Malware Researcher/Detection Engineer

  • Remote - Spain

Remote

Cybersecurity

Mid-level

Job description

About Us

At SentinelOne, we’re redefining cybersecurity by pushing the limits of what’s possible—leveraging AI-powered, data-driven innovation to stay ahead of tomorrow’s threats.

From building industry-leading products to cultivating an exceptional company culture, our core values guide everything we do. We’re looking for passionate individuals who thrive in collaborative environments and are eager to drive impact. If you’re excited about solving complex challenges in bold, innovative ways, we’d love to connect with you.

What are we looking for?

We are looking for a talented malware researcher/detection engineer with experience in the Linux or/and cloud security domain. People that can explore new technologies, design and develop from scratch innovative ideas and drive new detection capabilities and infrastructure at scale to our products.

What will you do?

  • You will be responsible for detecting the newest malwares and exploits based on SentinelOne’s AI-powered Endpoint platform (EPP/EDR).
  • The role includes an end to end responsibility for behaviour based detection capabilities, starting from reversing the samples, designing new methods to detect or prevent those, and incorporating it into the product along with the engineering teams.
  • You will be developing and using internal research tools, PoCs and discovering new ways to detect/prevent malicious techniques.

At the end of the day, your deliveries will enhance the security of countless of different Linux endpoints and cloud workloads platforms protected by our product, that serves thousands of users (from enterprise & public sector clients across the globe, incl. some of the largest companies globally) and billions of events daily as part of SentinelOne’s security offering.

You will also be encouraged to write white papers, blogs and articles (but only if you wish to).

Your duties:

  • Detection Development
  • Write tests to cover new detections
  • Conduct low level security research
  • Peer code reviews; Participate in team’s design reviews
  • Learn new technologies in the Linux and Cloud workloads security domains
  • Support customers with issues and requests within the team’s domain

What skills & knowledge should you bring?

  • Experience with reverse engineering of x86/x64 binaries
  • Experience in malware analysis (statically and dynamically)
  • Understanding of Linux and Containers threat landscape (including but not limited to frameworks, MITRE IaaS)
  • Proficient in Linux OS architecture and internals  - understanding how core system components (Processes and Threads, Virtual Memory and more) work behind the scenes.
  • Experience with Python or Lua or other languages for scripting
  • Solid familiarity and understanding of C++
  • An advantage would be:
    • understanding of existing Anti-Virus/Endpoint Protection SW internals
    • experience with eBPF (you may learn more about eBPF and how we use it at S1 here )
    • experience with Cloud Workloads (EKS, ECS, Fargate, etc.‘)
    • experience working on a production-grade product with a wide scale deployment

Why us?

Because you will meet extraordinary challenges facing the newest attacks and tech obstacles and overcoming them. You will work with the very BEST in the industry in a flexible and independent environment. You will influence the design of a disruptive product that will shape the security industry of tomorrow.

What we offer you

  • Flexible working hours, this is a 100% remote role based within Spain; we provide optional membership in major coworking chains

    • Currently for this role in Spain we are able to consider only candidates that are already eligible to work in the EU at the time of applying
    • Optionally for those willing to relocate to the Czech Republic relocation assistance is available for any candidates that are already eligible to work in the EU at the time of applying
  • Generous employee stock plan in the form of grant of RSUs(restricted stock units), not options; 4 years vesting with 1 year cliff and then quarterly, stock refresh yearly

  • Yearly bonus depending on the performance of the company, paid out in 2 installments

  • 30 Days of Paid Annual Leave

  • Flexible Paid Sick Days

  • Pension insurance contribution

  • Premium Life Insurance covered by S1

  • Premium Medical & Dental Insurance covered by S1

  • Meal, Transport & Homeoffice allowance of total 440 EUR/month

  • Global gender-neutral Parental Leave (16 weeks, beyond the leave provided by the local laws) & Grandparent Leave

  • Volunteering paid day off & Additional paid Company holidays off (e.g. 4 days in 2022)

  • Global Employee Assistance Program (confidential counseling related to both personal and work life matters)

  • Udemy Business platform for Hard/Soft skills Training & Support for your further educational activities/trainings

  • Above-standard referral bonus

& Aditional country-specific benefits to Spain

SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

SentinelOne participates in the E-Verify Program for all U.S. based roles.

Share this job:
Please let SentinelOne know you found this job on Remote First Jobs 🙏

Benefits of using Remote First Jobs

Discover Hidden Jobs

Unique jobs you won't find on other job boards.

Advanced Filters

Filter by category, benefits, seniority, and more.

Priority Job Alerts

Get timely alerts for new job openings every day.

Manage Your Job Hunt

Save jobs you like and keep a simple list of your applications.

Search remote, work from home, 100% online jobs

We help you connect with top remote-first companies.

Search jobs

Hiring remote talent? Post a job

Frequently Asked Questions

What makes Remote First Jobs different from other job boards?

Unlike other job boards that only show jobs from companies that pay to post, we actively scan over 20,000 companies to find remote positions. This means you get access to thousands more jobs, including ones from companies that don't typically post on traditional job boards. Our platform is dedicated to fully remote positions, focusing on companies that have adopted remote work as their standard practice.

How often are new jobs added?

New jobs are constantly being added as our system checks company websites every day. We process thousands of jobs daily to ensure you have access to the most up-to-date remote job listings. Our algorithms scan over 20,000 different sources daily, adding jobs to the board the moment they appear.

Can I trust the job listings on Remote First Jobs?

Yes! We verify all job listings and companies to ensure they're legitimate. Our system automatically filters out spam, junk, and fake jobs to ensure you only see real remote opportunities.

Can I suggest companies to be added to your search?

Yes! We're always looking to expand our listings and appreciate suggestions from our community. If you know of companies offering remote positions that should be included in our search, please let us know. We actively work to increase our coverage of remote job opportunities.

How do I apply for jobs?

When you find a job you're interested in, simply click the 'Apply Now' button on the job listing. This will take you directly to the company's application page. We kindly ask you to mention that you found the position through Remote First Jobs when applying, as it helps us grow and improve our service 🙏

Apply now