Staff Threat Researcher

Sorry, this job was removed at 04:13 p.m. (CST) on Friday, Sep 05, 2025
Be an Early Applicant
Poland
Information Technology • Security • Cybersecurity
The Role
About Us

At SentinelOne, we’re redefining cybersecurity by pushing the limits of what’s possible—leveraging AI-powered, data-driven innovation to stay ahead of tomorrow’s threats.

From building industry-leading products to cultivating an exceptional company culture, our core values guide everything we do. We’re looking for passionate individuals who thrive in collaborative environments and are eager to drive impact. If you’re excited about solving complex challenges in bold, innovative ways, we’d love to connect with you.

What are we looking for?

We are seeking a highly motivated and skilled individual to join our team as a Staff Threat (Intelligence) Researcher. The ideal new colleague should have a solid background in cybercrime investigation/threat research - incl. especially Linux and/or Cloud, and malware analysis. You will be responsible for conducting in-depth research and analysis of emerging and existing threats, provide actionable intelligence for detection, and will leverage your deep understanding of the tactics, techniques, and procedures used by ransomware operators and their ecosystem.

What You’ll Do?
  • Lead threat intelligence initiatives to proactively research, analyze, and assess emerging cyber threats, including ransomware groups, financially motivated actors with a focus on developing detection strategies.
  • Perform in-depth technical threat analysis, including malware reverse engineering (static/dynamic), campaign tracking, and infrastructure profiling, to inform and drive detection logic in endpoint detection and response (EDR) platforms.
  • Develop high-fidelity detection logic (YARA, platform rules etc) based on actionable intelligence derived from malware capabilities, actor TTPs, and behavioral patterns observed in telemetry and forensic artifacts.
  • Design and implement threat hunting strategies to proactively discover malicious activity, unearth novel attack patterns, and surface IOCs  and BOIs across diverse environments.
  • Continuously curate and maintain a threat intelligence knowledge base, including actor profiles, toolsets, infrastructure usage, TTPs, and affiliations, with a special focus on tracking ransomware and their evolving ecosystems.
  • Monitor adversary infrastructure (C2s, exploit servers), and develop automated methods to fingerprint and track infrastructure reuse across campaigns.
  • Collaborate with detection engineers to align threat research with detection coverage gaps
  • Produce actionable intelligence reports and detection recommendations for internal stakeholders, including concise executive briefings and deep technical analysis for detection engineering and response teams.
  • Stay ahead of the curve on malware trends, evasive techniques, and novel TTPs, and map findings to threat models (e.g., MITRE ATT&CK, Diamond Model) to maintain contextual awareness and detection depth.
  • Mentor and guide detection engineers, promoting a culture of continuous learning, collaboration, and threat-informed defense.
What experience or knowledge should you bring?
  • Expertise in malware analysis (both static and dynamic), reverse engineering, unpacking, and deobfuscation using tools like IDA Pro, Ghidra, x64dbg, and behavioral sandboxes (Cuckoo, CAPE, etc.).
  • Strong understanding of endpoint security technologies, especially EDR platforms and the internal workings of how detection signals are generated and triaged.
  • Deep knowledge of operating system internals (Windows, Linux), including memory management, process/thread architecture, registry, and system calls. Familiarity with Extended Berkeley Packet Filter (eBPF) and container security is highly valued.
  • Knowledge of cloud threat landscape, and threats and attacks targeting Linux, containers, and K8s.
  • Experience with cloud security research/ cloud threat hunting or IR/ cloud pentesting or redteaming; and with cloud threat detection and cloud-native telemetry (AWS, Azure, GCP). 
  • Proficient in threat intelligence frameworks and methodologies, including the Diamond Model, MITRE ATT&CK, Kill Chain, and mapping TTPs to coverage and detection gaps.
  • Strong data analysis and pattern recognition skills, able to sift through telemetry, logs, and artifacts to derive meaningful insights that drive detection hypotheses and logic.
  • Skilled in programming/scripting for automation, analysis, and detection logic generation (mostly Python)
  • Experience building and maintaining threat hunting playbooks, leveraging endpoint telemetry, behavior analytics, and threat intelligence to operationalize continuous threat detection.
  • Comprehensive understanding of threat actor behaviors, intrusion sets, and motivations and their tooling/ecosystem.
Nice-to-Have Skills and Qualifications:
  • Relevant certifications such as GIAC GREM, CREA, CMA, OSCE3, or RECA.
  • Familiarity with CTI enrichment platforms and tooling, such as MISP, ThreatConnect, or commercial TIPs.
  • Practical experience in building detection pipelines, integrating threat intelligence with SIEM/EDR platforms.
  • Contributions to open-source tools, YARA rulesets, or CTI repositories.
  • Authored some blogs
Why Us? 

Because you will meet extraordinary challenges facing the newest attacks and tech obstacles and overcoming them. You will work with the very BEST in the industry in a flexible and independent environment. You will influence the design of a disruptive product that will shape the security industry of tomorrow.

What we offer you
  • Permanent-fulltime collaboration (UoP)
  • Flexible working hours, this is a 100% remote role based within Poland; we provide optional membership in major co-working spaces
    • Currently for this role in Poland we are able to consider only candidates that are already eligible to work in the EU at the time of applying
    • Optionally for those willing to relocate to the Czech Republic relocation assistance is available for any candidates that are already eligible to work in the EU at the time of applying
  • Generous employee stock plan in the form of grant of RSUs (restricted stock units), not options; 4 years vesting with 1 year cliff and then quarterly, stock refresh yearly
  • Yearly bonus depending on the performance of the company, paid out in 2 installments
  • LuxMed, Life Insurance, Disability Insurance, PPK (4% employer contribution)
  • Flexible time off (up to 30 paid days off per annum!)
  • Volunteering paid day off & Additional paid Company holidays off (e.g. 4 days in 2022)
  • Monthly Wellness Allowance
  • Monthly Working from Home allowance
  • Global gender-neutral Parental Leave (16 weeks, beyond the leave provided by the local laws) & Grandparent Leave
  • Global Employee Assistance Program (confidential counseling related to both personal and work life matters)
  • Udemy Business platform for Hard/Soft skills Training & Support for your further educational activities/trainings
  • Above-standard referral bonus

& Aditional Country-specific Benefits & Allowances To Poland

SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

SentinelOne participates in the E-Verify Program for all U.S. based roles. 

SentinelOne Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about SentinelOne and has not been reviewed or approved by SentinelOne.

  • Parental & Family Support Policies include at least 16 weeks fully paid, gender‑neutral parental leave with family‑forming support and a flexible return period. Grandparent leave and caregiver‑inclusive language reinforce broad family coverage.
  • Leave & Time Off Breadth Time away options span unlimited PTO alongside paid holidays, sick time, and volunteer time. Feedback suggests teams can leverage varied leave types for both personal needs and community engagement.
  • Equity Value & Accessibility Equity features include RSU grants and an ESPP, complementing base pay and bonuses. Feedback suggests the equity mix is a meaningful part of total rewards with multi‑year vesting.

SentinelOne Insights

Similar Jobs

Mastercard Logo Mastercard

Product Management Specialist

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Warsaw, Warszawa, Masovian, POL
38800 Employees

Capco Logo Capco

Product Manager

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
Poland
6000 Employees

Motorola Solutions Logo Motorola Solutions

Embedded C/C++ Engineer

Artificial Intelligence • Hardware • Information Technology • Security • Software • Cybersecurity • Big Data Analytics
Hybrid
Kraków, Małopolskie, POL
23000 Employees

Motorola Solutions Logo Motorola Solutions

Cplusplus Software Engineer

Artificial Intelligence • Hardware • Information Technology • Security • Software • Cybersecurity • Big Data Analytics
Hybrid
Kraków, Małopolskie, POL
23000 Employees
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Mountain View, CA
2,830 Employees
Year Founded: 2013

What We Do

SentinelOne is a leading provider of autonomous security solutions for endpoint, cloud, and identity environments. Founded in 2013 by a team of cybersecurity and defense experts, SentinelOne revolutionized endpoint protection with a new, AI-powered approach. Our platform unifies prevention, detection, response, remediation, and forensics in a single, easy-to-use solution. Our endpoint security product is designed to protect your organization's endpoints from known and unknown threats, including malware, ransomware, and APTs. It uses artificial intelligence to continuously learn and adapt to new threats, providing real-time protection and automated response capabilities. SentinelOne's approach to security is designed to help organizations secure their assets with speed and simplicity. We provide the ability to detect malicious behavior across multiple vectors, rapidly eliminate threats with fully-automated integrated response, and adapt their defenses against the most advanced cyberattacks. We are recognized by Gartner in the Endpoint Protection Magic Quadrant as a Leader and have enterprise customers worldwide. Our customers include some of the world's largest companies in various industries such as finance, healthcare, government, and more. At SentinelOne, we understand that cybersecurity is a constantly evolving field and that the threats facing organizations are becoming increasingly sophisticated. That's why we are committed to staying at the forefront of technology and innovation and providing our customers with the best protection against cyber threats. We offer our customers a wide range of services, including threat hunting, incident response, and incident management. Our team of experts is available to assist you 24/7 and can help you respond to and manage cyber incidents quickly and effectively. To learn more about our products and services, please visit our website at www.sentinelone.com or contact us to schedule a demo

Gallery

Gallery

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Milestone Systems Thumbnail
Artificial Intelligence • Other • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account