Staff Threat Researcher
hace 4 días
**About Us**:
At SentinelOne, we're redefining cybersecurity by pushing the limits of what's possible—leveraging AI-powered, data-driven innovation to stay ahead of tomorrow's threats.
From building industry-leading products to cultivating an exceptional company culture, our core values guide everything we do. We're looking for passionate individuals who thrive in collaborative environments and are eager to drive impact. If you're excited about solving complex challenges in bold, innovative ways, we'd love to connect with you.
**What are we looking for?**:
We are seeking a highly motivated and skilled individual to join our team as a Staff Threat (Intelligence) Researcher. The ideal new colleague should have a solid background in cybercrime investigation/threat research - incl. especially Linux and/or Cloud, and malware analysis. You will be responsible for conducting in-depth research and analysis of emerging and existing threats, provide actionable intelligence for detection, and will leverage your deep understanding of the tactics, techniques, and procedures used by ransomware operators and their ecosystem.
**What You'll Do?**:
- **Lead threat intelligence initiatives** to proactively research, analyze, and assess emerging cyber threats, including ransomware groups, financially motivated actors with a focus on developing detection strategies.
- **Perform in-depth technical threat analysis**, including malware reverse engineering (static/dynamic), campaign tracking, and infrastructure profiling, to inform and drive detection logic in endpoint detection and response (EDR) platforms.
- **Develop high-fidelity detection logic** (YARA, platform rules etc) based on actionable intelligence derived from malware capabilities, actor TTPs, and behavioral patterns observed in telemetry and forensic artifacts.
- **Design and implement threat hunting strategies** to proactively discover malicious activity, unearth novel attack patterns, and surface IOCs and BOIs across diverse environments.
- **Continuously curate and maintain a threat intelligence knowledge base**, including actor profiles, toolsets, infrastructure usage, TTPs, and affiliations, with a special focus on tracking ransomware and their evolving ecosystems.
- **Monitor adversary infrastructure** (C2s, exploit servers), and develop automated methods to fingerprint and track infrastructure reuse across campaigns.
- **Collaborate with detection engineers**to align threat research with detection coverage gaps
- **Produce actionable intelligence reports and detection recommendations** for internal stakeholders, including concise executive briefings and deep technical analysis for detection engineering and response teams.
- **Stay ahead of the curve** on malware trends, evasive techniques, and novel TTPs, and map findings to threat models (e.g., MITRE ATT&CK, Diamond Model) to maintain contextual awareness and detection depth.
- **Mentor and guide detection engineers**, promoting a culture of continuous learning, collaboration, and threat-informed defense.
**What experience or knowledge should you bring?**:
- **Expertise in malware analysis** (both static and dynamic), reverse engineering, unpacking, and deobfuscation using tools like IDA Pro, Ghidra, x64dbg, and behavioral sandboxes (Cuckoo, CAPE, etc.).
- **Strong understanding of endpoint security technologies**, especially EDR platforms and the internal workings of how detection signals are generated and triaged.
- **Deep knowledge of operating system internals** (Windows, Linux), including memory management, process/thread architecture, registry, and system calls. Familiarity with Extended Berkeley Packet Filter (eBPF) and container security is highly valued.
- **Knowledge of cloud threat landscape**, and threats and attacks targeting Linux, containers, and K8s.
- **Experience with cloud** security research/ cloud threat hunting or IR/ cloud pentesting or redteaming; and with cloud threat detection and cloud-native telemetry (AWS, Azure, GCP).
- **Proficient in threat intelligence frameworks and methodologies**, including the Diamond Model, MITRE ATT&CK, Kill Chain, and mapping TTPs to coverage and detection gaps.
- **Strong data analysis and pattern recognition skills**, able to sift through telemetry, logs, and artifacts to derive meaningful insights that drive detection hypotheses and logic.
- **Skilled in programming/scripting** for automation, analysis, and detection logic generation (mostly Python)
- **Experience building and maintaining threat hunting playbooks**, leveraging endpoint telemetry, behavior analytics, and threat intelligence to operationalize continuous threat detection.
- **Comprehensive understanding of threat actor behaviors**, intrusion sets, and motivations and their tooling/ecosystem.
**_Nice-to-Have Skills and Qualifications:_**:
- Relevant certifications such as **GIAC GREM, CREA, CMA, OSCE3, or RECA**.
- Familiarity with **CTI enrichment platforms and tooling**, such as
-
Threat Researcher
hace 2 días
Madrid, España Infoblox A tiempo completoIt’s an exciting time to be at Infoblox. Named a Top 25 Cyber Security Company by The Software Report and one of _Inc_. magazine’s Best Workplaces for 2020, we are leading the way to next-level DDI with our Secure Cloud-Managed Network Services, bringing next-level security, reliability, and automation to cloud and hybrid systems—all managed through a...
-
Sr. Threat Researcher
hace 6 días
Madrid, Madrid, España Proofpoint A tiempo completoAbout UsWe are the leader in human-centric cybersecurity. Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We're driven by a mission to stay ahead of bad actors and safeguard the digital world. Join us in our pursuit to defend data and protect people.How We WorkAt Proofpoint, you'll be part of a...
-
Cybersecurity Researcher
hace 1 semana
Madrid, España Acronis A tiempo completoCybersecurity Researcher (Threat Analysis and Detection Engineering)Join to apply for the Cybersecurity Researcher (Threat Analysis and Detection Engineering) role at AcronisAcronis is revolutionizing cyber protection—providing natively integrated, all-in-one solutions that monitor, control, and protect the data that businesses and lives depend on. We are...
-
Cybersecurity Researcher
hace 1 semana
Madrid, España Acronis A tiempo completoCybersecurity Researcher (Threat Analysis and Detection Engineering)Es posible que un gran número de candidatos se presenten a este puesto, así que asegúrese de enviar su CV y su solicitud lo antes posible.Join to apply for theCybersecurity Researcher (Threat Analysis and Detection Engineering)role atAcronisAcronis is revolutionizing cyber...
-
HRS2026/001 Investigador
hace 3 días
Madrid, España EURAXESS Czech Republic A tiempo completoOrganisation/Company UNIVERSIDAD POLITECNICA DE MADRID Department HRS4R Research Field Technology » Computer technology Researcher Profile First Stage Researcher (R1) Positions Bachelor Positions Country Spain Application Deadline 21 Jan 2026 - 23:00 (Europe/Madrid) Type of Contract Permanent Job Status Full-time Hours Per Week 37,5 Offer Starting Date 7...
-
HRS2026/001 Investigador
hace 4 días
Madrid, España EURAXESS Czech Republic A tiempo completoOrganisation/Company UNIVERSIDAD POLITECNICA DE MADRID Department HRS4R Research Field Technology » Computer technology Researcher Profile First Stage Researcher (R1) Positions Bachelor Positions Country Spain Application Deadline 21 Jan 2026 - 23:00 (Europe/Madrid) Type of Contract Permanent Job Status Full-time Hours Per Week 37,5 Offer Starting Date 7...
-
HRS2026/001 Investigador
hace 1 semana
Madrid, España EURAXESS Czech Republic A tiempo completoOrganisation/Company UNIVERSIDAD POLITECNICA DE MADRID Department HRS4R Research Field Technology » Computer technology Researcher Profile First Stage Researcher (R1) Positions Bachelor Positions Country Spain Application Deadline 21 Jan 2026 - 23:00 (Europe/Madrid) Type of Contract Permanent Job Status Full-time Hours Per Week 37,5 Offer Starting Date 7...
-
Sr. Threat Research Engineer
hace 2 semanas
Madrid, España Netskope A tiempo completo**About Netskope**: Today, there's more data and users outside the enterprise than inside, causing the network perimeter as we know it to dissolve. We realized a new perimeter was needed, one that is built in the cloud and follows and protects data wherever it goes, so we started Netskope to redefine Cloud, Network and Data Security. **About the...
-
madrid, España EURAXESS Ireland A tiempo completoOrganisation/Company BIOGIPUZKOA HEALTH RESEARCH INSTITUTE Research Field Biological sciences Researcher Profile First Stage Researcher (R1) Positions PhD Positions Application Deadline 25 Feb 2026 - 23:59 (Europe/Madrid) Country Spain Type of Contract Permanent Job Status Full-time Hours Per Week 35 Offer Starting Date 23 Jan 2026 Is the job funded through...
-
Madrid, España ActiveFence A tiempo completoA cybersecurity firm is seeking a freelancer for an OSINT/WEBINT Intelligence Researcher role. You'll conduct in-depth research to identify various online threats including child safety issues, hate speech, and organized crime. The ideal candidate has at least 2 years of experience in intelligence analysis, strong analytical skills, and is fluent in English....