Private cellular networks carry a threat surface most security teams never see: signaling attacks, protocol abuse, SIM and identity manipulation, and CVEs across the core and RAN stack. This role owns OneLayer's understanding of that threat surface and turns it into detection. You will track cellular security research and CVEs across the 3GPP stack, judge which threats are real in OT and IT private cellular environments, and translate them into detection logic that runs against OneLayer's data collection. Where feasible and safe, you will build a reproducible demo of the exploit so the detection can be proven, not asserted. This is not a survey role. You read the research, you decide what matters, you build the detection, and you show it works.
Track cellular security research, disclosures, and CVEs across the 3GPP stack (NAS, RRC, S1-MME, S5/S8, S6a, S11, GTP-C/U, Diameter, 5GC N1/N2/N4/N6, SIP/IMS) and assess real-world exploitability in private cellular deployments
Translate that research into detection logic built on the data OneLayer already collects, and specify new collection where a detection needs it
Build reproducible proof-of-concept demos of exploits and CVEs in a controlled lab to validate detections end to end
Define the telemetry, signatures, and behavioral indicators that separate a real attack from normal network behavior
Partner with product and platform engineering to move validated detections into the product
Requirements
Deep knowledge of cellular protocols and 4G/5G core architecture: EPC (S5/S8, S6a, S11, S1-MME) and 5GC (N1/N2/N4/N6) interfaces, GTP-C/U, Diameter/RADIUS, SIP/IMS, EPS-AKA/5G-AKA, and SIM provisioning chains
A security researcher's instinct: you understand how protocols are abused, not just how they are specified
Ability to read offensive security research and CVE write-ups and reason about detectability from network-observable data
Detection engineering fundamentals: signatures, anomaly detection, behavioral baselines, and keeping false positives out of an OT environment
Lab experience building and running PoCs (open-source cores/RAN such as Open5GS/srsRAN, packet capture, Python scripting)
Clear technical writing. Your research is only useful if others can act on it