Senior Malware Detection Researcher



Bengaluru, Karnataka, India
Posted on Monday, June 17, 2024

About Us:

SentinelOne is defining the future of cybersecurity through our XDR platform that automatically prevents, detects, and responds to threats in real-time. Singularity XDR ingests data and leverages our patented AI models to deliver autonomous protection. With SentinelOne, organizations gain full transparency into everything happening across the network at machine speed – to defeat every attack, at every stage of the threat lifecycle.

We are a values-driven team where names are known, results are rewarded, and friendships are formed. Trust, accountability, relentlessness, ingenuity, and OneSentinel define the pillars of our collaborative and unified global culture. We're looking for people that will drive team success and collaboration across SentinelOne. If you’re enthusiastic about innovative approaches to problem-solving, we would love to speak with you about joining our team!

What are we looking for?

We are looking for talented Windows, Linux, and macOS researchers; people who are always looking to analyze and break things while looking for a complete understanding of how they work; people who live to beat the system and challenge it, and people who are in pursuit of outsmarting malware and overcoming it to protect our customers.

What will you do?

  • You’ll be part of an exceptional malware research team that will ensure we provide the best detection, protection, and visibility capabilities to our customers at any given time.
  • The team does it by performing in-depth analysis and research of threats and vulnerabilities while also being responsible for closing the detection gap through the development and deployment of signatures to millions of endpoints across the globe.
  • You’ll be working closely with other detection teams to ensure our customers get the best security products they can.
  • Your time will be mostly focused on research and development:


  • You’ll perform cutting edge research and analyze (through reverse engineering and other methods) files, TTPs, exploits, and malwares to understand how they operate and behave. The research will mostly be based on binaries and sample files but may also be based on other types of data sources like events and behaviors.
  • You’ll get the opportunity to work on the latest threats and malware samples to tackle sophisticated challenges of the field.
  • Your research findings will be used for delivering new signatures and/or shared with other detection teams to improve our products’ detection capabilities.
  • As malware research expert, you’ll collaborate with many internal/external teams to form a consensus group of experts who will enhance the Detection Research using their expertise and knowledge.


  • You’ll be responsible for developing the signatures for all of our engines that will improve our detection, protection, and visibility, reaching all of our millions of endpoints across the globe.
  • You’ll be responsible for the quality and accuracy of the deliverables that you’ll create and be accountable for them.
  • You’ll create, maintain, and improve existing infrastructure and tools that are being used by the team.

You will also be encouraged to write white papers, blogs, and articles (but only if you wish to).

What experience or knowledge should you bring?

  • A dedication to continuous learning and skill development to meet evolving job demands.
  • Minimum 3 years of experience in both static and dynamic malware analysis and reverse engineering.
  • Proficiency with reverse engineering and analysis tools, such as disassemblers, compilers, and debuggers like IDA, Ghidra, Hopper, LLDB, GDB.
  • Strong background in malware analysis and understanding its behavior consisting of advanced malware techniques, including but not limited to anti -tampering, defense evasion, lateral movement, ransomware, persistence.
  • Excellent and deep understanding of Linux (both UM and KM)
    • Excellent understanding how core system components (Process and Threads, IPC, tracing, Security, Virtual Memory, and more) work behind the scenes.
    • Understanding of Containers and K8s.
  • For macOS
    • Understanding of ARM/ M1 architecture
    • Understanding of sandbox internals/escapes, Transparency, Consent and Control (TCC) internals/escapes.
    • Understanding of security mechanisms File Quarantine, XProtect , Gatekeeper

      • Programming experience : Assembly, C/C++, Objective-C (for macOS), Python.
      • Advantages
        • Good understanding of existing AV/EDR/EPP internals and detection mechanisms.
        • Automation skills for handling malware detection based workflows.
Why us?
You will be joining a cutting-edge company, where you will tackle extraordinary challenges and work with the very best in the industry along with competitive compensation.
  • Flexible working hours and hybrid/remote work model.
  • Flexible Time Off.
  • Flexible Paid Sick Days.
  • Global gender-neutral Parental Leave (16 weeks, beyond the leave provided by the local laws)
  • Generous employee stock plan in the form of RSUs (restricted stock units)
  • On top of RSUs, you can benefit from our attractive ESPP (employee stock purchase plan)
  • Gym membership/sports gears by Cultfit.
  • Wellness Coach app, with 3,000+ on-demand sessions, daily interactive classes, audiobooks, and unlimited private coaching.
  • Private medical insurance plan for you and your family.
  • Life Insurance covered by S1 (for employees)
  • Telemedical app consultation (Practo)
  • Global Employee Assistance Program (confidential counseling related to both personal and work life matters)
  • High-end MacBook or Windows laptop.
  • Home-office-setup allowances (one time) and maintenance allowance.
  • Internet allowances.
  • Provident Fund and Gratuity (as per govt clause)
  • NPS contribution (Employee contribution)
  • Half yearly bonus program depending on the individual and company performance.
  • Above standard referral bonus as per policy.
  • Udemy Business platform for Hard/Soft skills Training & Support for your further educational activities/trainings
  • Sodexo food coupons.

SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

SentinelOne participates in the E-Verify Program for all U.S. based roles.