368,746open jobs
9,444companies
47,506added this week
Browse all
Salary
$92k – $188k per year (Estimated)
Location
Remote (United Kingdom)
Seniority
Senior
Employment
Full-Time
Overview
Company
Impact
Profile match
Sophos is a global leader in cybersecurity, providing businesses and individuals with a comprehensive range of solutions to protect against a wide range of cyber threats. Our products include endpoint protection, network security, and cloud security. Sophos is committed to providing our customers with the highest level of security and protection, and we are always innovating to stay ahead of the latest threats.

Role Summary

The X-Ops Insights team sits inside the Security organization, reporting to the CISO. As threat actors become more organized and AI reshapes the security landscape, we need a senior researcher who can operate at the intersection of applied AI, threat intelligence, and cyber operations-someone who can both advance what we know and change how we work.

This is a senior individual contributor role for a researcher who lives at the frontier of AI and cybersecurity. Your primary mission is to research how threat actors are adopting, weaponizing, and exploiting AI; from LLM-powered social engineering and automated vulnerability discovery to real-world attacks against agentic AI implementations. You'll help instrument telemetry to detect adversarial use of AI in the wild, assess emerging risks as AI capabilities evolve, and produce research that keeps Sophos and the broader security community ahead of the curve. As a domain expert in AI threats, you'll also be expected to help drive operational efficiencies across the Insights team, bringing the tools and techniques you research into our own workflows. You’ll report to the Sr. Manager, Threat Research and work alongside CTU researchers, SophosLabs malware analysts, MDR threat hunters, incident responders, engineering teams, and data scientists.

What You Will Do

    Research & Analysis

  • Investigate how threat actors are leveraging AI across the attack lifecycle, including: AI assisted social engineering, AI-generated malware, automated reconnaissance, and adversarial attacks against ML-based defenses.
  • Research real-world threats to agentic AI systems, AI supply chains, and enterprise AI deployments, assessing risk and developing detection strategies.
  • Help instrument and tune telemetry to identify indicators of AI-driven attacker behavior at scale.
  • Analyze global telemetry, case data, and OSINT to surface emerging AI-related threat trends and early-warning indicators.
  • Automation & Efficiency

  • As a practitioner of the technology you research, identify opportunities to automate repetitive research and reporting workflows using LLMs, scripting, and internal tooling.
  • Help the team evolve its operating model as new AI capabilities become available.
  • Cross-Functional Collaboration
  • Work closely with CTU researchers, SophosLabs analysts, MDR threat hunters, data
  • scientists, and engineering teams to synthesize findings into unique reporting with actionable intelligence.
  • Contribute to the joint task-force intelligence cycle, ensuring insights flow rapidly into protections, detection rules, and operational systems.
  • Content & Publication

  • Produce high-quality written intelligence outputs, including deep-dive research, rapid
  • analyses, and strategic forecasting.
  • Author work that is suitable for external publication via Sophos blogs, industry reports,
  • and conference presentations.
  • Present findings to internal stakeholders, external partners, and the broader security
  • community.

What You Will Bring

    Required Qualifications

  • Ability to interpret data from diverse telemetry sources and transform it into actionable

    intelligence.

  • Exceptional written communication skills suitable for both technical and executive

    audiences.

  • Demonstrated experience in at least two of the following: threat intelligence, malware analysis, detection engineering, or AI/ML research.
  • Strong knowledge of threat actor ecosystems, modern attack techniques, and the MITRE ATT&CK framework.
  • Hands-on proficiency with Python and modern AI development patterns, including building and orchestrating multi-agent systems, working with LLM APIs, and designing agentic workflows with sub-agents, tool use, and retrieval-augmented generation.
  • Experience building or using automation tools to streamline analytical or reporting

    workflows.

  • Preferred Qualifications

  • Experience working in MDR, incident response, or real-time security operations environments.
  • Prior authorship of externally published threat research (blogs, reports, conference presentations).
  • Experience with LLMs, prompt engineering, or building AI-assisted analytical tools.
  • Familiarity with large-scale telemetry pipelines, security data lakes, or SIEM/SOAR platforms.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,746 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
Equity • Remote/Hybrid • Part-Time • Bachelor's Degree • Tel Aviv
Python
SQL
AI/ML
AI Agents
Marketing
Salesforce
Apply
Equity • Remote/Hybrid • Part-Time • Master's Degree • Tel Aviv
Python
SQL
AI/ML
AI Agents
Claude
Copilot
Cursor
Scikit-learn
SHAP
XGBoost
Analytics
ETL/ELT
Marketing
Salesforce
Apply
$170k – $318k per year (Estimated) • Remote/Hybrid • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
JavaScript
Python
TypeScript
Python
pySpark
AI/ML
Prompt Engineering
Spark
DevOps
AWS
Azure
CI/CD
GCP
Git
Jenkins
GitHub
GitLab
Analytics
ETL/ELT
Apply
$47k – $103k per year (Estimated) • In office • Full-Time • 18+ years exp • Gurgaon
AI/ML
LLM
Apply
$20k – $49k per year (Estimated) • In office • Full-Time • 3+ years exp • Mumbai
Python
Apply
Remote • Full-Time • 5+ years exp
PowerShell
Python
SQL
DevOps
Splunk
Cybersecurity
MITRE ATT&CK
Sophos
Apply
$27k – $72k per year (Estimated) • Remote • Full-Time • 12+ years exp
Go
Java
TypeScript
JavaScript
AI/ML
AI Agents
LLM Guardrails
Frontend
Angular
React.js
DevOps
AWS
Cybersecurity
Sophos
Apply
$27k – $61k per year (Estimated) • Remote • Full-Time • 7+ years exp
PowerShell
SQL
Node JS
JavaScript
Node JS
Commander.js
Cybersecurity
MITRE ATT&CK
osquery
Sophos
Velociraptor
Apply
$98k – $192k per year (Estimated) • Remote • Full-Time • 7+ years exp
JavaScript
TypeScript
AI/ML
Claude
Frontend
Angular
React.js
DevOps
Amazon EC2
Amazon EKS
AWS
AWS Lambda
Kubernetes
Amazon CloudWatch
Amazon ECS
Amazon S3
Cybersecurity
Sophos
Apply
Infosec Engineer 14 days ago
$17k – $44k per year (Estimated) • Remote • Full-Time • 1+ year exp • Bachelor's Degree
Cybersecurity
Sophos
Apply
See all jobs
This is one of many
368,746 more open roles from verified company boards, updated every day.