Senior Security Research Engineer

Elastic
Spain
Workplace: OnsiteFull timeEUR 67,000 - 106,000Function: Research & Scientific (R&D)Experience: 6+ yearsSkills: ["Collaboration","Learning mindset","Adversarial thinking","Autonomous decision-making","Communication"]

Lead security research for Elastic Defend by turning emerging attacker techniques into shipped endpoint protections. Research tradecraft across in-memory threats, injections, credential theft, ransomware, and kernel tampering, then build endpoint visibility by instrumenting new event sources on Windows, macOS, and Linux. Write production-ready, performant C/C++ across millions of endpoints, improve efficacy using fleet-scale telemetry, and collaborate with malware researchers, detection engineers, and data scientists.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Elastic
Elastic
21 hours ago

Senior Security Research Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 7 hours agoStatus: Live

Job Summary

Lead security research for Elastic Defend by turning emerging attacker techniques into shipped endpoint protections. Research tradecraft across in-memory threats, injections, credential theft, ransomware, and kernel tampering, then build endpoint visibility by instrumenting new event sources on Windows, macOS, and Linux. Write production-ready, performant C/C++ across millions of endpoints, improve efficacy using fleet-scale telemetry, and collaborate with malware researchers, detection engineers, and data scientists.
Location: Spain
Workplace: Onsite
Employment Type: Full time
Job Function: Research & Scientific (R&D)
Seniority: Mid level

Key Responsibilities

  • •Research emerging attacker techniques and turn them into shipped endpoint protections.
  • •Build and extend endpoint visibility by instrumenting new event sources and closing telemetry gaps across Windows, macOS, and Linux.
  • •Develop production code in C/C++ that is performant and stable at large endpoint scale.
  • •Reverse engineer malware and study evasion to harden protections against real-world bypasses.
  • •Review fleet-scale telemetry to investigate false positives/performance regressions and drive mitigation strategies end to end.

Pay and Benefits

Salary: EUR 67,000 - 106,000
Perks:Health InsuranceParental LeavePaid Leave

Key Requirements

  • •6+ years analyzing attacker tactics, techniques, and procedures (TTPs) and building detection methods for real security threats.
  • •6+ years developing in C, C++, and Python, with the ability to write safe, fast, maintainable code in a security-critical codebase.
  • •Deep operating system internals knowledge in both kernel and user mode, with strongest need for Windows and additional depth in macOS or Linux.
  • •In-depth reverse engineering and malware analysis experience, comfortable working with tooling for understanding hard binaries.
  • •A collaborative, learning-oriented mindset with an ability to anticipate evasion and design resilient protections before release.
Experience:6+ years
Skills:CollaborationLearning mindsetAdversarial thinkingAutonomous decision-makingCommunication
Languages:English
Tech Stack:CC++PythonWindowsMacOSLinuxElastic StackElasticsearchKibanaMachine learningAIOpen source

Company Brief

Elastic
Builds the Elastic Stack (Elasticsearch, Kibana, Beats, Logstash) and provides search, observability, and security solutions that enable organizations to search, analyze, and protect data in real time across applications, infrastructure, and enterprises.
Industry: Data Infrastructure
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Amsterdam, Netherlands
Founded: 2012
WebsiteLinkedIn