Outscal Logooutscal logo

Senior Threat Intelligence Researcher - Linux

4 Months ago • 4-8 Years • Administrative

Job Summary

Job Description

As a Senior Threat Intelligence Researcher for Linux at SentinelOne, you will lead in-depth research and analysis of emerging and existing cyber threats, particularly ransomware. Responsibilities include malware analysis (static/dynamic, reverse engineering), creating actionable intelligence reports, tracking threat actors and infrastructure, developing hunting strategies, and maintaining a knowledge base on ransomware operations. You will leverage your expertise in Linux internals, malware analysis, and threat intelligence frameworks (MITRE ATT&CK, Diamond Model) to contribute to the company's cybersecurity efforts.
Must have:
  • Malware analysis expertise (static/dynamic)
  • Linux internals knowledge
  • Threat intelligence framework knowledge
  • Strong analytical skills
  • Linux malware analysis experience
  • Reverse engineering skills
  • Yara knowledge and validation best practices
  • Experience creating threat reports
Good to have:
  • Relevant certifications (CMA, CREA, GREM)
  • Python, Perl, or Lua programming
  • eBPF and Linux container knowledge
  • EDR in Linux environment understanding
Perks:
  • Flexible working hours and hybrid/remote work model
  • Flexible Time Off
  • Flexible Paid Sick Days
  • Global gender-neutral Parental Leave
  • Generous employee stock plan (RSUs)
  • ESPP (employee stock purchase plan)
  • Gym membership/sports gears
  • Wellness Coach app
  • Private medical insurance
  • Life Insurance
  • Telemedical app consultation
  • Global Employee Assistance Program
  • Home-office-setup allowances
  • Internet allowances
  • Provident Fund and Gratuity
  • NPS contribution
  • Half yearly bonus program
  • Referral bonus
  • LinkedIn Learning platform

Job Details

About the job

About Us:

SentinelOne is defining the future of cybersecurity through our XDR platform that automatically prevents, detects, and responds to threats in real-time. Singularity XDR ingests data and leverages our patented AI models to deliver autonomous protection. With SentinelOne, organizations gain full transparency into everything happening across the network at machine speed – to defeat every attack, at every stage of the threat lifecycle.

We are a values-driven team where names are known, results are rewarded, and friendships are formed. Trust, accountability, relentlessness, ingenuity, and OneSentinel define the pillars of our collaborative and unified global culture. We're looking for people that will drive team success and collaboration across SentinelOne. If you’re enthusiastic about innovative approaches to problem-solving, we would love to speak with you about joining our team!

What are we looking for?

We are seeking a highly motivated and skilled individual to join our team as a Senior Threat Intelligence Researcher for Linux research. The ideal candidate should have a solid background in cybercrime investigation, and malware analysis. As our new colleague you will be responsible for conducting in-depth research and analysis of emerging and existing threats, provide actionable intelligence for detection, and possess a deep understanding of the tactics, techniques, and procedures used by ransomware operators and their ecosystem.

What will you do?

  • Lead and conduct in-depth research and analysis of emerging and existing cyber threats, including ransomware campaigns, and other sophisticated attacks.
  • Utilize reverse engineering and malware analysis skills to identify and analyze malicious code and artifacts.
  • Create actionable intelligence reports and threat briefings to inform senior management and key stakeholders of the potential risks associated with ransomware groups.
  • Keep curating a KB on ransomware operations, their tradecraft, affiliations.
  • Identify and track threat actors, their capabilities, and the infrastructure they use.
  • Analyze malware samples and artifacts to identify their functionality, capabilities, and potential impact.
  • Stay current with emerging malware trends, attack techniques, and evasion tactics.
  • Create and maintain hunting strategies to keep track of operations and shifting in tactics
  • Monitor malicious infrastructures and extract fingerprints to track C2s

What experience or knowledge should you bring?

  • Strong knowledge of malware analysis tools and techniques, including static and dynamic analysis, sandboxing, and debugging. + Knowledge of unpacking and deobfuscation.
  • Understanding software vulnerabilities, and ability to implement hunting strategies to track and discover them
  • Knowledge of various threat intelligence frameworks such as the Diamond Model, MITRE ATT&CK
  • Knowledge of the cyber threat landscape, including actors and TTPs
  • Strong analytical skills, with the ability to identify patterns and trends in large datasets
  • Strong knowledge of Yara to track new malware families and knowledge on validation best practices
  • Knowledge of Linux Internals, Linux Threats, Extended Berkeley Packet Filter (eBPF) and Linux containers; familiarity with Linux distributions and their differences
  • Rudimentary knowledge about working of EDR in Linux environment
  • Familiarity with linux shell scripting (example, bash, zsh, lua)
  • Good to have - relevant certifications, such as Certified Malware Analyst (CMA), Certified Reverse Engineering Analyst (CREA), or GIAC Certified Malware Reverse Engineer (GREM)
  • Programming experience with Python, Perl or Lua
  • Expertise in Linux Systems: Advanced knowledge and hands-on experience with Linux operating systems, including various distributions and architectures.
  • In-depth Understanding of Linux Internals: Strong familiarity with Linux internals, including kernel structures, memory management, file systems, and networking stack.
  • Linux Malware Analysis: Proven experience in identifying, analyzing, and mitigating Linux-based malware. Skilled in reverse engineering and dissecting malware samples to understand their behavior, attack vectors, and impact on Linux systems.

Why us?

You will be joining a cutting-edge company, where you will tackle extraordinary challenges and work with the very best in the industry along with competitive compensation.

  • Flexible working hours and hybrid/remote work model
  • Flexible Time Off
  • Flexible Paid Sick Days
  • Global gender-neutral Parental Leave (16 weeks, beyond the leave provided by the local laws)
  • Generous employee stock plan in the form of RSUs (restricted stock units)
  • On top of RSUs, you can benefit from our attractive ESPP (employee stock purchase plan)
  • Gym membership/sports gears by Cultfit
  • Wellness Coach app, with 3,000+ on-demand sessions, daily interactive classes, audiobooks, and unlimited private coaching
  • Private medical insurance plan for you and your family
  • Life Insurance covered by S1 (for employees)
  • Telemedical app consultation (Practo)
  • Global Employee Assistance Program (confidential counseling related to both personal and work life matters)
  • High-end MacBook or Windows laptop
  • Home-office-setup allowances (one time) and maintenance allowance
  • Internet allowances.
  • Provident Fund and Gratuity (as per govt clause)
  • NPS contribution (Employee contribution)
  • Half yearly bonus program depending on the individual and company performance
  • Above standard referral bonus as per policy
  • LinkedIn Learning platform for Hard/Soft skills Training & Support for your further educational activities/trainings
  • Sodexo food coupons

SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

SentinelOne participates in the E-Verify Program for all U.S. based roles.

Similar Jobs

AMD - Formal Verification-11+ YRS

AMD

Bengaluru, Karnataka, India (On-Site)
6 Months ago
Google - Cloud Technical Solutions Engineer, Security

Google

Pune, Maharashtra, India (On-Site)
4 Months ago
Saviynt - Sr. Engineer, IGA Operations

Saviynt

Atlanta, Georgia, United States (Hybrid)
5 Months ago
Samsung Semiconductor - NVMe Test Engineer (Contractor)

Samsung Semiconductor

San Jose, California, United States (Hybrid)
2 Months ago
Bazaar Voice - Staff MLOps Engineer

Bazaar Voice

London, England, United Kingdom (Hybrid)
5 Months ago
Extreme Network - Cloud Database Administrator (9466)

Extreme Network

Toronto, Ontario, Canada (Hybrid)
5 Months ago
ION - Microsoft System Engineer, Italy

ION

Italy (Hybrid)
5 Months ago
Next Level Business Services - SAP PI/PO LEAD

Next Level Business Services

Scottsdale, Arizona, United States (On-Site)
4 Months ago
Buckman - Payroll & Benefits Specialist

Buckman

Ghent, Flanders, Belgium (On-Site)
4 Months ago
Tesla - Customer Support Specialist

Tesla

Taguig, Metro Manila, Philippines (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

BrightEdge - Devops Engineer

BrightEdge

Hyderabad, Telangana, India (On-Site)
5 Months ago
LeoVegas - Site Reliability Engineer

LeoVegas

Stockholm, Stockholm County, Sweden (Hybrid)
4 Months ago
Next Level Business Services - Full Stack Developer

Next Level Business Services

Jersey City, New Jersey, United States (On-Site)
5 Months ago
ByteDance - Principal Site Reliability Engineer, CDN

ByteDance

Singapore (On-Site)
5 Months ago
Matic Robots - Systems Engineer (Rust)

Matic Robots

Canada (On-Site)
5 Months ago
Rambus - SMTS Verification Engineering

Rambus

Bengaluru, Karnataka, India (Hybrid)
5 Months ago
Bazaar Voice - Staff MLOps Engineer

Bazaar Voice

London, England, United Kingdom (Hybrid)
5 Months ago
Okta - Site Reliability Engineer, Kubernetes

Okta

Bengaluru, Karnataka, India (Hybrid)
5 Months ago
Nielsen Holdings - Software Engineer - Bigdata (Java/ Scala/ Python ,SQL , AWS)

Nielsen Holdings

Bengaluru, Karnataka, India (Hybrid)
5 Months ago
CloudLinux - C Developer (worldwide remote, work anywhere)

CloudLinux

Masovian Voivodeship, Poland (Remote)
4 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

Dream Sports - Senior Product Designer

Dream Sports

Mumbai, Maharashtra, India (On-Site)
2 Months ago
Nagarro - Staff Engineer, .Net Fullstack

Nagarro

India (Remote)
5 Months ago
Starkflow - Marketing Manager

Starkflow

Gurugram, Haryana, India (On-Site)
3 Months ago
SatSure - Senior Machine Learning Researcher

SatSure

Bengaluru, Karnataka, India (On-Site)
6 Months ago
Egnyte - Staff Engineer - AI

Egnyte

India (Remote)
3 Months ago
Anthology  Inc  - Product Support Specialist

Anthology Inc

Bengaluru, Karnataka, India (On-Site)
2 Months ago
Paytm - Product Management - Senior Product Manager - UPI

Paytm

Bengaluru, Karnataka, India (On-Site)
5 Months ago
PwC - IN-Manager_D365 Azure Integration Developer_MS Dynamics– Advisory  - Kolkata

PwC

Kolkata, West Bengal, India (On-Site)
5 Months ago
Rivos - Silicon Logic Formal Verification - Full Time

Rivos

Bengaluru, Karnataka, India (Hybrid)
5 Months ago
Assystems - Manager / Senior Manager - Finance

Assystems

Chennai, Tamil Nadu, India (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Administrative Jobs

Alphasense - Principal People Systems Analyst

Alphasense

United Kingdom (Remote)
2 Months ago
Nielsen Holdings - Staff Sybase Architect

Nielsen Holdings

Mumbai, Maharashtra, India (Hybrid)
5 Months ago
Tesla - HR Operations Payroll Specialist

Tesla

London, England, United Kingdom (On-Site)
1 Month ago
Enphase Energy - Staff Engineer, Oracle APEX Development

Enphase Energy

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Tencent - Office Operations Specialist

Tencent

Kuala Lumpur, Federal Territory Of Kuala Lumpur, Malaysia (On-Site)
2 Months ago
Frontier Developments - Customer & Technical Support Representative

Frontier Developments

Cambridge, England, United Kingdom (Hybrid)
3 Months ago
Nintendo - Manager, Software Engineering

Nintendo

Redmond, Washington, United States (Hybrid)
7 Months ago
Milestone - Payroll Specialist - EMEA Region

Milestone

Copenhagen, Denmark (On-Site)
2 Months ago
Luxoft - Onboarding Technical Analyst

Luxoft

Hyderabad, Telangana, India (On-Site)
3 Months ago
PwC - Specialist | Cost Controlling in Infrastructure Managed Services

PwC

Warsaw, Masovian Voivodeship, Poland (Hybrid)
5 Months ago

Get notifed when new similar jobs are uploaded