Threat Research Engineer

BrazilPosted Aug 6, 2026

At Infoblox, every breakthrough begins with a bold “what if.”

What if your ideas could ignite global innovation?

What if your curiosity could redefine the future?

We invite you to step into the next exciting chapter of your career journey. Bring your creativity, drive, your daring spirit, and feel what it’s like to thrive on a team big enough to make an impact, yet small enough to make a difference. Our cloud-first networking and security solutions already protect 70% of the Fortune 500, and we’re looking for creative thinkers ready to push that influence even further. Join us and discover how far your bold “what if” can take the world, your community, and your career.

How we empower our people is extraordinary: we’re recognized as a Glassdoor Best Place to Work 2025, Great Place to Work-Certified in five countries, and honored by Cigna as a Healthy Workforce honors for three consecutive years; and what we build is world class: named CybersecAsia’s Best in Critical Infrastructure 2024 — clear evidence that when first-class technology meets empowered talent, remarkable careers take shape. So, what if the next big idea, and the next great career story, comes from you?

Become the force that turns every “what if” into “what’s next.”

In a world where you can be anything, Be Infoblox.

Threat Researcher II

We have an opportunity for a Threat Researcher II to join our Threat Intelligence team in Brazil, reporting to our Supervisor, Threat Intelligence. In this pivotal role, you will help generate the original DNS-centric threat intelligence that powers Infoblox Threat Defense, protecting customers from phishing, malware, brand abuse, and other emerging attacks worldwide. Collaborating closely with fellow threat researchers, data scientists, product teams, and our Axur external threat protection experts in Brazil, you will investigate advanced threat campaigns, design and refine detection algorithms, and leverage AI-assisted tooling to accelerate hunting, enrichment, and reporting.

Be a Contributor — What You’ll Do

  • Analyze large-scale DNS and network telemetry to identify malicious domains, IPs, and infrastructure tied to phishing, malware, C2, and fraud campaigns
  • Engineer and tune scripted detection logic and algorithms to automatically surface high-quality threat indicators at scale
  • Use Python, SQL, and big-data environments (such as Spark or Databricks) to prototype and iterate on threat hunting workflows
  • Leverage AI-powered tools (including Infoblox Dossier, Infoblox IQ for Threat Defense, and LLM-based assistants) to accelerate investigation, enrichment, and reporting
  • Correlate DNS-based indicators with OSINT, WHOIS, passive DNS, sandboxes, and Axur brand-abuse data to map attacker infrastructure and campaigns
  • Create, validate, and maintain high-fidelity indicators in Infoblox TIDE for consumption by Threat Defense and other enforcement platforms
  • Review and tune detections based on feedback from QA, product, and customer incidents, including campaigns targeting Brazil and Latin America
  • Draft clear threat intelligence reports, campaign briefs, and contribute to public-facing blogs, conference material, or GitHub indicator releases
  • Partner with engineering to productionize detection algorithms, contributing to code reviews and data-quality metrics
  • Collaborate across time zones with global researchers and Axur’s Brazilian threat operations team to disrupt attacker infrastructure earlier

Be Prepared — What You Bring

  • 5+ years of experience in threat research, threat hunting, SOC analysis, incident response, or malware analysis (E06 / Threat Hunting Specialist 3 level)
  • Hands-on experience analyzing network or DNS data to detect malicious activity such as phishing domains, DGAs, fast-flux, or C2 beacons
  • Proficiency in Python and SQL for data analysis and automation; familiarity with big-data or notebook environments (Spark, Databricks) is a plus
  • Working knowledge of the DNS protocol and how attackers abuse DNS for transport, evasion, and command-and-control
  • Experience with threat intelligence platforms and research tools (Dossier, VirusTotal, URLScan, passive DNS, WHOIS, sandboxes)
  • Practical experience using AI-assisted workflows (LLMs for summarization, hunting hypotheses, code/query generation) with sound verification judgment
  • Ability to write clear technical documentation in English; Portuguese and/or Spanish strongly preferred for regional research
  • Collaborative mindset with ability to work across distributed teams and mentor junior analysts
  • Bachelor’s degree in Computer Science, Engineering, Information Security, Data Science, or equivalent practical experience; relevant certifications (GIAC, OSCP, GREM) a plus

Be Successful — Your Path

First 90 Days: Immerse in our culture, connect with mentors (Blox Buddies), and map the systems and meet with key stakeholders that rely on your work. Discuss and create short/long term goals.

Six Months: 

  • Contribute detections and IOCs shipped in Infoblox RPZ feeds and Axur-originated protections, with measurable coverage against at least one active campaign affecting Brazil or Latin America
  • Independently run end-to-end investigations from initial DNS signal to infrastructure mapping and report drafting
  • Establish a regular collaboration rhythm with Axur’s Brazilian threat intelligence and takedown teams
  • Participate in code and logic reviews for new detection algorithms, contributing feedback on precision, recall, and adversary adaptation

One Year: 

  • Become a go-to subject-matter resource on at least one threat area (e.g., Brazilian banking malware, Portuguese-language phishing, or DNS-based C2 patterns)
  • Lead or co-author a significant internal or public research deliverable such as a blog, webinar, or in-depth campaign brief
  • Drive iterative improvements to at least one detection pipeline or research workflow, integrating AI-powered tools with rigorous validation
  • Mentor junior threat researchers globally, sharing best practices for DNS-layer hunting and safe, effective AI use

Belong — Your Community

Our culture thrives on inclusion, rewarding the bold ideas, curiosity, and creativity that move us forward. In a community where every voice counts, continuous learning is the norm. So, whether you code, create, sell, or care for customers, you’ll grow and belong here.

Ready to Be the Difference?

Infoblox is an Affirmative Action and Equal Opportunity Employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, national origin, genetic information, age, disability, veteran status, or any other legally protected basis 

#LI-Remote #LI-AC1

Want jobs like this matched to you?

SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.

Get started free