Senior Threat Researcher –Detection Engineer - MacOS

Sophos
Canada
$107K-$179K a year
Permanent

Role Summary

Threat hunter? Programmer? Data-driven? We have a fantastic opportunity here at Sophos Labs for a Threat Researcher to join our global team of behavior-based detection engineers, to hunt, to research, and to add real-time detection for suspicious activity across our customer environments.

Our team of skilled security experts combine their passion to detect & disrupt cyber-attacks with their capability to develop classification rules that can cut through the noise in modern computing environments to tease out attacker’s nefarious activities.

You are intrinsically motivated to understand the core logic behind malware and hacking attacks, to find & predict new ways attackers will modify their techniques and take great satisfaction in developing robust detection logic that is immune to evasive actions.

You will be responsible for writing rules that are able to signal early to late-breaking IOCs that highlight customers under attack, which are the foundation of Sophos next-gen approach.

Above all - you enjoy thinking creatively; combining your deep technical knowledge, your tenacity for innovation, and your can-do attitude to solve complex and challenging problems on a daily basis.

Our team is active in the wider threat research community. Take a look at some recent publications :

What You Will Do

  • Understand malware kill chain & hands-on-keyboard attacks
  • Accurate & efficient classification of malicious & suspicious behavior
  • Mapping IOCs to MITRE Att&ck matrix
  • Author classification rules, for both Endpoint & Cloud scenarios, to identify malicious & suspicious use of TTPs
  • Analyze real-world kill chains to discover new TTPs and gaps in coverage
  • Measure and tune TTP coverage through data mining, customer telemetry & internal sandbox feeds
  • Build & maintain playbooks on threat actor TTPs

What You Will Bring

  • Strong knowledge of MacOS operating system, internals & forensic tools
  • Programming experience, Python / Lua
  • Excellent grasp of MITRE Att&ck tactics, techniques & simulation
  • Familiar with computational cost analysis & problem solving to minimize impact
  • Bachelor degree in Computer Software (Computer Security preferable)
  • Big data experience, Elastic Search, Kibana, Redshift

In Canada, the base salary for this role ranges from $107,000 to $179,000. In addition to base salary, we offer additional compensation including bonus eligibility and a comprehensive benefits package.

A candidate’s specific pay within this range will depend on a variety of factors, including job-related skills, training, location, experience, relevant education, certifications, and other business and organizational needs.

B1#LI-SS1#LI-Remote Ready to Join Us? At Sophos, we believe in the power of diverse perspectives to fuel innovation. Research shows that candidates sometimes hesitate to apply if they don't check every box in a job description.

We challenge that notion. Your unique experiences and skills might be exactly what we need to enhance our team. Don't let a checklist hold you back we encourage you to apply.

What's Great About Sophos? · Sophos operates a remote-first working model, making remote work the primary option for most employees.

However, some roles may necessitate a hybrid approach. Please refer to the location details in our job postings for further information.

  • Our people we innovate and create, all of which are accompanied by a great sense of fun and team spirit· Employee-led diversity and inclusion networks that build community and provide education and advocacy· Annual charity and fundraising initiatives and volunteer days for employees to support local communities· Global employee sustainability initiatives to reduce our environmental footprint· Global fitness and trivia competitions to keep our bodies and minds sharp· Global wellbeing days for employees to relax and recharge · Monthly wellbeing webinars and training to support employee health and wellbeing
  • 25 days ago
Related jobs
Sophos
Canada
Part-time

Role SummaryThreat hunter? Programmer? Data driven? We have a fantastic opportunity here at Sophos Labs for a Threat Researcher to join our global team of behavior based detection engineers, to..

Quantum
Remote, CA
Quick Apply
Remote
Part-time

Ref. No. 113030 Position Threat Detection Analyst (Security)Location Remote (EST hours)Perks Competitive.. Experience with MacOS environment and Google Suite. Familiarity with SIEMs and expertise in utilizing..

Promoted
Ledcor
Vancouver, British Columbia
Full-time

Job Summary. You're an experienced cyber security leader with experience in threat monitoring.. Creates the strategy, architecture, design, and processes for the timely detection and response of..

Services de Gestion Quantum Ltée
Toronto, Ontario
Full-time

Position. Electrical Engineer Location. Vaughan Job Type. Permanent We are looking to hire an Electrical.. Graduate of Electrical Engineering program (C.E.T. or P.Eng.). Ontario industrial electrician license..

Apex Systems
Toronto, Ontario
Quick Apply
Full-time

Apex Systems is hiring a Senior Data Engineer for a government health service provider! Location.. Remote, must work PST Duration. 6 months with possible extensions The Data Engineer will work in a..

Okta
New Canada, Nova Scotia
Full-time

Device Access Group Device Access Group is a new engineering team with a vision to secure customers.. Analyze Refine Requirements with Product Management and Engineering for prototyping Windows client..