More jobs:
Job Description & How to Apply Below
By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic’s complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI.
What is
The Role:
The Elastic Security Endpoint Protections team researches, designs, and builds the visibility and prevention capabilities at the core of Elastic Defend, our endpoint and SIEM security solution. We are looking for a Senior Security Research Engineer to help lead our efforts to build innovative features that secure our users against the latest emerging threats. You will collaborate with the broader Elastic Security team, a diverse group of skilled researchers, data scientists, and engineers who bring deep domain knowledge in their respective areas.
Our geographically dispersed team values positivity and inclusivity in the workplace, clear communication, collaborative learning, and guided mentorship.
We don't just claim our protections work. In recent third-party enterprise protection testing, Elastic Security earned a perfect malware protection score with zero false alarms, the top result in the field. If you have a passion for security research and would enjoy the challenge of devising novel methods for thwarting malicious actors in an ever-evolving threat landscape, join our growing team!
Elastic believes that employees should have the opportunity to share in the value that we create together for our shareholders. Therefore, in addition to cash compensation, this role is currently eligible to participate in Elastic's stock program. Our total rewards package also includes a company-matched Registered Retirement Savings Plan (RRSP) with dollar-for-dollar matching up to 6% of eligible earnings, along with a range of other benefits offered with a holistic emphasis on employee well-being.
What You Will Be Doing:
Research emerging attacker techniques and turn them into shipped protections. Study real-world tradecraft across in-memory threats, injection, credential theft, ransomware, and kernel tampering, then design protections that hold up against an adversary actively trying to defeat them.
Build and extend endpoint visibility. Instrument new event sources across Windows, macOS, and Linux, deepen the telemetry we already collect, and close the gaps attackers rely on. Every source you add becomes a foundation for other teams.
Develop production code that runs everywhere. Write performant, stable C/C++ that executes on millions of endpoints, where a memory leak or a few milliseconds of overhead is a customer-visible problem.
Reverse engineer malware and study evasion. Learn how attackers bypass endpoint security controls in the wild, and feed that understanding directly into the protections you design and harden.
Own efficacy end to end. Review customer telemetry at fleet scale, investigate false positives and performance regressions, and establish mitigation strategies. Shipping the feature is the beginning of the job, not the end.
Extend protection parity across platforms. Bring the depth we have on Windows to macOS and Linux, and support new hardware architectures as they reach the enterprise.
Collaborate across Elastic Security. Implement endpoint code alongside peers in multiple countries and time zones, and work with the detection engineers, malware…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×