Senior Threat Researcher – Behavioral Protection

Sophos
Canada
Workplace: RemoteFull timeFunction: Research & Scientific (R&D)Skills: ["Communication","Mentorship","Teamwork","Problem-solving","Triage"]

Senior Threat Researcher focused on Windows threat behaviors, memory-resident threats, and behavioral protection. You’ll study MITRE ATT&CK techniques, develop rules to detect novel attack methods, and contribute to real-time protection improvements, impacting the security posture of millions of users. The role involves independent work, mentoring peers, and collaboration with the Threat Intelligence team to prioritize protections against emerging threats.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Sophos
Sophos
5 months ago

Senior Threat Researcher – Behavioral Protection

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 4 hours agoStatus: Live

Job Summary

Senior Threat Researcher focused on Windows threat behaviors, memory-resident threats, and behavioral protection. You’ll study MITRE ATT&CK techniques, develop rules to detect novel attack methods, and contribute to real-time protection improvements, impacting the security posture of millions of users. The role involves independent work, mentoring peers, and collaboration with the Threat Intelligence team to prioritize protections against emerging threats.
Location: Canada
Workplace: Remote
Employment Type: Full time
Job Function: Research & Scientific (R&D)
Seniority: Sr. Manager level

Key Responsibilities

  • •Analyze malware behaviors aligned with MITRE ATT&CK TTPs and the full attack lifecycle, with a focus on in-memory techniques, fileless malware, and evasive behaviors.
  • •Research and identify behavioral techniques used by novel Advanced Persistent Threats (APTs) and translate insights into effective behavioral protection rules.
  • •Drive protection coverage for zero-day malware and novel attack techniques.
  • •Work independently with minimal supervision while managing priority protection tasks.
  • •Review and provide actionable feedback on detection logic and code developed by fellow researchers.

Key Requirements

  • •Proven hands-on experience in Windows based malware analysis using static and dynamic analysis tools (e.g., IDA Pro, Windbg)
  • •Deep understanding of behavioral techniques, memory injection methods, persistence mechanisms, and evasion tactics
  • •Demonstrated programming experience, preferably Python and Lua
  • •Experience in a fast-paced threat research or security operations environment
  • •Strong communication skills and ability to provide technical mentorship to peers
Experience:CybersecurityThreat research
Skills:CommunicationMentorshipTeamworkProblem-solvingTriage
Tech Stack:IDA ProWindbgPythonLuaWindows

Company Brief

Sophos
Provides enterprise cybersecurity software and services including endpoint protection, network security, cloud security, encryption, and managed threat response to protect organizations from advanced threats and ransomware.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 500M to 1B
Growth: Established Company
Valuation: Unicorn (USD 1B+)
Funding: Private Equity Backed
Headquarters: Abingdon, United Kingdom
Founded: 1985
WebsiteLinkedIn