At Infoblox, every breakthrough begins with a bold “what if.”
What if your ideas could ignite global innovation?
What if your curiosity could redefine the future?
We invite you to step into the next exciting chapter of your career journey. Bring your creativity, drive, your daring spirit, and feel what it’s like to thrive on a team big enough to make an impact, yet small enough to make a difference. Our cloud-first networking and security solutions already protect 70% of the Fortune 500, and we’re looking for creative thinkers ready to push that influence even further. Join us and discover how far your bold “what if” can take the world, your community, and your career.
How we empower our people is extraordinary: we’re recognized as a Glassdoor Best Place to Work 2025, Great Place to Work-Certified in five countries, and honored by Cigna as a Healthy Workforce honors for three consecutive years; and what we build is world class: named CybersecAsia’s Best in Critical Infrastructure 2024 — clear evidence that when first-class technology meets empowered talent, remarkable careers take shape. So, what if the next big idea, and the next great career story, comes from you?
Become the force that turns every “what if” into “what’s next.”
In a world where you can be anything, Be Infoblox.
Threat Researcher
We have an opportunity for a Threat Researcher II to join our Threat Intelligence team in Brazil, reporting to our Supervisor, Threat Intelligence. In this pivotal role, you will help generate the original DNS-centric threat intelligence that powers Infoblox Threat Defense, protecting customers from phishing, malware, brand abuse, and other emerging attacks worldwide. Collaborating closely with fellow threat researchers, data scientists, product teams, and our Axur external threat protection experts in Brazil, you will investigate advanced threat campaigns, design and refine detection algorithms, and leverage AI-assisted tooling to accelerate hunting, enrichment, and reporting.
Be a Contributor — What You’ll Do
- Run end-to-end cyber threat investigations on the Axur platform, from initial request through information gathering, item analysis, and final intelligence report — across the team's core categories: brand phishing, leaked credentials, and threat-actor frau
- Investigate Brazilian and LATAM fraud schemes including direct interaction with threat actors when the case requires human judgment (engagement, negotiation, and evidence collection)
- Hunt for artifacts across the dark web, deep web, Telegram channels, and underground forums, correlating findings with the specific target brand, client, or campaign
- Enrich IOCs (URLs, domains, IPs, hashes) with OSINT and threat intel sources such as VirusTotal, URLScan, WHOIS, passive DNS, Certificate Transparency logs, sandboxes, and Abuse.ch community feeds
- Map phishing and fraud infrastructure — connecting a single URL or ticket to the broader campaign, shared hosting, and operator behind it
- Conduct OSINT investigations on people and entities, Building relationship graphs from open-source seeds
- Write clear, assertive intelligence reports (PT-BR / EN / ES) — executive summary first, every finding tied to evidence, correct TLP classification, and recommendations grounded in the specific modus operandi
- Query the internal data bases to contextualize cases, quantify exposure, and surface patterns across clients and campaigns
Be Prepared — What You Bring
- 3+ years in threat intelligence, threat hunting, fraud analysis, SOC, incident response, or a related cybersecurity function
- Hands-on experience investigating phishing, brand abuse, credential leaks, or online fraud — ideally in the Brazilian / LATAM threat landscape
- Practical dark web and OSINT research skills: navigating forums, Telegram, marketplaces, and paste sites, and knowing how to pivot from a single artifact to full infrastructure
- Comfort analyzing and enriching IOCs with tools like VirusTotal, URLScan, WHOIS, passive DNS, Certificate Transparency, and Abuse.ch
- Strong written communication — able to produce assertive, evidence-backed intelligence reports
- Sound judgment for threat-actor interaction and sensitive-data handling, with a clear sense of operational and ethical boundaries
- Collaborative mindset and the ability to work within a shared investigation queue with defined SLAs and quality standards
- Bachelor's degree in Information Security, Computer Science, Data Science, or equivalent practical experience; certifications such as GIAC, OSCP, or GREM are a plus
Be Successful — Your Path
First 90 Days:
- Immerse yourself in the team's culture and connect with your mentors; get familiar with the Axur platform, the investigation lifecycle, and the clients and stakeholders who rely on your work
- Learn the team's investigation tracks, category definitions, tooling, and report quality standards, and align on short- and long-term goals with your leader
- Independently close initial investigations end-to-end, meeting SLA and quality gates
Six Months:
- Own investigations across all core categories, from initial signal through infrastructure mapping, dark web hunting, and report delivery
- Handle threat-actor fraud cases with confidence, including briefing and executing controlled actor interactions when required
- Build a steady rhythm with the brand protection, threat hunting, and takedown teams, contributing to detection and non-detection feedback
- Participate in report and methodology reviews, giving feedback on evidence quality, assertiveness, and investigative rigor
One Year:
- Become a trusted reference in at least one threat area — such as Brazilian banking fraud, Portuguese-language phishing, or large-scale credential exposure
- Take on high-complexity investigations with autonomy
- Contribute to a meaningful research deliverable — an internal threat brief, a client-facing campaign report, or a public-facing piece
- Help improve at least one investigation workflow or automation (including responsible use of AI-powered tools) and support the development of newer analysts
Belong — Your Community
Our culture thrives on inclusion, rewarding the bold ideas, curiosity, and creativity that move us forward. In a community where every voice counts, continuous learning is the norm. So, whether you code, create, sell, or care for customers, you’ll grow and belong here.
Ready to Be the Difference?
Infoblox is an Affirmative Action and Equal Opportunity Employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, national origin, genetic information, age, disability, veteran status, or any other legally protected basis
#LI-Remote #LI-AC1