What You Will Do
- Investigate how threat actors are leveraging AI across the attack lifecycle, including: AI assisted social engineering, AI-generated malware, automated reconnaissance, and adversarial attacks against ML-based defenses.
- Research real-world threats to agentic AI systems, AI supply chains, and enterprise AI deployments, assessing risk and developing detection strategies.
- Help instrument and tune telemetry to identify indicators of AI-driven attacker behavior at scale.
- Analyze global telemetry, case data, and OSINT to surface emerging AI-related threat trends and early-warning indicators.
- As a practitioner of the technology you research, identify opportunities to automate repetitive research and reporting workflows using LLMs, scripting, and internal tooling.
- Help the team evolve its operating model as new AI capabilities become available.
- Cross-Functional Collaboration
- Work closely with CTU researchers, SophosLabs analysts, MDR threat hunters, data
- scientists, and engineering teams to synthesize findings into unique reporting with actionable intelligence.
- Contribute to the joint task-force intelligence cycle, ensuring insights flow rapidly into protections, detection rules, and operational systems.
- Produce high-quality written intelligence outputs, including deep-dive research, rapid
- analyses, and strategic forecasting.
- Author work that is suitable for external publication via Sophos blogs, industry reports,
- and conference presentations.
- Present findings to internal stakeholders, external partners, and the broader security
- community.
Research & Analysis
Automation & Efficiency
Content & Publication
What You Will Bring
- Ability to interpret data from diverse telemetry sources and transform it into actionable
intelligence. - Exceptional written communication skills suitable for both technical and executive
audiences. - Demonstrated experience in at least two of the following: threat intelligence, malware analysis, detection engineering, or AI/ML research.
- Strong knowledge of threat actor ecosystems, modern attack techniques, and the MITRE ATT&CK framework.
- Hands-on proficiency with Python and modern AI development patterns, including building and orchestrating multi-agent systems, working with LLM APIs, and designing agentic workflows with sub-agents, tool use, and retrieval-augmented generation.
- Experience building or using automation tools to streamline analytical or reporting
workflows. - Experience working in MDR, incident response, or real-time security operations environments.
- Prior authorship of externally published threat research (blogs, reports, conference presentations).
- Experience with LLMs, prompt engineering, or building AI-assisted analytical tools.
- Familiarity with large-scale telemetry pipelines, security data lakes, or SIEM/SOAR platforms.
Preferred Qualifications
Skills Required
- Ability to interpret data from diverse telemetry sources and transform it into actionable intelligence.
- Exceptional written communication skills suitable for both technical and executive audiences.
- Demonstrated experience in at least two of the following: threat intelligence, malware analysis, detection engineering, or AI/ML research.
- Strong knowledge of threat actor ecosystems, modern attack techniques, and the MITRE ATT&CK framework.
- Hands-on proficiency with Python and modern AI development patterns, including building and orchestrating multi-agent systems.
- Experience building or using automation tools to streamline analytical or reporting workflows.
Sophos Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Sophos and has not been reviewed or approved by Sophos.
-
Leave & Time Off Breadth — Time away is positioned as broad, with company-wide wellness days plus dedicated learning days and paid volunteer time.
-
Parental & Family Support — Family-related leave appears more comprehensive than baseline offerings, including paid parental leave, caregiver leave, and extended bereavement leave.
-
Wellbeing & Lifestyle Benefits — Wellbeing support is emphasized through always-available assistance resources and a Calm subscription, suggesting a lifestyle-oriented benefits approach.
Sophos Insights
What We Do
Cybersecurity Evolved. As a worldwide leader in next-generation cybersecurity, Sophos protects nearly 400,000 organizations of all sizes in more than 150 countries from today’s most advanced cyberthreats. Powered by SophosLabs – a global threat intelligence and data science team – Sophos’ cloud-native and AI-enhanced solutions secure endpoints (laptops, servers and mobile devices) and networks against evolving cybercriminal tactics and techniques, including automated and active-adversary breaches, ransomware, malware, exploits, data exfiltration, phishing, and more.





