Senior Security Research Engineer, SONAR (Security Operations and Novel Adversary Research)

Elastic
Spain
Full timeEUR 67,000 - 106,000 annuallyFunction: Research & Scientific (R&D)Experience: 6+ yearsSkills: ["Clear communication","Collaboration","Guided mentorship","Technical writing","Continuous learning"]

Take point on SONAR investigations to reverse engineer previously undocumented malware and turn discoveries into shipped protections for customers. You’ll analyze obfuscated samples across Windows, macOS, and Linux, operate global endpoint telemetry to identify threats at scale, and author resilient detection signatures plus automation/AI-assisted workflows. Publish research through Elastic Security Labs and open-source tools, collaborating with adjacent Elastic Security teams to raise the bar on threat intelligence and detection engineering.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Elastic
Elastic
20 hours ago

Senior Security Research Engineer, SONAR (Security Operations and Novel Adversary Research)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 1 hour agoStatus: Live

Job Summary

Take point on SONAR investigations to reverse engineer previously undocumented malware and turn discoveries into shipped protections for customers. You’ll analyze obfuscated samples across Windows, macOS, and Linux, operate global endpoint telemetry to identify threats at scale, and author resilient detection signatures plus automation/AI-assisted workflows. Publish research through Elastic Security Labs and open-source tools, collaborating with adjacent Elastic Security teams to raise the bar on threat intelligence and detection engineering.
Location: Spain
Employment Type: Full time
Job Function: Research & Scientific (R&D)
Seniority: Mid level

Key Responsibilities

  • •Reverse engineer malware nobody has documented yet by unpacking and analyzing obfuscated samples across Windows, macOS, and Linux to understand communication, configuration, and stealth.
  • •Use global endpoint telemetry to identify and mitigate threats, building campaign context for customers and pushing fleet-wide mitigations.
  • •Turn discoveries into shipped protections by authoring detection signatures and creating automation and AI-assisted workflows to speed investigations.
  • •Publish public research via Elastic Security Labs and release tools/detection artifacts to public GitHub repositories; present at conferences.
  • •Help lead the team’s technical direction by taking point on long-running investigations, raising review quality, and mentoring earlier-career researchers.

Pay and Benefits

Salary: EUR 67,000 - 106,000 annually
Perks:Health InsuranceParental LeavePaid Leave

Key Requirements

  • •6+ years reverse engineering malware and researching adversary tradecraft using static and dynamic analysis across executable formats and architectures (including obfuscated/packed code).
  • •Python experience building research tooling and automation, with the ability to read C and C++ and learn new runtimes as needed (samples may involve Rust, Go, NodeJS).
  • •YARA authorship and hunting at scale to detect weak signals in large telemetry datasets and keep signatures holding against variants.
  • •Working knowledge of Windows and Linux internals, network protocols (HTTP, TLS), and applied cryptography fundamentals for recognizing protection of configuration data.
  • •Ability to write clear technical analyses from investigations, and a track record using AI to accelerate development, debug complex systems, and optimize code while owning outcomes.
Experience:6+ yearsCybersecurityMalware researchThreat intelligenceEndpoint telemetryOpen-source
Skills:Clear communicationCollaborationGuided mentorshipTechnical writingContinuous learning
Tech Stack:PythonCC++RustGoNodeJSYARAWindowsLinuxMacOSPEELFMach-OX86-64ARMHTTPTLSGitHubElastic StackElasticsearch

Company Brief

Elastic
Builds the Elastic Stack (Elasticsearch, Kibana, Beats, Logstash) and provides search, observability, and security solutions that enable organizations to search, analyze, and protect data in real time across applications, infrastructure, and enterprises.
Industry: Data Infrastructure
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Amsterdam, Netherlands
Founded: 2012
WebsiteLinkedIn