412,170open jobs
14,281companies
71,440added this week
Browse all
Salary
$71k – $151k per year (Estimated)
Location
In office (Bristol)
Employment
Full-Time
Overview
Company
Impact
Profile match
HP Inc. is an American technology company created in 2015 when the original Hewlett-Packard split its personal systems and printing businesses away from its enterprise arm. It is one of the largest personal computer vendors in the world, shipping consumer and commercial laptops, desktops and workstations under the HP, Pavilion, Envy, EliteBook, OMEN and Poly brands, alongside a printing division covering home, office, large-format and industrial 3D printing. Headquartered in Palo Alto, California, the company earns a large share of profit from supplies and services attached to its installed base and has pushed into hybrid-work peripherals and subscription hardware.
Threat Research Engineer

Description -

Threat Research Engineer

Security Lab, HP Labs, Bristol, UK

We have an exciting opportunity to join the HP security team, to study current and emerging endpoint device attack trends, educate internal and external stakeholders on cyber threats, and help influence HP’s security research and innovation strategy. Our HP Security Lab is recruiting an experienced Threat Research Engineer to focus on researching, analysing, explaining, and reporting emerging threats affecting modern endpoints, from OS-level malware, to hardware and firmware attacks. The role combines hands-on technical analysis of malware with the ability to communicate complex findings clearly within HP as well as with external stakeholders and partners.

In this role you will help HP maintain an authoritative view of the endpoint threat landscape and the state of the art in defensive endpoint security technologies. You will help educate internal and external stakeholders and inform HP security technology strategy. You will work closely with other threat researchers, systems security research engineers and security technologists across HP, as well as business stakeholders such as the marketing and communication teams.

The successful candidate will have solid technical skills, a background in low-level computer engineering or computer security architecture, and excellent written and spoken communication skills.

Job Responsibilities

  • Threat Research and Technical Analysis

    • Study and document emerging trends in endpoint security, from OS-level to hardware and firmware threats, including exploit behaviours, bootkits, ransomware, stealthy attacks and other platform-level attack techniques.

    • Analyse attacks observed in the wild, assess their risk, maturity and likely impact, and identify and document relevant mitigation approaches through HP or industry solutions.

    • Research public sources, vulnerability disclosures, technical reports, proof-of-concept material and attacker tradecraft to build evidence-led assessments of threats of interest.

    • Maintain awareness of the latest cyber threat landscape, emerging technologies, defensive endpoint security standards and state of the art capabilities.

  • Technical Analysis and Documentation of Endpoint Cyber Threats, and Endpoint Security State of the Art

    • Translate complex technical concepts into clear, accessible artefacts for technical experts, non-technical teams and external stakeholders.

    • Contribute reports and educational material for technical and non-technical audiences about malware and firmware attack trends and techniques.

  • External Threat Research Communication and Engagement

    • Create high-quality external-facing threat research content, including HP Threat Research Blog posts, technical reports, conference submissions, customer-facing briefings and media-support materials.

    • Communicate clearly with external stakeholders such as customers, conference audiences, industry partners, analysts and media contacts, ensuring technical accuracy while tailoring the message to the audience.

Job Requirements

  • Technical Understanding and Expertise

    • OS architecture knowledge foundation (Windows, Linux…)

    • Some experience with reverse engineering tools

    • Experience with attack and killchain analysis standard frameworks

    • Strong understanding of endpoint security technologies, proven experience in computer security architecture and low-level systems security.

  • Threat Analysis and Research Skills

    • Ability to analyse malware, vulnerabilities, exploit behaviours, attack methods and proof-of-concept material to assess risk, maturity and impact.

    • Ability to find details on attacks and vulnerabilities and gather information from public sources.

    • Experience analysing qualitative and quantitative cyber threat data is desirable.

    • Knowledge of scripting languages such as Python.

  • Analysis, Documentation and Knowledge Management Skills

    • Strong ability to synthesise complex information into structured documentation aimed at the relevant stakeholders.

    • Experience writing clear technical analysis documents, and authoring technical reports.

  • Communication and External Engagement Skills

    • Excellent writing skills and an ability to convey technical knowledge to both technical experts and non-technical audiences.

    • Strong verbal communication skills, including the ability to brief customers, contribute to conference material, support media-facing narratives and partner with marketing and communications teams.

    • Previous experience publishing technical reports, blogs or external threat research content is highly desirable.

The following skills and attributes are a plus

  • Engineering-level knowledge in systems security.

  • Knowledge of PC hardware and firmware architecture and technologies, including x86, ARM, UEFI, PCIe and DMA.

  • Knowledge of OS kernel and hypervisor security.

  • Knowledge of enterprise IT, device security and security management.

  • Some experience in attack analysis, penetration testing or exploit kits, such as Metasploit.

  • Experience in malware analysis, vulnerability research, attack reproduction or attack demonstration.

  • Experience with scripting languages is required. C or C++ coding is a plus..

  • Experience writing and presenting about offensive security, platform security or threat research topics.

  • Degree in Electronic Engineering, Computer Science, Cybersecurity or a related field, or equivalent experience.

About HP

At HP, you’ll have a chance to create tools, technology, and solutions that reshape the way the world works in the future. If you’re looking to join a company that allows you to connect with a network of professionals eager to support you in doing your best work, we want to talk to you. Our legendary culture guides every employee toward success-fostering collaboration and driving innovation.

Operating in over 170 countries, HP is always creating new services, products, and capabilities giving you more opportunities to advance your career. Here, innovation is the key to professional development and career mobility.

When you join HP, you’re joining a company that believes every voice matters and that we all deserve a seat at the table. From the boardroom to factory floor, we create a culture where everyone is respected and where people can be themselves. You will be part of a global laboratory where different perspectives and experiences will help you solve problems in new ways. This is where you can build a long and wide-ranging career.

Equal opportunity employer

HP, Inc. provides equal employment opportunity to all employees and prospective employees, without regard to race, color, religion, sex, national origin, ancestry, citizenship, sexual orientation, age, disability, or status as a protected veteran, marital status, familial status, physical or mental disability, medical condition, pregnancy, genetic predisposition or carrier status, uniformed service status, political affiliation or any other characteristic protected by applicable national, federal, state, and local law(s).

Please be assured that you will not be subject to any adverse treatment if you choose to disclose the information requested. This information is provided voluntarily. The information obtained will be kept in strict confidence.

For more information, review HP’s EEO Policy or read about your rights as an applicant under the law here: “Know Your Rights: Workplace Discrimination is Illegal".

You can find out more about HP or go to the careers site to explore other opportunities.

#LIpost

Job -

Engineering

Schedule -

Full time

Shift -

No shift premium (United Kingdom)

Travel -

Relocation -

Equal Opportunity Employer (EEO)-

HP, Inc. provides equal employment opportunity to all employees and prospective employees, without regard to race, color, religion, sex, national origin, ancestry, citizenship, sexual orientation, age, disability, or status as a protected veteran, marital status, familial status, physical or mental disability, medical condition, pregnancy, genetic predisposition or carrier status, uniformed service status, political affiliation or any other characteristic protected by applicable national, federal, state, and local law(s).

Please be assured that you will not be subject to any adverse treatment if you choose to disclose the information requested. This information is provided voluntarily. The information obtained will be kept in strict confidence.

For more information, review HP’sEEO Policy or read about your rights as an applicant under the law here: “ Know Your Rights: Workplace Discrimination is Illegal "

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
412,170 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Bristol
$63k – $141k per year (Estimated) • Equity • In office • 5+ years exp
AI/ML
Red Teaming
DevOps
GCP
Azure
AWS
Cybersecurity
Okta
MITRE D3FEND
Cyber Kill Chain
Vectra AI
Microsoft Entra ID
Apply
$68k – $155k per year (Estimated) • Equity • In office • 5+ years exp
AI/ML
Red Teaming
DevOps
GCP
Azure
AWS
Cybersecurity
Okta
MITRE D3FEND
Cyber Kill Chain
Vectra AI
Microsoft Entra ID
Apply
$100k – $110k per year • Remote • Full-Time • 4+ years exp
Cybersecurity
MITRE ATT&CK
Cyber Kill Chain
Apply
In office • Full-Time • 8+ years exp • Bachelor's Degree
Cybersecurity
Cyber Kill Chain
Diamond Model
Apply
In office • Full-Time • 8+ years exp • Bachelor's Degree
Cybersecurity
Cyber Kill Chain
Diamond Model
Apply
$116k – $182k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Scotts Valley
Management
Smartsheet
Jira
Apply
$93k – $144k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • Houston
Management
Microsoft Project
Apply
$77k – $177k per year (Estimated) • In office • Full-Time • 10+ years exp • Houston • Tlaquepaque
Apply
$31k – $113k per year (Estimated) • Remote/Hybrid • Full-Time • PhD • Sant Cugat del Vallès
Apply
$31k – $113k per year (Estimated) • In office • Full-Time • Sant Cugat del Vallès
Apply
$58k – $131k per year (Estimated) • Remote/Hybrid • Bristol
Apply
$51k – $167k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Bristol
Apply
$46k – $152k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Bristol
Apply
$60k – $108k per year (Estimated) • Remote/Hybrid • Full-Time • 12+ years exp • Bristol
Apply
$60k – $108k per year (Estimated) • Remote/Hybrid • Full-Time • 10+ years exp • Bristol
Apply
See all jobs
This is one of many
412,170 more open roles from verified company boards, updated every day.