368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$28k – $64k per year (Estimated)
Location
In office
Seniority
Senior · 5+ years exp
Overview
Company
Impact
Profile match
SentinelOne is an American cybersecurity company founded in 2013 and headquartered in Mountain View, California that builds autonomous endpoint and cloud protection. Its Singularity platform runs behavioural AI models directly on each protected device, so threats can be detected, blocked and rolled back without waiting for a cloud signature lookup or an analyst decision. The platform has expanded from endpoint detection into cloud workload security, identity threat protection and a security data lake, and the company has traded on the New York Stock Exchange since 2021.

Our Purpose

At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them becomes more critical than ever. When you join SentinelOne, your work helps protect global enterprises, critical infrastructure, and the technologies shaping tomorrow. If you are motivated by meaningful challenges and want your impact to be real, measurable, and global, you will find purpose here.

About Us

SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response with clarity and speed. By combining real-time analytics, intelligent automation, and a unified data foundation, we reduce noise, simplify complexity, and empower security teams to focus on what truly matters.

Our teams are builders, problem-solvers, and innovators committed to shaping the future of security. If you are excited to solve hard problems alongside talented, mission-driven people, we invite you to help us build a safer future for humanity.

What Are We Looking For?

We’re looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes.

As a Senior Malware Detection Engineer with deep expertise in Linux and macOS - someone who is always looking to analyze and break things while pursuing a complete understanding of how they work, who lives to beat the system and challenge it, and who is driven to outsmart malware to protect our customers. 

What Will You Do?

Primary responsibilities include

  • Research

    • Perform in-depth analysis and research (through reverse engineering and other methods) of Linux and macOS threats, TTPs, exploits, and malware - including ELF and Mach-O binaries, shell/script-based malware, and software supply-chain / malicious open-source packages - to understand how they operate and close detection gaps.
    • Analyze endpoint telemetry alongside binaries and samples to validate detections, hunt telemetry and use security platforms for emerging malware families, and prioritize new coverage.
    • Share research findings with other detection teams and collaborate across internal/external groups to strengthen detection capability.

    Development

    • Own detection coverage end to end: write and maintain detection assets, be accountable for FP/FN quality, detection efficacy and performance.
    • Design and maintain the CI/testing infrastructure used to build, test, and ship detection content safely.
    • Build and improve tooling that gives the team visibility into rule performance, coverage, and FP/FN trends - increasingly leveraging AI/LLM-assisted pipelines to speed up triage and analysis for covering the detection gap.
    • Respond quickly to emerging threats and customer detection escalations for malware requests.
    • Support detection coverage validation against BAS (Breach and Attack Simulation) frameworks.
    • Mentor other engineers on Linux/macOS malware analysis and detection engineering practices.
    • You'll also be encouraged to write whitepapers, blogs, and articles.

What Skills and Knowledge Will You Bring?

Ideal candidates will have: 

    • A dedication to continuous learning and skill development to meet evolving job demands.
    • 5+ years of experience in both static and dynamic malware analysis and reverse engineering, with proven depth on Linux and working knowledge of macOS (or vice versa).
    • Proficiency with reverse engineering and analysis tools, such as disassemblers, compilers, and debuggers like IDA, Ghidra, Hopper, LLDB, GDB.
    • Strong background in malware analysis and understanding its behavior, including advanced techniques such as anti-tampering, defense evasion, lateral movement, persistence, and ransomware activity.
    • Good understanding of MITRE ATT&CK TTPs.
    • A strong inclination toward automating routine analysis and detection workflows.
    • Excellent and deep understanding of Linux (both user-mode and kernel-mode):
    • Core system internals - processes and threads, IPC, tracing (including eBPF), security, virtual memory - and how they work behind the scenes.
    • Understanding of containers and Kubernetes, including common container escape and cloud-native attack techniques.
    • For macOS:
      • Understanding of ARM64/Apple Silicon architecture.
      • Understanding of sandbox internals/escapes, and Transparency, Consent and Control (TCC) internals/escapes.
      • Understanding of security mechanisms such as File Quarantine, XProtect, and Gatekeeper.
      • Programming experience: Assembly, C/C++, Objective-C (for macOS), Python.
      • Experience creating production detection rules using YARA/plist or similar engines.

    Preferred / Advantages (One or more)

    • Exposure to AI/LLM-assisted reverse engineering or detection-authoring tooling.
    • Good understanding of existing AV/EDR/EPP internals and detection mechanisms.
    • Experience building CI/CD pipelines (Jenkins, GitHub Actions, or similar) for shipping detection content.
    • Familiarity with attack simulation frameworks (BAS) and their TTPs.
    • Experience querying large-scale telemetry (SQL, EventDB/DataSet, Redash, or similar) to validate detections.

Why SentinelOne?

AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI-native platform designed to operate at machine speed, not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place.

We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family:

Equity & Rewards

  • Restricted Stock Units (RSUs)
  • Employee Stock Purchase Plan (ESPP)

Time Off & Wellbeing

  • Competitive leave benefits
  • Gender-neutral parental leave

Insurance & Financial Security

  • Medical and insurance benefits
  • Employee Assistance Program (EAP)

Work Perks & Flexibility

  • Global home office allowance
  • Internet allowance
  • LinkedIn Learning license
  • Social Connect program
  • Food allowance (Bangalore office)
  • Meal vouchers (Sodexo)

Wellness & Lifestyle

  • Health & wellness benefit

SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

SentinelOne participates in the E-Verify Program for all U.S. based roles. 

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$18k – $46k per year (Estimated) • Remote • Full-Time • Tula
C#
JavaScript
Node JS
SQL
TypeScript
C#
.NET
Node JS
InversifyJS
Databases
DynamoDB
MySQL
AI/ML
Claude
Copilot
Cursor
OpenAI Codex
Frontend
Angular
React.js
Tailwind CSS
Mobile
Dependency Injection
DevOps
AWS
AWS Lambda
CI/CD
OpenTelemetry
Rest API
Terraform
Amazon CloudWatch
Amazon S3
API Gateway
GitHub
Cybersecurity
HIPAA
Apply
SDET 1 day ago
$12k – $39k per year (Estimated) • In office • 4+ years exp • Gurgaon
Java
DevOps
AWS
Azure
CI/CD
Jenkins
QA
Appium
JMeter
Playwright
Rest-Assured
Selenium
Apply
$80k – $147k per year (Estimated) • Remote/Hybrid • Full-Time • Sydney
DevOps
CI/CD
Apply
$108k – $242k per year (Estimated) • Remote • Full-Time • 5+ years exp
C#
SQL
C#
.NET
Databases
MS SQL
RabbitMQ
AI/ML
ChatGPT
Claude
Claude Code
Copilot
Cursor
LLM
RAG
Model Context Protocol
DevOps
CI/CD
Git
GitHub
Apply
$40k – $107k per year (Estimated) • Remote • 5+ years exp • Tbilisi
C#
SQL
C#
.NET
Databases
MS SQL
RabbitMQ
AI/ML
ChatGPT
Claude
Claude Code
Copilot
Cursor
LLM
RAG
Model Context Protocol
DevOps
CI/CD
Git
GitHub
Apply
$171k – $326k per year (Estimated) • Equity • In office • 15+ years exp • Bachelor's Degree
DevOps
Platform Engineering
Cybersecurity
FedRAMP
SentinelOne
Apply
$22k – $55k per year (Estimated) • Equity • In office • Internship • 5+ years exp • Bengaluru
Python
TypeScript
DevOps
Jenkins
Cybersecurity
SentinelOne
QA
Playwright
Selenium
Apply
$152k – $275k per year (Estimated) • Equity • Remote • 10+ years exp
AI/ML
LLM
Prompt Engineering
LLM Guardrails
AI Agents
DevOps
CI/CD
Git
Progressive Delivery
SLI/SLO/SLA
Cybersecurity
FedRAMP
SentinelOne
Apply
Equity • Remote/Hybrid • 3+ years exp • Bachelor's Degree
Java
Python
TypeScript
Databases
Apache Kafka
AI/ML
Prompt Engineering
DevOps
AWS
CI/CD
Docker
GCP
Jenkins
Kubernetes
GitHub
GitLab
Cybersecurity
SentinelOne
QA
Playwright
Pytest
Apply
Equity • Remote/Hybrid • 3+ years exp • Bachelor's Degree • Brno
Java
Python
TypeScript
Databases
Apache Kafka
AI/ML
Prompt Engineering
DevOps
AWS
CI/CD
Docker
GCP
Jenkins
Kubernetes
GitHub
GitLab
Cybersecurity
SentinelOne
QA
Playwright
Pytest
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.