Talent.com
Esta oferta de trabajo no está disponible en tu país.
Staff Threat Researcher

Staff Threat Researcher

SentinelOnebilbao, España
Hace 20 días
Descripción del trabajo

Join to apply for the Staff Threat Researcher role at SentinelOne

2 days ago Be among the first 25 applicants

Join to apply for the Staff Threat Researcher role at SentinelOne

About Us

At SentinelOne, we’re redefining cybersecurity by pushing the limits of what’s possible—leveraging AI-powered, data-driven innovation to stay ahead of tomorrow’s threats.

About Us

At SentinelOne, we’re redefining cybersecurity by pushing the limits of what’s possible—leveraging AI-powered, data-driven innovation to stay ahead of tomorrow’s threats.

From building industry-leading products to cultivating an exceptional company culture, our core values guide everything we do. We’re looking for passionate individuals who thrive in collaborative environments and are eager to drive impact. If you’re excited about solving complex challenges in bold, innovative ways, we’d love to connect with you.

What are we looking for?

We are seeking a highly motivated and skilled individual to join our team as a Staff Threat (Intelligence) Researcher. The ideal new colleague should have a solid background in cybercrime investigation / threat research - incl. especially Linux and / or Cloud, and malware analysis. You will be responsible for conducting in-depth research and analysis of emerging and existing threats, provide actionable intelligence for detection, and will leverage your deep understanding of the tactics, techniques, and procedures used by ransomware operators and their ecosystem.

What You’ll Do?

  • Lead threat intelligence initiatives to proactively research, analyze, and assess emerging cyber threats, including ransomware groups, financially motivated actors with a focus on developing detection strategies.
  • Perform in-depth technical threat analysis, including malware reverse engineering (static / dynamic), campaign tracking, and infrastructure profiling, to inform and drive detection logic in endpoint detection and response (EDR) platforms.
  • Develop high-fidelity detection logic (YARA, platform rules etc) based on actionable intelligence derived from malware capabilities, actor TTPs, and behavioral patterns observed in telemetry and forensic artifacts.
  • Design and implement threat hunting strategies to proactively discover malicious activity, unearth novel attack patterns, and surface IOCs and BOIs across diverse environments.
  • Continuously curate and maintain a threat intelligence knowledge base, including actor profiles, toolsets, infrastructure usage, TTPs, and affiliations, with a special focus on tracking ransomware and their evolving ecosystems.
  • Monitor adversary infrastructure (C2s, exploit servers), and develop automated methods to fingerprint and track infrastructure reuse across campaigns.
  • Collaborate with detection engineers to align threat research with detection coverage gaps
  • Produce actionable intelligence reports and detection recommendations for internal stakeholders, including concise executive briefings and deep technical analysis for detection engineering and response teams.
  • Stay ahead of the curve on malware trends, evasive techniques, and novel TTPs, and map findings to threat models (e.g., MITRE ATT&CK, Diamond Model) to maintain contextual awareness and detection depth.
  • Mentor and guide detection engineers, promoting a culture of continuous learning, collaboration, and threat-informed defense.

What experience or knowledge should you bring?

  • Expertise in malware analysis (both static and dynamic), reverse engineering, unpacking, and deobfuscation using tools like IDA Pro, Ghidra, x64dbg, and behavioral sandboxes (Cuckoo, CAPE, etc.).
  • Strong understanding of endpoint security technologies, especially EDR platforms and the internal workings of how detection signals are generated and triaged.
  • Deep knowledge of operating system internals (Windows, Linux), including memory management, process / thread architecture, registry, and system calls. Familiarity with Extended Berkeley Packet Filter (eBPF) and container security is highly valued.
  • Knowledge of cloud threat landscape, and threats and attacks targeting Linux, containers, and K8s.
  • Experience with cloud security research / cloud threat hunting or IR / cloud pentesting or redteaming; and with cloud threat detection and cloud-native telemetry (AWS, Azure, GCP).
  • Proficient in threat intelligence frameworks and methodologies, including the Diamond Model, MITRE ATT&CK, Kill Chain, and mapping TTPs to coverage and detection gaps.
  • Strong data analysis and pattern recognition skills, able to sift through telemetry, logs, and artifacts to derive meaningful insights that drive detection hypotheses and logic.
  • Skilled in programming / scripting for automation, analysis, and detection logic generation (mostly Python)
  • Experience building and maintaining threat hunting playbooks, leveraging endpoint telemetry, behavior analytics, and threat intelligence to operationalize continuous threat detection.
  • Comprehensive understanding of threat actor behaviors, intrusion sets, and motivations and their tooling / ecosystem.
  • Nice-to-Have Skills and Qualifications :

  • Relevant certifications such as GIAC GREM, CREA, CMA, OSCE3, or RECA.
  • Familiarity with CTI enrichment platforms and tooling, such as MISP, ThreatConnect, or commercial TIPs.
  • Practical experience in building detection pipelines, integrating threat intelligence with SIEM / EDR platforms.
  • Contributions to open-source tools, YARA rulesets, or CTI repositories.
  • Authored some blogs
  • Why Us?

    Because you will meet extraordinary challenges facing the newest attacks and tech obstacles and overcoming them. You will work with the very BEST in the industry in a flexible and independent environment. You will influence the design of a disruptive product that will shape the security industry of tomorrow.

    What We Offer You

  • Flexible working hours, this is a 100% remote role based within Spain; we provide optional membership in major coworking chains
  • Currently for this role in Spain we are able to consider only candidates that are already eligible to work in the EU at the time of applying
  • Optionally for those willing to relocate to the Czech Republic relocation assistance is available for any candidates that are already eligible to work in the EU at the time of applying
  • Generous employee stock plan in the form of grant of RSUs (restricted stock units), not options; 4 years vesting with 1 year cliff and then quarterly, stock refresh yearly
  • Yearly bonus depending on the performance of the company, paid out in 2 installments
  • 30 Days of Paid Annual Leave
  • Flexible Paid Sick Days
  • Pension insurance contribution
  • Premium Life Insurance covered by S1
  • Premium Medical & Dental Insurance covered by S1
  • Meal, Transport & Homeoffice allowance of total 440 EUR / month
  • Global gender-neutral Parental Leave (16 weeks, beyond the leave provided by the local laws) & Grandparent Leave
  • Volunteering paid day off & Additional paid Company holidays off (e.g. 4 days in 2022)
  • Global Employee Assistance Program (confidential counseling related to both personal and work life matters)
  • Udemy Business platform for Hard / Soft skills Training & Support for your further educational activities / trainings
  • Above-standard referral bonus
  • Aditional Country-specific Benefits To Spain

    SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

    SentinelOne participates in the E-Verify Program for all U.S. based roles. Seniority level

  • Seniority level Not Applicable
  • Employment type

  • Employment type Full-time
  • Job function

  • Job function Information Technology
  • Industries Computer and Network Security
  • Referrals increase your chances of interviewing at SentinelOne by 2x

    Sign in to set job alerts for “Cyber Threat Investigator” roles. Security Architect and Cyber-Threat Intelligence Analyst

    Madrid, Community of Madrid, Spain 2 days ago

    Senior Presales Engineer - Cloud Security Start Up Vendor - Paying €200,000 OTE + Stock

    Madrid, Community of Madrid, Spain 2 months ago

    Senior Cloud Security Engineer (100% remote, only Spain)

    Sevilla La Nueva, Community of Madrid, Spain 3 months ago

    Madrid, Community of Madrid, Spain 3 months ago

    Salamanca, Castilla and Leon, Spain 3 months ago

    Senior Malware Researcher / Detection Engineer - Linux / Cloud Security Senior Director Analyst, Security Architecture and Cloud Security (Remote Canada and EMEA)

    Madrid, Community of Madrid, Spain 2 weeks ago

    Security Analyst Experience - Senior Software Engineer, Generative AI

    We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

    J-18808-Ljbffr

    Crear una alerta de empleo para esta búsqueda

    Researcher • bilbao, España

    Ofertas relacionadas
    • Oferta promocionada
    Market Researcher

    Market Researcher

    Open Home Foundationbilbao, España
    The Open Home Foundation is seeking a Market Researcher to help us answer the big questions : Who are our potential users? Where is the smart home industry headed? What makes our ecosystem differen...Mostrar másÚltima actualización: hace 1 día
    • Oferta promocionada
    Especialista de Threat Protection L3

    Especialista de Threat Protection L3

    Evolutio Empowering the cloudbilbao, España
    BT (British Telecom) con una nueva visión : ser el socio de confianza que acompaña a las empresas en el proceso de Transformación asociado a la adopción de las tecnologías Cloud.Nuestro portfolio in...Mostrar másÚltima actualización: hace 23 días
    • Oferta promocionada
    User Experience Researcher

    User Experience Researcher

    Trend Labs Solutionsbilbao, España
    UX Researcher (Remote / Madrid) - Join Our Team!.We're expanding our team! We're seeking a skilled UX Researcher to join us in Spain to help shape seamless, user-centric digital experiences.If you're...Mostrar másÚltima actualización: hace 9 días
    • Oferta promocionada
    Machine Learning Researcher

    Machine Learning Researcher

    TransPerfectCatalonia, Spain
    This role requires excellent technical skills and the ability to bring innovative AI solutions from research to robust, production-grade implementations. Conduct research and development of novel mo...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Postdoctoral researcher in polymer synthesis

    Postdoctoral researcher in polymer synthesis

    CIC energiGUNEbilbao, España
    CIC energiGUNE is a research center specialized in energy, electrochemical storage (batteries and supercapacitors), thermal energy solutions, and hydrogen. It is a member of the Basque Research and ...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    • Nueva oferta
    Postdoctoral Researcher in Biomedical Wearable Sensors

    Postdoctoral Researcher in Biomedical Wearable Sensors

    UCAMbilbao, España
    The UCAM-SENS unit is looking for an experienced Postdoctoral Researcher in Biomedical.The UCAM-SENS research unit is seeking a highly motivated and experienced postdoctoral.If you have a strong tr...Mostrar másÚltima actualización: hace 18 horas
    • Oferta promocionada
    Staff Infrastructure Engineer

    Staff Infrastructure Engineer

    Factorialbilbao, España
    Be among the first 25 applicants.We’re excited to announce an opening for a.Our mission is to keep the Factorial application running 24 / 7, ensure its performance, scalability and security, as well ...Mostrar másÚltima actualización: hace 17 días
    • Oferta promocionada
    User Experience Researcher

    User Experience Researcher

    Avenue Unitedbilbao, España
    Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive features.This is a full-time remote role for a User Experience Researcher. The User Experience Researcher will b...Mostrar másÚltima actualización: hace 21 días
    • Oferta promocionada
    Offer_2025-Phd Researcher On 5G / 6G And Ai / Ml & Llm

    Offer_2025-Phd Researcher On 5G / 6G And Ai / Ml & Llm

    Iquadratbilbao, España
    Offer_2025-Phd Researcher On 5G / 6G And Ai / Ml & Llm.Offer_2025-Phd Researcher On 5G / 6G And Ai / Ml & Llm.Offer_2025-Phd Researcher On 5G / 6G And Ai / Ml & Llm. Be among the first 25 applicants.Offer_2025-...Mostrar másÚltima actualización: hace 3 días
    • Oferta promocionada
    Postdoctoral Researcher in Biomedical Wearable Sensors

    Postdoctoral Researcher in Biomedical Wearable Sensors

    euraxess.ec.europa.eu - Jobboardbilbao, España
    Organisation / Company UNIVERSIDAD CATÓLICA DE MURCIA - FUNDACIÓN UNIVERSITARIA SAN ANTONIO DE MURCIA Research Field Chemistry Researcher Profile First Stage Researcher (R1) Positions Postdoc Positio...Mostrar másÚltima actualización: hace 8 días
    • Oferta promocionada
    Solid State Battery Researcher

    Solid State Battery Researcher

    CIDETECbilbao, España
    CIDETEC Energy Storage is looking for a person to join in the Energy Materials Unit.If you want to be part of this revolution, we are waiting for you!. Our work covers the entire value chain, from b...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Researcher for Battery Post-Mortem Area

    Researcher for Battery Post-Mortem Area

    Cidetecbilbao, España
    Would you like to build the future? Join CIDETEC!.CIDETEC is a technology centre that brings together three leading international centres in the fields of Energy Storage, Surface Engineering and Na...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Job offer

    Job offer

    Rovira i Virgili University (URV)bilbao, España
    Organisation / Company Rovira i Virgili University (URV) Research Field Computer science » Other Researcher Profile Recognised Researcher (R2) Country Spain Application Deadline 15 Nov 2025 - 00 : 00 (...Mostrar másÚltima actualización: hace 10 días
    • Oferta promocionada
    156006 Predoctoral Research Staff in Training

    156006 Predoctoral Research Staff in Training

    Euraxessbilbao, España
    Organisation / Company Universidade de Vigo Department C05 Statistics and Operations Research Research Field Mathematics » Statistics Researcher Profile First Stage Researcher (R1) Positions Master P...Mostrar másÚltima actualización: hace 8 días
    • Oferta promocionada
    Postdoctoral Researcher In Security And Privacy

    Postdoctoral Researcher In Security And Privacy

    buscojobs Españabilbao, España
    Organisation / Company Rovira i Virgili University (URV) Research Field Computer science » Other Researcher Profile Recognised Researcher (R2) Country Spain Application Deadline 15 Nov 2025 - 00 : ...Mostrar másÚltima actualización: hace 7 días
    • Oferta promocionada
    Predoctoral researcher

    Predoctoral researcher

    European Commissionbilbao, España
    Organisation / Company CIC biomaGUNE Department Research in Biomaterials Research Field Biological sciences Researcher Profile Recognised Researcher (R2) Leading Researcher (R4) First Stage Researche...Mostrar másÚltima actualización: hace 3 días
    • Oferta promocionada
    Researcher in Autonomous Driving

    Researcher in Autonomous Driving

    Vicomtechbilbao, España
    We are looking for an Autonomous Driving researcher to join our Connected, Cooperative and Automated System department.The automotive industry has arrived at an inflexion point : a shift towards aut...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Research support technician 2025 / CP / 091

    Research support technician 2025 / CP / 091

    EURAXESS Czech Republicbilbao, España
    Organisation / Company : University of A Coruña.Research Field : Engineering » Civil Engineering.Researcher Profile : First Stage Researcher (R1). Application Deadline : 28 Jul 2025 - 15 : 00 (Europe / Brusse...Mostrar másÚltima actualización: hace más de 30 días