Staff Threat Researcher

Remote: 
Full Remote
Contract: 
Work from: 

Offer summary

Qualifications:

Solid background in cybercrime investigation and malware analysis., Expertise in malware analysis, reverse engineering, and unpacking using tools like IDA Pro and Ghidra., Strong understanding of endpoint security technologies and operating system internals., Proficient in threat intelligence frameworks and skilled in programming/scripting for automation..

Key responsabilities:

  • Lead threat intelligence initiatives to research and assess emerging cyber threats.
  • Perform in-depth technical threat analysis and develop high-fidelity detection logic.
  • Design and implement threat hunting strategies to discover malicious activity.
  • Collaborate with detection engineers and produce actionable intelligence reports for internal stakeholders.

SentinelOne logo
SentinelOne Large http://www.sentinelone.com
1001 - 5000 Employees
See all jobs

Job description

About Us

At SentinelOne, we’re redefining cybersecurity by pushing the limits of what’s possible—leveraging AI-powered, data-driven innovation to stay ahead of tomorrow’s threats.

From building industry-leading products to cultivating an exceptional company culture, our core values guide everything we do. We’re looking for passionate individuals who thrive in collaborative environments and are eager to drive impact. If you’re excited about solving complex challenges in bold, innovative ways, we’d love to connect with you.

 

What are we looking for?

We are seeking a highly motivated and skilled individual to join our team as a Staff Threat Researcher. The ideal new colleague should have a solid background in cybercrime investigation, and malware analysis. You will be responsible for conducting in-depth research and analysis of emerging and existing threats, provide actionable intelligence for detection, and will leverage your deep understanding of the tactics, techniques, and procedures used by ransomware operators and their ecosystem. 

What You’ll Do?
  • Lead threat intelligence initiatives to proactively research, analyze, and assess emerging cyber threats, including ransomware groups, financially motivated actors with a focus on developing detection strategies.
  • Perform in-depth technical threat analysis, including malware reverse engineering (static/dynamic), campaign tracking, and infrastructure profiling, to inform and drive detection logic in endpoint detection and response (EDR) platforms.
  • Develop high-fidelity detection logic (YARA, platform rules etc) based on actionable intelligence derived from malware capabilities, actor TTPs, and behavioral patterns observed in telemetry and forensic artifacts.
  • Design and implement threat hunting strategies to proactively discover malicious activity, unearth novel attack patterns, and surface IOCs  and BOIs across diverse environments.
  • Continuously curate and maintain a threat intelligence knowledge base, including actor profiles, toolsets, infrastructure usage, TTPs, and affiliations, with a special focus on tracking ransomware and their evolving ecosystems.
  • Monitor adversary infrastructure (C2s, exploit servers), and develop automated methods to fingerprint and track infrastructure reuse across campaigns.
  • Collaborate with detection engineers to align threat research with detection coverage gaps
  • Produce actionable intelligence reports and detection recommendations for internal stakeholders, including concise executive briefings and deep technical analysis for detection engineering and response teams.
  • Stay ahead of the curve on malware trends, evasive techniques, and novel TTPs, and map findings to threat models (e.g., MITRE ATT&CK, Diamond Model) to maintain contextual awareness and detection depth.
  • Mentor and guide detection engineers, promoting a culture of continuous learning, collaboration, and threat-informed defense.
What experience or knowledge should you bring?
  • Expertise in malware analysis (both static and dynamic), reverse engineering, unpacking, and deobfuscation using tools like IDA Pro, Ghidra, x64dbg, and behavioral sandboxes (Cuckoo, CAPE, etc.).
  • Strong understanding of endpoint security technologies, especially EDR platforms and the internal workings of how detection signals are generated and triaged.
  • Deep knowledge of operating system internals (Windows, Linux), including memory management, process/thread architecture, registry, and system calls. Familiarity with Extended Berkeley Packet Filter (eBPF) and container security is highly valued.
  • Proficient in threat intelligence frameworks and methodologies, including the Diamond Model, MITRE ATT&CK, Kill Chain, and mapping TTPs to coverage and detection gaps.
  • Strong data analysis and pattern recognition skills, able to sift through telemetry, logs, and artifacts to derive meaningful insights that drive detection hypotheses and logic.
  • Skilled in programming/scripting for automation, analysis, and detection logic generation (mostly Python)
  • Experience building and maintaining threat hunting playbooks, leveraging endpoint telemetry, behavior analytics, and threat intelligence to operationalize continuous threat detection.
  • Comprehensive understanding of threat actor behaviors, intrusion sets, and motivations and their tooling/ecosystem.
Nice-to-Have Skills and Qualifications:
  • Relevant certifications such as GIAC GREM, CREA, CMA, OSCE3, or RECA.
  • Experience with cloud threat detection and cloud-native telemetry (AWS, Azure, GCP).
  • Familiarity with CTI enrichment platforms and tooling, such as MISP, ThreatConnect, or commercial TIPs.
  • Practical experience in building detection pipelines, integrating threat intelligence with SIEM/EDR platforms.
  • Contributions to open-source tools, YARA rulesets, or CTI repositories.
  • Authored some blogs
What we offer you

Salary from 4000 EUR/month.
Yearly % bonus depending on the performance of the company, paid out in 2 installments.
*The final base salary component can be increased accordingly to individual skills and experience of the selected candidate.

On top of that you may look forward to:

  • Flexible working hours & Full remote within Slovakia; optional membership in Regus co-working spaces; in Czechia we also have offices in Prague or Brno
  • Generous employee stock plan in the form of RSUs (restricted stock units) not options; 4 years vesting with 1 year cliff and then quarterly
  • Meal Allowance (maximum value of the employer’s contribution per day: €4.29)
  • Wellbeing Allowance (€120/month)
  • Flexible Time Off (on top of the standard 5 weeks of vacation)
  • Flexible Paid Sick Days
  • Fully Paid Short Term Sick/Short Term Nursing Leave
  • Global gender-neutral Parental Leave (16 weeks, beyond the leave provided by the local laws) & Grandparent Leave
  • Volunteering paid day off & Additional paid Company holidays off (e.g. 4 days in 2022)
  • Pension insurance contribution
  • Premium Life Insurance covered by S1
  • Global Employee Assistance Program (confidential counseling related to both personal and work life matters), Wellness Coach:Mind Body Sleep app company access (sessions, audiobooks, classes, private coaching etc.)
  • High-end MacBook or Windows laptop, Home-office-setup gear & on top of that additional WFH Allowance
  • Udemy Business platform for Hard/Soft skills Training, internal mentoring 'MentorOne' & Support for your further educational activities/trainings
  • Above-standard referral bonus
  • Yearly bonus depending on the performance of the company
  • Optional company events for those who like to meet outside of work too - mostly in Czechia expensed as business trip (sport, BBQ, charity etc.)

SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

SentinelOne participates in the E-Verify Program for all U.S. based roles. 

Required profile

Experience

Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Collaboration
  • Communication
  • Problem Solving

Researcher Related jobs