Senior Threat Researcher in London

Senior Threat Researcher in London

London Full-Time 60000 - 80000 £ / year (est.) No working from home possible
Sophos

At a Glance

  • Tasks: Analyse advanced security threats and develop high-fidelity detections for our platform.
  • Company: Join a leading cybersecurity firm with a focus on innovation and teamwork.
  • Benefits: Remote-first model, flexible hours, wellness days, and leadership development opportunities.
  • Other info: Enjoy social events, fitness challenges, and a supportive global community.
  • Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
  • Qualifications: Experience in log analysis, malware research, and scripting languages required.

The predicted salary is between 60000 - 80000 £ per year.

We are seeking a detail-oriented and technically skilled Detection Engineer to join our X-OPS team.

In this role, you will be responsible for analyzing advanced security threats—ranging from malware to complex web attacks—and translating threat intelligence into high-fidelity detections across our platform.

Your work will help ensure our analysts and clients receive highly accurate, actionable alerts with minimal noise.

  • You will leverage data from over 40 third‑party and internal sources, partner with our CTU Threat Intelligence team, and use a range of scripting and automation tools to strengthen detection capabilities.

The ideal candidate is a hands‑on security practitioner with a deep understanding of endpoint behavior, cloud behavior, and detection development who thrives in fast‑paced, technical environments.

  • Develop countermeasures to detect advanced threats based on research and intelligence from the CTU team.
  • Analyze endpoint behaviors and logs to design detections using multi‑source telemetry.
  • Continuously refine and monitor detection rules to optimize the signal‑to‑noise ratio for alerts.
  • Research and implement alert handling for new device ingestions, ensuring high‑value signal delivery.
  • Leverage internal tooling to distinguish native from standard integrations for detection accuracy.
  • Collaborate on the development of internal tools, automation, and detection infrastructure.
  • Act as a subject‑matter expert across departments including Product Management, Marketing, and Labs Research.

Benefits

  • We encourage teams to get together in person periodically to help facilitate teamwork.
  • Remote‑first working model & hybrid options.
  • Flexible start and end times for many roles.
  • Leadership development program.
  • Access to Linked In Learning.
  • Global internal coaching program (Coach Match).
  • Periodic Sophos wellness days off for all Sophos to help employees relax and recharge.
  • Global wellbeing program, which offers a range of wellbeing resources, including Sophos Wellbeing Webinars, Stress Management Toolkits, and Developing Resilience Courses.
  • Free Employee Assistance Program (EAP) for confidential advice and counseling on a wide range of work and personal issues.
  • Free annual subscription to the Calm app.
  • Paid parental leave, caregiver leave & bereavement/compassion leave available.
  • We host some unforgettable social experiences for our global teams including our music festival SOPH‑Fest, go‑karting, Sophmudder, and incredible holiday parties!
  • Our annual global fitness challenge, SOPH‑Fit, sees thousands of employees taking part in our virtual global race around the world.
  • Each quarter, we celebrate our exceptional global team by running the Sophos Values Awards, which recognizes and rewards employees who embody the Sophos values and who we are as a company.
  • Health care benefits available worldwide.

Qualifications

  • Proficiency in analyzing logs from firewalls, proxies, and security infrastructure to identify anomalies.
  • Experience in malware analysis, including static/dynamic techniques and reverse engineering (IA32/64, ARM binaries) is a plus.
  • Strong passion for cybersecurity research and the ability to quickly learn emerging technologies.
  • Knowledge of CI/CD pipelines, testing frameworks, and automation principles.
  • Hands‑on experience in scripting languages (Power Shell, Bash, Python) and use of Python data science libraries (e. g., Num Py, Pandas, Matplotlib).
  • Familiarity with event logs, traffic pattern anomalies, and threat hunting methodologies.
  • Forensic analysis of memory and disk images across various OS and file system types is a plus.
  • Strong understanding of endpoint detection, Linux/Unix and Windows OS internals, vulnerability identification, and workflow automation.
  • Network traffic analysis skills, including identification of anomalous or malicious traits is a plus.
  • Solid grasp of database querying, systems architecture, and process automation for operational improvements is a nice to have.
  • Experience with event correlation and incident reconstruction using log data is a plus.
  • #J-18808-Ljbffr

Senior Threat Researcher in London employer: Sophos

At Sophos, we pride ourselves on being an excellent employer that fosters a diverse and inclusive work culture, where every team member's contributions are valued. As a OneStream Finance Automation Specialist, you will have the opportunity to work in a dynamic environment in the UK, with access to continuous professional development and growth opportunities, all while playing a crucial role in enhancing financial processes through cutting-edge technology. Join us to be part of a team dedicated to solving complex cybersecurity challenges and making a meaningful impact.

Sophos

Contact Details:

Sophos Recruitment Team

We think you need these skills to ace Senior Threat Researcher in London

Analysing logs from firewalls
Malware analysis
Reverse engineering
Cybersecurity research
CI/CD pipelines
Testing frameworks
Scripting languages (PowerShell, Bash, Python)