Windows Malware Researcher / Detection Engineer - Senior or Staff
Job Description
Our Purpose
At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them becomes more critical than ever. When you join SentinelOne, your work helps protect global enterprises, critical infrastructure, and the technologies shaping tomorrow. If you are motivated by meaningful challenges and want your impact to be real, measurable, and global, you will find purpose here.
About Us
SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response with clarity and speed. By combining real-time analytics, intelligent automation, and a unified data foundation, we reduce noise, simplify complexity, and empower security teams to focus on what truly matters.
Our teams are builders, problem-solvers, and innovators committed to shaping the future of security. If you are excited to solve hard problems alongside talented, mission-driven people, we invite you to help us build a safer future for humanity.
What Are We Looking For?
We’re looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes.
As a Senior/Staff Windows Detection Engineer you will help shape the future of endpoint security through a unified, converged platform that automatically prevents, detects, and responds to threats in real time. You will design and develop advanced Windows detections by combining deep system process inspection, behavioral analysis, and innovative machine learning techniques to identify and stop sophisticated attacks before they cause harm.
You will join a growing team of passionate security experts and technical leaders who think differently, challenge assumptions, and constantly explore new ways to outsmart adversaries. In this role, you will hunt for emerging threats, solve complex security problems, and deliver high-impact detection capabilities with speed and precision.
What will you do?
Primary responsibilities include:
- You will be responsible for detecting the newest malware and exploits based on SentinelOne’s Endpoint Protection platform. Your role won’t end with a hypothesis or a document - you’ll have an end to end responsibility for behaviour-based detection capabilities, starting from reversing the samples, designing new methods to detect or prevent those, and implementing it in the product in the end (SW development in C++23 and scripting in Lua).
- You will be developing and using internal research tools, PoCs and discovering new ways to detect/prevent exploitation attacks (EoP, drive-by attacks and more).
- At the end of the day, your deliveries will enhance the security of dozens of millions of Windows endpoints which are protected by our platform.
What experience or knowledge should you bring?
Ideal candidates will have:
- Proven experience with reverse engineering of x86/x64/ARM binaries
- Several years of experience in malware analysis (statically and dynamically)
- Several years of experience with C++
- Excellent understanding of the Windows Internals - understanding how core system components (Process and Threads, Virtual Memory and more) work behind the scenes
- Experienced with analysis tools, such as: IDA, WinDBG, SysInternals etc.
- An advantage would be - kernel development experience, Python experience, and/or understanding of existing AVs internals
Why SentinelOne?
AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI-native platform designed to operate at machine speed, not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place.
We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family:
- Flexible working hours, this is a 100% remote role based within Spain; we provide optional membership in major coworking chains
- Currently for this role in Spain we are able to consider only candidates that are already eligible to work in the EU at the time of applying
- Optionally for those willing to relocate to the Czech Republic relocation assistance is available for any candidates that are already eligible to work in the EU at the time of applying
- Generous employee stock plan in the form of grant of RSUs (restricted stock units), not options; 4 years vesting with 1 year cliff and then quarterly, stock refresh yearly
- Yearly bonus depending on the performance of the company, paid out in 2 installments
- 30 Days of Paid Annual Leave
- Flexible Paid Sick Days
- Pension insurance contribution
- Premium Life Insurance covered by S1
- Premium Medical & Dental Insurance covered by S1
- Meal, Transport & Homeoffice allowance of total 440 EUR/month
- Global gender-neutral Parental Leave (16 weeks, beyond the leave provided by the local laws) & Grandparent Leave
- Volunteering paid day off & Additional paid Company holidays off (e.g. 4 days in 2022)
- Global Employee Assistance Program (confidential counseling related to both personal and work life matters)
- LinkedIn Learning platform for Hard/Soft skills Training & Support for your further educational activities/trainings
- Above-standard referral bonus
& Additional country-specific benefits to Spain
SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
SentinelOne participates in the E-Verify Program for all U.S. based roles.