Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Debugging @ 4
Security
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
SentinelOne is seeking a Senior Threat Intelligence Researcher to lead deep-dive investigations into emerging and known threats, monitor malware developments, synthesize complex data into actionable intelligence, and develop threat-hunting strategies that anticipate changes in threat actor tactics and techniques. The role includes tracking adversary infrastructure and providing senior management with clear briefings to support risk mitigation.
Responsibilities
- Synthesize data from internal threat-hunting findings, dark web forums, leak sites, and research repositories into actionable threat briefings and risk assessments for security leadership and senior stakeholders.
- Lead hypothesis-driven threat hunts across internal networks, cloud environments, and endpoints to uncover sophisticated intrusions that evade traditional security controls.
- Map threat actor footprints internally by pivoting through EDR telemetry.
- Analyze adversary tactics, techniques, and procedures (TTPs), including changes in execution, persistence, and lateral movement.
- Trace adversary infrastructure externally through domain registrations, SSL certificates, and passive DNS.
- Monitor malware developments and track changes in threat actor tradecraft.
Requirements
- Background in threat intelligence or threat hunting.
- Knowledge of the cyber threat landscape, including threat actors and their tactics, techniques, and procedures (TTPs).
- Strong analytical skills and the ability to identify patterns and trends in large datasets.
- Knowledge of how endpoint detection and response (EDR) products operate and how to maximize their telemetry.
- Strong knowledge of YARA and validation best practices for tracking new malware families.
- Understanding of software vulnerabilities and the ability to implement internal hunting strategies to track their exploitation.
- Knowledge of MITRE ATT&CK, CISA KEV, EPSS, AMITT, and MISP Galaxy.
- Knowledge of malware analysis tools and techniques, including static and dynamic analysis, sandboxing, and debugging.
- Technical writing and content development skills.
- Solid technical understanding of EDR systems preferred.
- Relevant certifications preferred, including Certified Malware Analyst (CMA), Certified Reverse Engineering Analyst (CREA), or GIAC Certified Malware Reverse Engineer (GREM).
Benefits
- Restricted Stock Units (RSUs).
- Employee Stock Purchase Plan (ESPP).
- Competitive leave benefits.
- Gender-neutral parental leave.
- Medical and insurance benefits.
- Pension.
- Employee Assistance Program (EAP).
- Global home office allowance.
- Mobile phone reimbursement.
The role is covered by the Italian CBA (Contratto Collettivo Nazionale di Lavoro per i Dipendenti di Aziende del Terziario della Distribuzione e dei Servizi) and is classified as Quadro. The base pay range applies consistently across Italy, regardless of candidate location.
More jobs at SentinelOne
Senior Back-End Engineer
SentinelOne · United States
USD 132,000-182,000 per year
Offensive Security Researcher
SentinelOne · Italy
EUR 51,200-70,000 per year
Senior Forward Deploy Engineer
SentinelOne · United States
USD 132,000-182,000 per year
Marketing Operations Analyst (Data & Systems)
SentinelOne · United States
USD 92,800-128,000 per year
Mid-Level MDR Analyst
SentinelOne · United States
USD 84,000-100,000 per year
Similar jobs
Senior Site Reliability Engineer
ClickHouse · United States
USD 150,000-230,000 per year
Operating Systems Engineer, On-Device Inference | Consumer Devices
OpenAI · San Francisco, United States
USD 230,000-385,000 per year
Operating Systems Engineer, Linux Kernel | Consumer Devices
OpenAI · San Francisco, United States
USD 230,000-385,000 per year
Operating Systems Engineer, Connectivity & Networking | Consumer Devices
OpenAI · San Francisco, United States
USD 230,000-385,000 per year
Research Intern, Robotics – Summer 2027
Nvidia · Seattle, United States
USD 38-94 per hour
Senior Storage Software Engineer - DGX Cloud
Nvidia · Santa Clara, United States
USD 224,000-431,200 per year
Staff Field Engineer
Grafana Labs · Netherlands
EUR 137,000-165,000 per year
Staff Field Engineer
Grafana Labs · Germany
EUR 137,000-164,000 per year