368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$77k – $175k per year (Estimated)
Location
Remote (United Kingdom)
Seniority
Senior
Employment
Full-Time
Overview
Company
Impact
Profile match
Sophos is a global leader in cybersecurity, providing businesses and individuals with a comprehensive range of solutions to protect against a wide range of cyber threats. Our products include endpoint protection, network security, and cloud security. Sophos is committed to providing our customers with the highest level of security and protection, and we are always innovating to stay ahead of the latest threats.

Role Summary

We are seeking a detail-oriented and technically skilled Detection Engineer to join our X-OPS team. In this role, you will be responsible for analyzing advanced security threats-ranging from malware to complex web attacks-and translating threat intelligence into high-fidelity detections across our platform. Your work will help ensure our analysts and clients receive highly accurate, actionable alerts with minimal noise.

You will leverage data from over 40 third-party and internal sources, partner with our CTU Threat Intelligence team, and use a range of scripting and automation tools to strengthen detection capabilities. The ideal candidate is a hands-on security practitioner with a deep understanding of endpoint behavior, cloud behavior, and detection development who thrives in fast-paced, technical environments.

What You Will Do

  • Develop countermeasures to detect advanced threats based on research and intelligence from the CTU team.
  • Analyze endpoint behaviors and logs to design detections using multi-source telemetry.
  • Continuously refine and monitor detection rules to optimize the signal-to-noise ratio for alerts.
  • Research and implement alert handling for new device ingestions, ensuring high-value signal delivery.
  • Leverage internal tooling to distinguish native from standard integrations for detection accuracy.
  • Collaborate on the development of internal tools, automation, and detection infrastructure.
  • Act as a subject matter expert across departments including Product Management, Marketing, and Labs Research.

What You Will Bring

  • Strong passion for cybersecurity research and the ability to quickly learn emerging technologies.
  • Hands-on experience in scripting languages (PowerShell, Bash, Python) and use of Python data science libraries (e.g., NumPy, Pandas, Matplotlib).
  • Knowledge of CI/CD pipelines, testing frameworks, and automation principles.
  • Proficiency in analyzing logs from firewalls, proxies, and security infrastructure to identify anomalies.
  • Familiarity with event logs, traffic pattern anomalies, and threat hunting methodologies.
  • Strong understanding of endpoint detection, Linux/Unix and Windows OS internals, vulnerability identification, and workflow automation.
  • Forensic analysis of memory and disk images across various OS and file system types is a plus.
  • Experience in malware analysis, including static/dynamic techniques and reverse engineering (IA32/64, ARM binaries) is a plus.
  • Experience with event correlation and incident reconstruction using log data is a plus.
  • Network traffic analysis skills, including identification of anomalous or malicious traits is a plus.
  • Solid grasp of database querying, systems architecture, and process automation for operational improvements is a nice to have.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$184k – $307k per year • Remote • Full-Time • PhD • United States
DevOps
CI/CD
Apply
$137k – $229k per year • Remote • Full-Time • PhD • United States
AI/ML
Human-in-the-Loop
DevOps
CI/CD
Apply
$220k – $350k per year • Remote/Hybrid • Full-Time • 15+ years exp • New York • Princeton
AI/ML
AI Agents
LLM Guardrails
Model Context Protocol
DevOps
Azure
Azure DevOps
CI/CD
GitHub
Platform Engineering
Design
Figma
Management
Jira
QA
Playwright
Apply
$80k – $175k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Toronto
AI/ML
Text-to-Speech
DevOps
CI/CD
Apply
ML/AI Developer 1 hour ago
$65k – $140k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Toronto
AI/ML
Text-to-Speech
DevOps
CI/CD
Apply
Remote • Full-Time • 5+ years exp
PowerShell
Python
SQL
DevOps
Splunk
Cybersecurity
MITRE ATT&CK
Sophos
Apply
$27k – $72k per year (Estimated) • Remote • Full-Time • 12+ years exp
Go
Java
TypeScript
JavaScript
AI/ML
AI Agents
LLM Guardrails
Frontend
Angular
React.js
DevOps
AWS
Cybersecurity
Sophos
Apply
$27k – $61k per year (Estimated) • Remote • Full-Time • 7+ years exp
PowerShell
SQL
Node JS
JavaScript
Node JS
Commander.js
Cybersecurity
MITRE ATT&CK
osquery
Sophos
Velociraptor
Apply
$98k – $192k per year (Estimated) • Remote • Full-Time • 7+ years exp
JavaScript
TypeScript
AI/ML
Claude
Frontend
Angular
React.js
DevOps
Amazon EC2
Amazon EKS
AWS
AWS Lambda
Kubernetes
Amazon CloudWatch
Amazon ECS
Amazon S3
Cybersecurity
Sophos
Apply
Infosec Engineer 14 days ago
$17k – $44k per year (Estimated) • Remote • Full-Time • 1+ year exp • Bachelor's Degree
Cybersecurity
Sophos
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.