Sr. Threat Hunter
Czech Republic
SentinelOne
SentinelOne vereint Endpoint, Cloud Identity und Datenschutz f in einer Lösung - die zusammen mit Security Data Lake für nahtlose und effiziente Cybersecurity ermöglicht.About Us:
SentinelOne is defining the future of cybersecurity through our XDR platform that automatically prevents, detects, and responds to threats in real-time. Singularity XDR ingests data and leverages our patented AI models to deliver autonomous protection. With SentinelOne, organizations gain full transparency into everything happening across the network at machine speed – to defeat every attack, at every stage of the threat lifecycle.
We are a values-driven team where names are known, results are rewarded, and friendships are formed. Trust, accountability, relentlessness, ingenuity, and OneSentinel define the pillars of our collaborative and unified global culture. We're looking for people that will drive team success and collaboration across SentinelOne. If you’re enthusiastic about innovative approaches to problem-solving, we would love to speak with you about joining our team!
What are we looking for?
Join SetinelOne’s elite professional services division by becoming part of our proactive threat hunting program. Our Threat Hunters serve our clients by utilizing the SentinelOne platform to identify potential malware, malicious behavior, insider threats, and security hygiene issues that exist within client environments.
The Hunters’ goal is to identify threats, disrupt attacks prior to further damage occurring within a client environment, and advise for remediation as well as long-term security posture improvement. Incumbent will be responsible for identifying attack trends and threat intelligence by harvesting threat data generated by several million endpoints from across the globe.
This is an exciting opportunity to join a growing team of industry renowned experts dedicated to providing the highest level of security service to our clients.
What will you do?
- Conduct proactive threat hunting services for SentinelOne clients
- Build, evolve, and expand hunting tooling, techniques and use-cases
- Integrate relevant threat intelligence and dark web data into hunting operations
- Advise engineering team on platform enhancements to further enable rapid and effective threat hunting
- Work closely with clients to remediate threats and improve long-term security posture
What experience or knowledge should you bring?
- At least 5 years experience in cyber security relevant roles like security engineering, SOC operations, system administration, digital forensic investigations, penetration testing, red teaming, threat intelligence, network threat hunting, or malware analysis
- Experience in threat hunting via endpoint focused threat hunting
- Strong knowledge in Python scripting, including:
- API integration
- DB integration
- data manipulation
- Multiprocessing
- Working knowledge of git
- Working knowledge on utilising CTI tools for data enrichment
- Working experience with GCP and Amazon Cloud solutions
- Experience with working under Scrum regime
- Ability to create code with the best Python practices
- Ability to work with large datasets to get valuable and vital information
- Strong understanding of common malware activity on endpoints
- Knowledge of MITRE ATT&CK framework and known APT group activity
- Operating system internals knowledge (Windows, Linux, OSX)
- Experience utilizing EDR technologies
- Experience with working with Cyber threat Intelligence tools and data
- Knowledge of OSINT tools and techniques
Why us?
- Generous RSUs (Restricted Stock Units) and ESPP (Employee Stock Purchase Programme) available
- Annual bonus based on your performance, paid out in 2 instalments
- Flexible time off on top of the standard 5 weeks of vacation
- Flexible paid sick days and fully paid short term sick and short term nursing leave
- Global gender-neutral parental leave (16 weeks, beyond the leave provided by the local laws) and grandparent leave
- Volunteering paid day off and additional paid company-wide days off (e.g. 4 days in 2022)
- Premium life insurance, private medical care and pension insurance contribution
- Meal & Wellbeing Allowances
- Global Employee Assistance Program, including confidential counselling related to both personal and work life matters
- High-end MacBook, or Windows laptop, home-office-setup gear and a work-from-home allowance
- Full access to LinkedIn Learning, an e-learning platform
- Refreshments and snacks at the offices
- Optional company events for those who like to meet outside of work (sports days, BBQs, charity events, etc.)
- Above-standard referral bonus
SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
SentinelOne participates in the E-Verify Program for all U.S. based roles.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: APIs APT Cloud EDR GCP Linux Malware MITRE ATT&CK OSINT Pentesting Python Red team Scripting Scrum SOC Threat intelligence Windows XDR
Perks/benefits: Career development Equity / stock options Flex hours Flex vacation Gear Health care Home office stipend Insurance Medical leave Parental leave Salary bonus Team events Transparency
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.