6 months ago
Responsibilities
- Develop countermeasures for advanced threats using research and intelligence from the Counter Threat Unit.
- Analyze endpoint behavior and logs to design detections from multi-source telemetry.
- Monitor and refine detection rules to improve alert signal-to-noise ratios.
- Research and implement alert handling for new device ingestions.
- Use internal tooling to distinguish native from standard integrations for detection accuracy.
- Collaborate on internal tools, automation, and detection infrastructure.
- Serve as a subject matter expert for Product Management, Marketing, and Labs Research.
Requirements
- Strong cybersecurity research skills and the ability to learn emerging technologies quickly.
- Hands-on experience with PowerShell, Bash, Python, and Python data science libraries such as NumPy, Pandas, and Matplotlib.
- Knowledge of CI/CD pipelines, testing frameworks, and automation principles.
- Experience analyzing firewall, proxy, and security-infrastructure logs to identify anomalies.
- Familiarity with event logs, traffic-pattern anomalies, and threat-hunting methodologies.
- Strong understanding of endpoint detection, Linux/Unix and Windows internals, vulnerability identification, and workflow automation.
- Forensic analysis of memory and disk images is a plus.
- Malware analysis, static and dynamic techniques, and reverse engineering of IA32/64 and ARM binaries are a plus.
- Experience with event correlation and incident reconstruction using log data is a plus.
- Network traffic analysis skills for identifying anomalous or malicious traits are a plus.
- Knowledge of database querying, systems architecture, and process automation is nice to have.
Benefits
- Remote-first working model, with hybrid work possible for some roles.
- Legal authorization to work in the posted jurisdiction is required without employer sponsorship.
- Employee-led diversity and inclusion networks.
- Annual charity, fundraising, and volunteer days.
- Global sustainability initiatives.
- Global fitness and trivia competitions.
- Global wellbeing days and monthly wellbeing webinars and training.
About Sophos
Sophos, a global cybersecurity leader, defends more than 625,000 organizations worldwide with Sophos Fusion, the industry's first and most complete AI-native cybersecurity defense system: a single, connected architecture where every control point operates as one. Powered by agentic AI and elite human expertise, Sophos detects, investigates, and neutralizes threats before they become business-disrupting events. Working alongside a global ecosystem of managed service providers, resellers, and technology partners, Sophos compounds intelligence from every threat encountered and every environment defended to make every customer's defense stronger than the last. More information is available at www.sophos.com.
