Senior Threat Researcher – Behavioral Protection
TLDR
Contribute to the security posture of millions by developing behavioral protection strategies and analyzing malware behaviors aligned with emerging attack techniques.
-
Analyze malware behaviors aligned with MITRE ATT&CK TTPs (and beyond), covering the full attack lifecycle, including initial access vectors, execution techniques, payload delivery—with a strong focus on in-memory techniques, fileless malware, and evasive behaviors.
-
Research and identify behavioral techniques employed by novel and sophisticated Advanced Persistent Threats (APTs) and translate these insights into effective behavioral protection rules to enhance prevention capabilities.
-
Drive protection coverage for zero-day malware and novel attack techniques.
-
Work independently with minimal supervision while managing priority protection tasks.
-
Review and provide actionable feedback on detection logic and code developed by fellow researchers.
-
Collaborate with the team to define clear protection priorities and deliver updates to customers in a timely manner.
-
Produce quality threat analysis reports for both internal and external audience
-
Proven hands-on experience in Windows based malware analysis using both static and dynamic analysis tools such as using IDAPro and Windbg.
-
Deep understanding of behavioral techniques, memory injection methods, persistence mechanisms, and evasion tactics.
-
Ability to write robust, high-quality behavioral protection rules.
-
Demonstrated programming experience, preferably Python, Lua.
-
Experience working in a fast-paced threat research or security operations environment.
-
Strong communication skills and the ability to provide technical mentorship to peers.
-
Proactive, self-driven mindset with the ability to lead in critical incident or zero-day response scenarios.
Benefits
Wellbeing Webinars
Monthly wellbeing webinars and training to support employee health and wellbeing.
Remote-Friendly
Sophos operates a remote-first working model, making remote work the primary option for most employees. However, some roles may necessitate a hybrid approach.
Sophos builds advanced security solutions designed to protect against cyberattacks, delivering comprehensive services like Managed Detection and Response (MDR) and endpoint, network, and email security. Targeting organizations across the globe, Sophos serves over 600,000 clients, utilizing the expertise of their combined technologies following the acquisition of Secureworks. Their unique offerings interoperate through the Sophos Central platform, fortified by real-time threat intelligence from their dedicated threat teams.
- Founded
- Founded 1985
- Employees
- 500+ employees
- Industry
- Professional Services