Security Researcher

Remote
CompanyReco
LocationUS (Remote)
CategorySecurity
DepartmentR&D
Seniority-
WorkplaceRemote
Posted2026-07-06
Viacomeet

Description

Reco is a fast-growing SaaS security company that helps organizations secure their SaaS and AI environments by detecting identity-based threats and risky configurations.

We are looking for a Threat Detection Engineer to analyze large-scale SaaS security data, investigate incidents, and develop advanced threat detection strategies.

You will work closely with security researchers and customers to identify emerging threats and improve detection capabilities across SaaS environments.

  • A background of at least 5 years in cybersecurity, preferably in SOC, SIEM, Threat Intelligence, or Cloud Security
  • Experience with SaaS security challenges, such as shadow IT, OAuth risks, IDP misconfigurations, and excessive permissions.
  • Hands-on experience with security data analysis, including large-scale log processing, anomaly detection, and behavioral analytics.
  • Proficiency in SQL (e.g., ClickHouse) for querying security events and correlating threat indicators.
  • Strong understanding of identity-based attacks, insider threats, and SOC detection methodologies.
  • Familiarity with SIEM and XDR solutions (e.g., Splunk, Sentinel, Chronicle) and their role in modern detection engineering.
  • Strong problem-solving and analytical skills to triage security incidents and optimize detection rules.

Advantages:

  • Familiarity with SaaS security best practices, including least-privilege access, OAuth governance, and SSPM.
  • Knowledge of SaaS security frameworks (e.g., SSPM, CASB).
  • Experience with IDP security (Okta, Azure AD, Google IAM) and detecting identity-related SaaS threats.
  • Hands-on experience with Threat Hunting and / or Detection engineering in SaaS environments.
  • Understanding of SaaS API security and experience analyzing integrations with third-party applications.