SonicWall is a cybersecurity forerunner with more than 30 years of expertise and is recognized as a leading partner-first company, ensuring our partners and their customers are never alone in the fight against cybercrime. With the ability to build, scale and manage security across the cloud, hybrid and traditional environments in real-time, SonicWall provides relentless security against the most evasive cyberattacks across endless exposure points for increasingly remote, mobile and cloud-enabled users. With its own threat research center, SonicWall can quickly and economically provide purpose-built security solutions to enable any organization—enterprise, government agencies and SMBs—around the world. For more information, visit www.sonicwall.com or follow us on Twitter, LinkedIn, Facebook and Instagram.
We are seeking a Senior Software Engineer to join our Threat Detection Platform team and help build the next generation of malware detection and analysis technologies. This role focuses on developing scalable cloud-based services that analyze, classify, and process suspicious files using a combination of static analysis, dynamic analysis, and machine learning techniques.
- Develop, optimize, and maintain static analysis capabilities, including PE and Authenticode signature validation, YARA scanning, Office macro analysis, PDF inspection, archive analysis, and cloud-based hash reputation lookups.
- Manage the machine learning inference pipeline across both products, including model integration, tuning, deployment, and version control within production services.
- Own and enhance the dynamic analysis environment, including Windows VM lifecycle management on KVM/libvirt, guest configuration, behavioral telemetry collection, and support for additional operating systems.
- Read, troubleshoot, enhance, and maintain C/C++-based analysis components that support platform detection capabilities.
- Improve detection effectiveness by developing new analysis engines, expanding file-type coverage, creating behavioral signatures, and increasing test coverage across detection workflows.
- Investigate and resolve production detection issues, including false positives, false negatives, engine failures, and sandbox-related issues.
- Participate in architectural discussions, design reviews, and code reviews to help maintain high engineering standards.
- Collaborate closely with cross-functional teams to continuously improve platform performance, reliability, and detection accuracy.
- Minimum of 8 years of software engineering experience with a Bachelor's degree in Computer Science, Engineering, or a related field; alternatively, 6+ years with a Master's degree, 3+ years with a PhD, or equivalent professional experience.
- Strong Python development experience, including multithreaded programming and performance optimization.
- Working proficiency in C and C++, with the ability to read, debug, build, and modify compiled analysis components.
- Solid understanding of static file analysis techniques, including PE file structures, code-signing validation, YARA rules, Office macros, PDF formats, and archive file inspection.
- Experience deploying and maintaining machine learning inference solutions in production using frameworks such as PyTorch, LightGBM, scikit-learn, or ONNX, including feature engineering and model optimization.
- Familiarity with KVM/libvirt or similar virtualization technologies and a working knowledge of Windows internals, or the ability to quickly develop expertise in these areas.
- Experience with malware analysis, sandbox technologies, threat detection platforms, or cybersecurity software.
- Comfortable working in Linux environments, including process troubleshooting, log analysis, and shell scripting on Ubuntu or Debian-based systems.
- Strong written communication skills and the ability to collaborate effectively within a distributed, asynchronous team environment.
- Contribute to a collaborative engineering environment where team members provide coverage across functional areas when needed.
- Provide maintenance-level support and first-line incident response outside primary areas of expertise, including Python-based services, distributed task processing systems, management APIs, and deployment infrastructure.
- Support operational continuity during teammate absences and partner with subject matter experts when deeper technical specialization is required.
#LI-KB7
#LI-Hybrid
#Python
#MYSQL
SonicWall is an equal opportunity employer.
We are committed to creating a diverse environment and are an equal opportunity employer. All qualified applicants receive consideration for employment without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.
At SonicWall, we pride ourselves on recruiting a diverse mix of talented people and providing active security solutions in 100+ countries.
Applicant Privacy Notice
Skills Required
- Minimum of 8 years software engineering experience (Bachelor's) or equivalent (Masters/PhD alternative experience)
- Strong Python development experience, including multithreaded programming and performance optimization
- Working proficiency in C and C++ to read, debug, build, and modify compiled components
- Solid understanding of static file analysis techniques (PE structures, Authenticode, YARA, Office macros, PDF, archive inspection)
- Experience deploying and maintaining ML inference solutions in production using PyTorch, LightGBM, scikit-learn, or ONNX, including feature engineering and model optimization
- Familiarity with KVM/libvirt or similar virtualization technologies and working knowledge of Windows internals (or ability to quickly develop expertise)
- Experience with malware analysis, sandbox technologies, threat detection platforms, or cybersecurity software
- Comfortable in Linux environments with process troubleshooting, log analysis, and shell scripting on Ubuntu/Debian systems
- Strong written communication skills and ability to collaborate in a distributed, asynchronous team
- Provide maintenance-level support and first-line incident response for Python services, distributed task processing systems, management APIs, and deployment infrastructure
SonicWall Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about SonicWall and has not been reviewed or approved by SonicWall.
-
Healthcare Strength — Health, dental, vision, mental-health support, and wellness programs are part of the package. Feedback suggests coverage breadth is a dependable component of total rewards.
-
Leave & Time Off Breadth — Generous PTO, paid holidays and sick time, and bereavement leave are described alongside flexible or remote options. Feedback suggests ample time away meaningfully supports balance.
-
Retirement Support — A 401(k) and core financial protections such as life and disability insurance are included. Feedback suggests these fundamentals meet standard expectations for many.
SonicWall Insights
What We Do
SonicWall has been fighting the cyber-criminal industry for over 25 years defending small, medium-size businesses and enterprises worldwide. Backed by research from the Global Response Intelligent Defense (GRID) Threat Network, our award-winning real-time breach detection and prevention solutions, coupled with the formidable resources of over 10,000 loyal channel partners around the globe, are the backbone securing more than a million business and mobile networks and their emails, applications and data. This combination of products and partners has enabled a real-time cyber defense solution tuned to the specific needs of the more than 500,000 global businesses in more than 215 countries and territories.








