Staff Threat Intelligence Engineer - SentinelLabs

Brno, South Moravian, Czech Republic

SentinelOne

SentinelOne vereint Endpoint, Cloud Identity und Datenschutz f in einer Lösung - die zusammen mit Security Data Lake für nahtlose und effiziente Cybersecurity ermöglicht.

View all jobs at SentinelOne

Apply now Apply later

About Us:

SentinelOne is defining the future of cybersecurity through our XDR platform that automatically prevents, detects, and responds to threats in real-time. Singularity XDR ingests data and leverages our patented AI models to deliver autonomous protection. With SentinelOne, organizations gain full transparency into everything happening across the network at machine speed – to defeat every attack, at every stage of the threat lifecycle. 

We are a values-driven team where names are known, results are rewarded, and friendships are formed. Trust, accountability, relentlessness, ingenuity, and OneSentinel define the pillars of our collaborative and unified global culture. We're looking for people that will drive team success and collaboration across SentinelOne. If you’re enthusiastic about innovative approaches to problem-solving, we would love to speak with you about joining our team!

What are we looking for?

We are looking for a Staff Threat Intelligence Engineer to join the SentinelLabs team. This role is designed for a highly skilled, self-directed engineer who excels in programming and analytical problem-solving. As a key developer of our threat intelligence tooling, you will work closely with a world-class team threat hunters and security researchers to produce innovative tools that automate, enhance, curate, and expand our team's capabilities. Your expertise will be pivotal in navigating various technology stacks and rapidly prototyping tools to codify threat hunting processes into a repeatable pipeline. The systems and tools you develop will be instrumental in enabling threat hunting, telemetry enrichment, and data curation, supporting diverse stakeholders across SentinelOne.

What will you do? 

As a Staff Threat Intelligence Engineer at SentinelLabs, your primary responsibilities will include:

  • Collaborating closely with threat hunters and security researchers to identify their needs, translating these into technical specifications for tool development
  • Developing and integrating tools with Vertex Synapse, incorporating external enrichments, custom internal tools, and existing power ups to meet research requirements
  • Rapidly prototyping and refining tools to ensure they effectively support threat hunting processes and are seamlessly integrated into a repeatable pipeline
  • Designing and implementing systems for telemetry enrichment and data curation to streamline the collection, analysis, storage, tagging, and enrichment of indicators of compromise and related data
  • Codifying threat hunting processes to maximize the value of diverse and unique data sources, meaningfully contributing to SentinelLabs threat research

What skills and knowledge should you bring?

  • Expertise working with threat intelligence platforms, particularly Vertex Synapse, with a strong understanding of how to leverage these platforms for data enrichment and threat intelligence automation
  • A solid understanding of threat hunting processes and the ability to codify these processes into repeatable, scalable pipelines that enhance the efficacy of threat research efforts
  • Strong analytical skills, capable of dissecting complex problems, synthesizing actionable information from diverse data sources, and finding opportunities for novel correlation
  • Experience in software development, with strong proficiency in Python and/or Go, especially in developing and maintaining tools for security applications
  • Comfort with rapidly prototyping and iterating on tools to ensure they meet the evolving needs of threat hunters and security researchers
  • Knowledge of security telemetry data management, including the collection, analysis, storage, tagging, and enrichment of indicators of compromise and associated data sources such as VirusTotal Intelligence/Stairwell, and types like passive DNS, netflow, and scanning
  • Excellent communication and collaboration skills, able to work effectively with cross-functional teams and surmise technical requirements from diverse stakeholders

Why Us?

You will work on real-world problems and make an impact by protecting our customers from cyber threats. You will be joining a cutting-edge project and will be able to influence the architecture, design, and structure of our core platform. You will tackle extraordinary challenges and work with the very BEST in the industry.

On top of that we offer you

  • Flexible working hours, In Prague & nearby we're working in a hybrid model with offices in Karlin, remotely in the rest of CZ or SK, with optional Brno offices (Clubco Vlněna) for those who like to meet
  • Generous employee stock plan in the form of RSUs (restricted stock units) grant not options; 4 years vesting with 1-year cliff and then quarterly
  • Yearly bonus depending on the performance of the company, paid out in 2 installments
  • Flexible Time Off (on top of the standard 5 weeks of vacation)
  • Flexible Paid Sick Days
  • Fully Paid Short Term Sick/Short Term Nursing Leave
  • Global gender-neutral Parental Leave (16 weeks, beyond the leave provided by the local laws) & Grandparent Leave
  • Volunteering paid day off & Additional paid Company holidays off (e.g. 4 days in 2022)
  • Pension insurance contribution
  • Premium Life Insurance covered by S1
  • Monthly Meal & Wellbeing Allowance
  • Private medical care membership (English speaking) for you and your +1
  • Global Employee Assistance Program (confidential counseling related to both personal and work life matters), Wellness Coach:Mind Body Sleep app company access (sessions, audiobooks, classes, private coaching etc.)
  • High-end MacBook or Windows laptop, Home-office-setup gear & on top of that additional WFH Allowance
  • LinkedIn Learning platform for Hard/Soft skills Training, internal mentoring 'MentorOne' & Support for your further educational activities/trainings
  • Above-standard referral bonus
  • On top of RSUs, you can benefit also from our attractive ESPP (employee stock purchase plan)
  • Refreshments and snacks at the offices
  • Optional company events for those who like to meet outside of work too (sport, BBQ, charity etc.)
  • DEI&B programs that promote employee resource groups like SentinelWIN (Women Inclusion Network), Blk@S1, Latinos@S1, Pan-Asian@S1, Out@S1 (LGBTQIA+) and Sentinels Who Served

SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

SentinelOne participates in the E-Verify Program for all U.S. based roles. 

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0

Tags: Automation DNS Prototyping Python Threat intelligence Threat Research VirusTotal Windows XDR

Perks/benefits: Career development Equity / stock options Flex hours Flex vacation Gear Health care Home office stipend Insurance Medical leave Parental leave Salary bonus Team events Transparency Wellness

Region: Europe
Country: Czechia

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.