Senior Threat Researcher – Behavioral Protection

sophos
Canada
On-site
Full-time
Posted 4 months ago
Threat Intelligence

Job Description

Role Summary 
 
We are seeking a skilled and passionate Threat Researcher with deep expertise in Windows based threat behaviors, particularly having a strong understanding on memory-resident threats. In this role, you will be at the forefront of detecting and understanding emerging attack techniques, developing behavioral-based protection strategies, and enhancing our real-time protection capabilities. Your insights and contributions will directly impact on the security posture of millions of users worldwide. 

Responsibilities

What You Will Do

  • Analyze malware behaviors aligned with MITRE ATT&CK TTPs (and beyond), covering the full attack lifecycle, including initial access vectors, execution techniques, payload delivery—with a strong focus on in-memory techniques, fileless malware, and evasive behaviors. 

  • Research and identify behavioral techniques employed by novel and sophisticated Advanced Persistent Threats (APTs) and translate these insights into effective behavioral protection rules to enhance prevention capabilities. 

  • Drive protection coverage for zero-day malware and novel attack techniques. 

  • Work independently with minimal supervision while managing priority protection tasks. 

  • Review and provide actionable feedback on detection logic and code developed by fellow researchers. 

  • Collaborate with the team to define clear protection priorities and deliver updates to customers in a timely manner. 

  • Produce quality threat analysis reports for both internal and external audience 

What You Will Bring

  • Proven hands-on experience in Windows based malware analysis using both static and dynamic analysis tools such as using IDAPro and Windbg. 

  • Deep understanding of behavioral techniques, memory injection methods, persistence mechanisms, and evasion tactics. 

  • Ability to write robust, high-quality behavioral protection rules. 

  • Demonstrated programming experience, preferably Python, Lua. 

  • Experience working in a fast-paced threat research or security operations environment. 

  • Strong communication skills and the ability to provide technical mentorship to peers. 

  • Proactive, self-driven mindset with the ability to lead in critical incident or zero-day response scenarios. 

Ready to Apply?

Take the next step in your career journey

Apply Now

Explore more

Browse more jobs like this

Disclaimer: Real Jobs From Anywhere is an independent platform dedicated to providing information about job openings. We are not affiliated with, nor do we represent, any company, agency, or agent mentioned in the job listings. Please refer to our Terms of Services for further details.