC an asset MUST
- Security minded practitioners experienced in operational or security engineering roles with an emphasis in vulnerability and misconfiguration detection tooling.
- Full understanding and use of DevOps methods and practices
- Understanding and ability to work with test-driven development.
- Fluency with AI-assisted development: you've made AI tools a natural extension of how you work, know where they help and where they fall short, and prior experience in adopting them effectively.
Bonus Considerations For
- Experience with 3rd Party Vulnerability Management tools (Qualys, Nessus, Rapid7, OpenVAS)
- Experience with Cloud-based configuration and Security Posture Management tools (Azure Security Centre, AWS Security Hub, Sonrai, Cloudsploit, Prisma Cloud)
- A background working with open-source vulnerability and pen-testing platforms such as Nmap, OpenVAS, Burp, or Metasploit
- IT Deployment backgrounds in particular leveraging deployment automation tools such as Salt or Ansible
Requirements
Backend language experience
2-4 years of experience in at least one backend language, preferably Go, Python, or Rust.
Secure development practices
A full understanding and application of secure development practices is essential.
Cloud technologies
Experience with AWS, Docker, Kubernetes, and Infrastructure as Code (IaC) is a must.
DevOps methods
A full understanding and use of DevOps methods and practices is required.
Nice to Have
Experience with third-party vulnerability management tools like Qualys or Nessus is a plus.
Familiarity with cloud-based configuration and security posture management tools is beneficial.
Experience with open-source vulnerability and pen-testing platforms such as Nmap or Metasploit is advantageous.
Benefits
Collaborative culture
Arctic Wolf offers a culture of sharing, allowing teams to present their work department-wide.
Annual Hackathon
The company holds a department-wide Hackathon once a year for cross-team collaboration.