πCzech Republic
Staff Threat Researcher

SentinelOne
πRemote - Spain
Please let SentinelOne know you found this job on JobsCollider. Thanks! π
Summary
Join SentinelOne as a Staff Threat (Intelligence) Researcher and lead threat intelligence initiatives, performing in-depth technical threat analysis, developing detection logic, and designing threat hunting strategies. You will curate a threat intelligence knowledge base, monitor adversary infrastructure, collaborate with detection engineers, and produce intelligence reports. The role requires expertise in malware analysis, endpoint security, operating system internals, and cloud security. Strong data analysis and scripting skills are essential. This is a 100% remote role based in Spain, offering flexible working hours and various benefits.
Requirements
- Expertise in malware analysis (both static and dynamic), reverse engineering, unpacking, and deobfuscation using tools like IDA Pro, Ghidra, x64dbg, and behavioral sandboxes (Cuckoo, CAPE, etc.)
- Strong understanding of endpoint security technologies , especially EDR platforms and the internal workings of how detection signals are generated and triaged
- Deep knowledge of operating system internals (Windows, Linux), including memory management, process/thread architecture, registry, and system calls. Familiarity with Extended Berkeley Packet Filter (eBPF) and container security is highly valued
- Knowledge of cloud threat landscape , and threats and attacks targeting Linux, containers, and K8s
- Experience with cloud security research/ cloud threat hunting or IR/ cloud pentesting or redteaming; and with cloud threat detection and cloud-native telemetry (AWS, Azure, GCP)
- Proficient in threat intelligence frameworks and methodologies , including the Diamond Model, MITRE ATT&CK, Kill Chain, and mapping TTPs to coverage and detection gaps
- Strong data analysis and pattern recognition skills , able to sift through telemetry, logs, and artifacts to derive meaningful insights that drive detection hypotheses and logic
- Skilled in programming/scripting for automation, analysis, and detection logic generation (mostly Python)
- Experience building and maintaining threat hunting playbooks , leveraging endpoint telemetry, behavior analytics, and threat intelligence to operationalize continuous threat detection
- Comprehensive understanding of threat actor behaviors , intrusion sets, and motivations and their tooling/ecosystem
Responsibilities
- Lead threat intelligence initiatives to proactively research, analyze, and assess emerging cyber threats, including ransomware groups, financially motivated actors with a focus on developing detection strategies
- Perform in-depth technical threat analysis , including malware reverse engineering (static/dynamic), campaign tracking, and infrastructure profiling, to inform and drive detection logic in endpoint detection and response (EDR) platforms
- Develop high-fidelity detection logic (YARA, platform rules etc) based on actionable intelligence derived from malware capabilities, actor TTPs, and behavioral patterns observed in telemetry and forensic artifacts
- Design and implement threat hunting strategies to proactively discover malicious activity, unearth novel attack patterns, and surface IOCs and BOIs across diverse environments
- Continuously curate and maintain a threat intelligence knowledge base , including actor profiles, toolsets, infrastructure usage, TTPs, and affiliations, with a special focus on tracking ransomware and their evolving ecosystems
- Monitor adversary infrastructure (C2s, exploit servers), and develop automated methods to fingerprint and track infrastructure reuse across campaigns
- Collaborate with detection engineers to align threat research with detection coverage gaps
- Produce actionable intelligence reports and detection recommendations for internal stakeholders, including concise executive briefings and deep technical analysis for detection engineering and response teams
- Stay ahead of the curve on malware trends, evasive techniques, and novel TTPs, and map findings to threat models (e.g., MITRE ATT&CK, Diamond Model) to maintain contextual awareness and detection depth
- Mentor and guide detection engineers , promoting a culture of continuous learning, collaboration, and threat-informed defense
Preferred Qualifications
- Relevant certifications such as GIAC GREM, CREA, CMA, OSCE3, or RECA
- Familiarity with CTI enrichment platforms and tooling , such as MISP, ThreatConnect, or commercial TIPs
- Practical experience in building detection pipelines , integrating threat intelligence with SIEM/EDR platforms
- Contributions to open-source tools, YARA rulesets, or CTI repositories
- Authored some blogs
Benefits
- Flexible working hours, this is a 100% remote role based within Spain ; we provide optional membership in major coworking chains Currently for this role in Spain we are able to consider only candidates that are already eligible to work in the EU at the time of applying
- Optionally for those willing to relocate to the Czech Republic relocation assistance is available for any candidates that are already eligible to work in the EU at the time of applying
- Generous employee stock plan in the form of grant of RSUs (restricted stock units), not options; 4 years vesting with 1 year cliff and then quarterly, stock refresh yearly
- Yearly bonus depending on the performance of the company, paid out in 2 installments
- 30 Days of Paid Annual Leave
- Flexible Paid Sick Days
- Pension insurance contribution
- Premium Life Insurance covered by S1
- Premium Medical & Dental Insurance covered by S1
- Meal, Transport & Homeoffice allowance of total 440 EUR/month
- Global gender-neutral Parental Leave (16 weeks, beyond the leave provided by the local laws) & Grandparent Leave
- Volunteering paid day off & Additional paid Company holidays off (e.g. 4 days in 2022)
- Global Employee Assistance Program (confidential counseling related to both personal and work life matters)
- Udemy Business platform for Hard/Soft skills Training & Support for your further educational activities/trainings
- Above-standard referral bonus
- & Aditional country-specific benefits to Spain
Share this job:
Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.
Similar Remote Jobs
πCzech Republic
πCzech Republic
π°$66k
πSlovakia
πPoland
πItaly
πIsrael
π°$100k-$113k
πUnited States
π°$130k-$150k
πWorldwide


