At a Glance
- Tasks: Analyse advanced security threats and develop high-fidelity detections for our platform.
- Company: Join a leading cybersecurity firm with a focus on innovation and teamwork.
- Benefits: Remote-first model, flexible hours, wellness days, and leadership development opportunities.
- Other info: Enjoy social events, fitness challenges, and a supportive global community.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
- Qualifications: Experience in log analysis, malware research, and scripting languages required.
The predicted salary is between 60000 - 80000 £ per year.
We are seeking a detail-oriented and technically skilled Detection Engineer to join our X-OPS team.
In this role, you will be responsible for analyzing advanced security threats—ranging from malware to complex web attacks—and translating threat intelligence into high-fidelity detections across our platform.
Your work will help ensure our analysts and clients receive highly accurate, actionable alerts with minimal noise.
- You will leverage data from over 40 third‑party and internal sources, partner with our CTU Threat Intelligence team, and use a range of scripting and automation tools to strengthen detection capabilities.
The ideal candidate is a hands‑on security practitioner with a deep understanding of endpoint behavior, cloud behavior, and detection development who thrives in fast‑paced, technical environments.
- Develop countermeasures to detect advanced threats based on research and intelligence from the CTU team.
- Analyze endpoint behaviors and logs to design detections using multi‑source telemetry.
- Continuously refine and monitor detection rules to optimize the signal‑to‑noise ratio for alerts.
- Research and implement alert handling for new device ingestions, ensuring high‑value signal delivery.
- Leverage internal tooling to distinguish native from standard integrations for detection accuracy.
- Collaborate on the development of internal tools, automation, and detection infrastructure.
- Act as a subject‑matter expert across departments including Product Management, Marketing, and Labs Research.
Benefits
- We encourage teams to get together in person periodically to help facilitate teamwork.
- Remote‑first working model & hybrid options.
- Flexible start and end times for many roles.
- Leadership development program.
- Access to Linked In Learning.
- Global internal coaching program (Coach Match).
- Periodic Sophos wellness days off for all Sophos to help employees relax and recharge.
- Global wellbeing program, which offers a range of wellbeing resources, including Sophos Wellbeing Webinars, Stress Management Toolkits, and Developing Resilience Courses.
- Free Employee Assistance Program (EAP) for confidential advice and counseling on a wide range of work and personal issues.
- Free annual subscription to the Calm app.
- Paid parental leave, caregiver leave & bereavement/compassion leave available.
- We host some unforgettable social experiences for our global teams including our music festival SOPH‑Fest, go‑karting, Sophmudder, and incredible holiday parties!
- Our annual global fitness challenge, SOPH‑Fit, sees thousands of employees taking part in our virtual global race around the world.
- Each quarter, we celebrate our exceptional global team by running the Sophos Values Awards, which recognizes and rewards employees who embody the Sophos values and who we are as a company.
- Health care benefits available worldwide.
Qualifications
- Proficiency in analyzing logs from firewalls, proxies, and security infrastructure to identify anomalies.
- Experience in malware analysis, including static/dynamic techniques and reverse engineering (IA32/64, ARM binaries) is a plus.
- Strong passion for cybersecurity research and the ability to quickly learn emerging technologies.
- Knowledge of CI/CD pipelines, testing frameworks, and automation principles.
- Hands‑on experience in scripting languages (Power Shell, Bash, Python) and use of Python data science libraries (e. g., Num Py, Pandas, Matplotlib).
- Familiarity with event logs, traffic pattern anomalies, and threat hunting methodologies.
- Forensic analysis of memory and disk images across various OS and file system types is a plus.
- Strong understanding of endpoint detection, Linux/Unix and Windows OS internals, vulnerability identification, and workflow automation.
- Network traffic analysis skills, including identification of anomalous or malicious traits is a plus.
- Solid grasp of database querying, systems architecture, and process automation for operational improvements is a nice to have.
- Experience with event correlation and incident reconstruction using log data is a plus.
- #J-18808-Ljbffr
Senior Threat Researcher in London employer: Sophos
At Sophos, we pride ourselves on being an excellent employer that fosters a diverse and inclusive work culture, where every team member's contributions are valued. As a OneStream Finance Automation Specialist, you will have the opportunity to work in a dynamic environment in the UK, with access to continuous professional development and growth opportunities, all while playing a crucial role in enhancing financial processes through cutting-edge technology. Join us to be part of a team dedicated to solving complex cybersecurity challenges and making a meaningful impact.