Senior Threat Researcher – Behavioral Protection
Listed on 2026-06-03
-
Security
Cybersecurity, Data Security
Role Summary
We are seeking a skilled and passionate Threat Researcher with deep expertise in Windows based threat behaviors, particularly having a strong understanding on memory-resident threats. In this role, you will be at the forefront of detecting and understanding emerging attack techniques, developing behavioral-based protection strategies, and enhancing our real-time protection capabilities. Your insights and contributions will directly impact on the security posture of millions of users worldwide.
WhatYou Will Do
- Analyze malware behaviors aligned with MITRE ATT&CK TTPs (and beyond), covering the full attack lifecycle, including initial access vectors, execution techniques, payload delivery—with a strong focus on in-memory techniques, fileless malware, and evasive behaviors.
- Research and identify behavioral techniques employed by novel and sophisticated Advanced Persistent Threats (APTs) and translate these insights into effective behavioral protection rules to enhance prevention capabilities.
- Drive protection coverage for zero-day malware and novel attack techniques.
- Work independently with minimal supervision while managing priority protection tasks.
- Review and provide actionable feedback on detection logic and code developed by fellow researchers.
- Collaborate with the team to define clear protection priorities and deliver updates to customers in a timely manner.
- Produce quality threat analysis reports for both internal and external audience.
- Proven hands-on experience in Windows based malware analysis using both static and dynamic analysis tools such as using IDAPro and Windbg.
- Deep understanding of behavioral techniques, memory injection methods, persistence mechanisms, and evasion tactics.
- Ability to write robust, high-quality behavioral protection rules.
- Demonstrated programming experience, preferably Python, Lua.
- Experience working in a fast-paced threat research or security operations environment.
- Strong communication skills and the ability to provide technical mentorship to peers.
- Proactive, self-driven mindset with the ability to lead in critical incident or zero-day response scenarios.
In Canada, the base salary for this role ranges from $129,000 to $215,000. In addition to base salary, we offer additional compensation including bonus eligibility and a comprehensive benefits package. A candidate’s specific pay within this range will depend on a variety of factors, including job- related skills, training, location, experience, relevant education, certifications, and other business and organizational needs.
Data ProtectionIf you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights.
For more information on Sophos’ data protection practices, please consult our Privacy Policy.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: