Threat Hunter; Romania
Listed on 2026-02-23
-
IT/Tech
Cybersecurity
Location: Romania
About Us
Sophos is a global leader and innovator of advanced security solutions for defeating cyberattacks. The company acquired Secureworks in February 2025, bringing together two pioneers that have redefined the cybersecurity industry with their innovative, native AI-optimized services, technologies and products. Sophos is now the largest pure‑play Managed Detection and Response (MDR) provider, supporting more than 28,000 organizations. In addition to MDR and other services, Sophos’ complete portfolio includes industry‑leading endpoint, network, email, and cloud security that interoperate and adapt to defend through the Sophos Central platform.
Secureworks provides the innovative, market‑leading Taegis XDR/MDR, identity threat detection and response (ITDR), next‑gen SIEM capabilities, managed risk, and a comprehensive set of advisory services. Sophos sells all these solutions through reseller partners, Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) worldwide, defending more than 600,000 organizations worldwide from phishing, ransomware, data theft, other everyday and state‑sponsored cybercrimes.
The solutions are powered by historical and real‑time threat intelligence from Sophos X‑Ops and the newly added Counter Threat Unit (CTU). Sophos is headquartered in Oxford, U.K. More information is available at
We are seeking a detail‑oriented and technically skilled Threat Hunter to join our dedicated threat hunting team. In this role, you will be responsible for proactively defending customer environments before attacks prevail, by using a variety of tools and techniques to gather, classify, enrich, and tune suspicious activity. To accomplish this, you must be able to research, evaluate, and stay current on emerging tools, techniques, and technologies.
You are expected to act as a mentor, working side‑by‑side with other personnel in an advisory, support, and training role to enhance security effectiveness & efficiency of the Security Operations Center (SOC). They will be leading security thought & innovation both internally to Sophos and across the industry.
- Review telemetry and hunting leads from various sources and determine whether they are benign or warrant further investigation.
- Propose new countermeasures or updates to detect advanced threats and reduce signal‑to‑noise ratio.
- Conduct threat hunts across the MDR Elite customer base using a variety of tools and methodologies.
- Communicate and document findings to various customer audiences, including technical and executive teams.
- Actively research emerging Indicators of Compromise/Attack, threat actor TTPs, exploits, and vulnerabilities.
- Assume ownership in problem resolution, striving for customer satisfaction.
- Proactively work to document and minimize operational and client‑impacting issues that arise during day‑to‑day operations, develop innovative and creative recommendations that improve customer outcomes.
- Provide mentorship to junior teammates, guiding their career development.
- Actively contribute to internal projects per assignments received from the manager in alignment with own knowledge, skills, and workload.
- 5–8 years of relevant experience or equivalent combination of education and work experience.
- Thorough understanding of Threat Hunting methodologies.
- Familiarity with Python, Python data science libraries and Jupyter Notebooks.
- Knowledge of common and new adversarial attack methods, tactics and techniques.
- Endpoint and network security experience required; IDS, IPS, EDR, ATP, malware defenses and monitoring experience.
- Bachelor’s in information technology, Computer Science or a related field; or relevant commensurate work experience.
- Excellent written and verbal communication skills with both technical and non‑technical individuals.
- Self‑initiative and ability to successfully manage your time to meet the various demands of the role with minimal leadership oversight.
- Preferred certifications: GCIA, GCFE, GCFA, OSCP or equivalent.
At Sophos, we believe in the power of diverse perspectives to fuel innovation. Research shows that candidates sometimes…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).