Senior Threat Researcher, FTR

🏢 Trend Micro · all Trend Micro jobs
📍 United States
📅 Posted 2026-08-03 · via Himalayas
🏷 THREAT-RESEARCH,Cybersecurity-Research,Threat-Intelligence,Red-Team-Operations,Security-Analysis,Senior-Threat-Analyst,Senior-Security-Researcher,Senior-Threat-Intelligence-Specialist,Senior-Threat-Intelligence-Subject-Matter-Expert
Apply on original site ↗

TrendAI™, the global AI security leader and enterprise business unit of Trend Micro , empowers organizations with full AI visibility and consolidated security that inspires confidence, drives innovation, and eliminates risk.

At TrendAI™, we’re always seeking exceptional talent; people who want to collaborate with the best and push boundaries together. Here, your work goes beyond building a career. You will help protect what matters and play a vital role in shaping a safer, more trustworthy AI-powered future.
AI Fearlessly.

TrendAI™, the global AI security leader and enterprise business unit of Trend Micro , empowers organizations with full AI visibility and consolidated security that inspires confidence, drives innovation, and eliminates risk.

At TrendAI™, we’re always seeking exceptional talent; people who want to collaborate with the best and push boundaries together. Here, your work goes beyond building a career. You will help protect what matters and play a vital role in shaping a safer, more trustworthy AI-powered future.

AI Fearlessly .
Position Summary

TrendAI's Forward Looking Threat Research team (FTR) is a global team of Senior Researchers tasked with "Scouting the Future of Threats" — looking at the next 1–3 years of likely future risk in security.
We research:

-
The cutting edge of cybercriminal techniques and business models today (Underground, Targeted Attacks, Threat Actor tracking)

-
How attackers actually get in, move, and stay hidden

-
What technologies are emerging now and in the near future, and how both attackers and defenders will adapt to them

We are looking for a Senior Threat Researcher who has stood on both sides of the intrusion — someone who has either broken into networks as part of a red team, or hunted and tracked the people who do it for real, and who understands the other discipline well enough to speak its language fluently.

Note that the primary goal of our research is not to hunt for vulnerabilities in isolation, but to demonstrate and showcase real-world business impact of attacker tradecraft, of cybercrime business models, and of the gaps between how defenders think attackers behave and how they actually behave. Findings feed directly into research publications, threat actor tracking, and product/mitigation proposals.
What You'll Do

-
Research and profile cyber threat actors: their tradecraft, infrastructure, motivations, and business models, with the rigor of someone who has actually tracked a campaign end to end

-
Translate hands-on offensive findings into defensive research: detection opportunities, hunting hypotheses, and mitigation guidance that a blue team can act on

-
Publish external-facing research (blogs, whitepapers, conference talks) that moves the industry's understanding forward. FTR researchers regularly present at BlackHat, FIRST, HITB, and RSA

-
Partner with Law Enforcement (Interpol, Europol, FBI, NCA, and others) where research surfaces actionable intelligence

-
Represent TrendAI at external conferences, as an attendee or speaker

-
Work cross-functionally with product and detection engineering teams to turn research into (product) ideas and mitigation proposals

What You'll Bring
Core experience (required):

-

6+ years of experience in at least one of the following, with meaningful working exposure to the other:

-
Offensive security / red teaming — adversary emulation, attack path development, breach-and-attack simulation, or offensive tooling development

-
Threat investigation / threat hunting , specifically involving tracking and profiling real-world cyber threat actors (APT, cybercrime, or both)

-
Demonstrated ability to think and operate on both sides of the intrusion lifecycle — you don't need to be equally deep in both, but you need to have done real work in both and be conversant enough to design research that crosses the line between them

-
A "hacker mentality": the ability to quickly identify security weaknesses in d

← All remote jobs