Senior Threat Intelligence Researcher

📍 Italy
EUR 51,200-70,000 per year
SENIOR
✅ Remote

Tech Stack

Debugging @ 4 Security

Details

SentinelOne is seeking a Senior Threat Intelligence Researcher to lead deep-dive investigations into emerging and known threats, monitor malware developments, synthesize complex data into actionable intelligence, and develop threat-hunting strategies that anticipate changes in threat actor tactics and techniques. The role includes tracking adversary infrastructure and providing senior management with clear briefings to support risk mitigation.

Responsibilities

  • Synthesize data from internal threat-hunting findings, dark web forums, leak sites, and research repositories into actionable threat briefings and risk assessments for security leadership and senior stakeholders.
  • Lead hypothesis-driven threat hunts across internal networks, cloud environments, and endpoints to uncover sophisticated intrusions that evade traditional security controls.
  • Map threat actor footprints internally by pivoting through EDR telemetry.
  • Analyze adversary tactics, techniques, and procedures (TTPs), including changes in execution, persistence, and lateral movement.
  • Trace adversary infrastructure externally through domain registrations, SSL certificates, and passive DNS.
  • Monitor malware developments and track changes in threat actor tradecraft.

Requirements

  • Background in threat intelligence or threat hunting.
  • Knowledge of the cyber threat landscape, including threat actors and their tactics, techniques, and procedures (TTPs).
  • Strong analytical skills and the ability to identify patterns and trends in large datasets.
  • Knowledge of how endpoint detection and response (EDR) products operate and how to maximize their telemetry.
  • Strong knowledge of YARA and validation best practices for tracking new malware families.
  • Understanding of software vulnerabilities and the ability to implement internal hunting strategies to track their exploitation.
  • Knowledge of MITRE ATT&CK, CISA KEV, EPSS, AMITT, and MISP Galaxy.
  • Knowledge of malware analysis tools and techniques, including static and dynamic analysis, sandboxing, and debugging.
  • Technical writing and content development skills.
  • Solid technical understanding of EDR systems preferred.
  • Relevant certifications preferred, including Certified Malware Analyst (CMA), Certified Reverse Engineering Analyst (CREA), or GIAC Certified Malware Reverse Engineer (GREM).

Benefits

  • Restricted Stock Units (RSUs).
  • Employee Stock Purchase Plan (ESPP).
  • Competitive leave benefits.
  • Gender-neutral parental leave.
  • Medical and insurance benefits.
  • Pension.
  • Employee Assistance Program (EAP).
  • Global home office allowance.
  • Mobile phone reimbursement.

The role is covered by the Italian CBA (Contratto Collettivo Nazionale di Lavoro per i Dipendenti di Aziende del Terziario della Distribuzione e dei Servizi) and is classified as Quadro. The base pay range applies consistently across Italy, regardless of candidate location.

More jobs at SentinelOne

Similar jobs