Senior Malware Detection Engineer
India
- Posted 2mo ago
- From SentinelOne’s careers page
- Location
- India
- Level
- Senior
- Experience
- 5+ years
- Department
- Research and Development (R&D)
This role is no longer on SentinelOne’s careers page. See 65 open roles
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Our Purpose
At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them becomes more critical than ever. When you join SentinelOne, your work helps protect global enterprises, critical infrastructure, and the technologies shaping tomorrow.
About Us
SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response with clarity and speed.
Our teams are builders, problem-solvers, and innovators committed to shaping the future of security.
What Are We Looking For?
We are looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member to build fluency in AI tools and concepts.
As a Senior Malware Detection Engineer with deep expertise in Linux and macOS, you are someone who analyzes and breaks things to understand how they work, and who is driven to outsmart malware to protect our customers.
What Will You Do?
Primary responsibilities include:
- Research: perform in-depth reverse engineering and analysis of Linux and macOS threats, TTPs, exploits, and malware, including ELF and Mach-O binaries, shell/script-based malware, and software supply-chain and malicious open-source packages, to close detection gaps.
- Research: analyze endpoint telemetry alongside binaries and samples to validate detections, hunt telemetry, and prioritize coverage for emerging malware families.
- Research: share findings with other detection teams and collaborate across internal and external groups.
- Development: own detection coverage end to end, including writing and maintaining detection assets and being accountable for FP/FN quality, efficacy, and performance.
- Development: design and maintain CI/testing infrastructure used to build, test, and ship detection content.
- Development: build tooling for rule performance, coverage, and FP/FN trends, increasingly leveraging AI/LLM-assisted pipelines.
- Development: respond quickly to emerging threats and customer malware escalations.
- Development: support detection coverage validation against BAS (Breach and Attack Simulation) frameworks.
- Development: mentor engineers on Linux/macOS malware analysis and detection engineering practices.
- You will also be encouraged to write whitepapers, blogs, and articles.
What Skills and Knowledge Will You Bring?
Ideal candidates will have:
- A dedication to continuous learning and skill development.
- 5+ years of experience in static and dynamic malware analysis and reverse engineering, with proven depth on Linux and working knowledge of macOS (or vice versa).
- Proficiency with reverse engineering tools such as IDA, Ghidra, Hopper, LLDB, and GDB.
- Strong background in malware behavior, including anti-tampering, defense evasion, lateral movement, persistence, and ransomware activity.
- Good understanding of MITRE ATT&CK TTPs.
- A strong inclination toward automating routine analysis and detection workflows.
- Excellent understanding of Linux (user-mode and kernel-mode), including processes and threads, IPC, tracing (including eBPF), security, and virtual memory.
- Understanding of containers and Kubernetes, including container escape and cloud-native attack techniques.
- For macOS: understanding of ARM64/Apple Silicon architecture, sandbox and TCC internals and escapes, and security mechanisms such as File Quarantine, XProtect, and Gatekeeper.
- Programming experience in Assembly, C/C++, Objective-C (for macOS), and Python.
- Experience creating production detection rules using YARA/plist or similar engines.
Preferred / Advantages (one or more)
- Exposure to AI/LLM-assisted reverse engineering or detection-authoring tooling.
- Good understanding of AV/EDR/EPP internals and detection mechanisms.
- Experience building CI/CD pipelines (Jenkins, GitHub Actions, or similar) for shipping detection content.
- Familiarity with attack simulation frameworks (BAS) and their TTPs.
- Experience querying large-scale telemetry (SQL, EventDB/DataSet, Redash, or similar) to validate detections.
Why SentinelOne?
AI is redefining how the world operates and rewriting the rules of security in real time. From day one, SentinelOne architected an AI-native platform designed to operate at machine speed.
We invest in our Sentinels with comprehensive, competitive benefits, including:
Equity & Rewards
- Restricted Stock Units (RSUs)
- Employee Stock Purchase Plan (ESPP)
Time Off & Wellbeing
- Competitive leave benefits
- Gender-neutral parental leave
Insurance & Financial Security
- Medical and insurance benefits
- Employee Assistance Program (EAP)
Work Perks & Flexibility
- Global home office allowance
- Internet allowance
- LinkedIn Learning license
- Social Connect program
- Food allowance (Bangalore office)
- Meal vouchers (Sodexo)
Wellness & Lifestyle
- Health & wellness benefit
SentinelOne is an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
SentinelOne participates in the E-Verify Program for all U.S. based roles.
Skills they ask for
Pick one to see other roles that ask for it.
About SentinelOne
Autonomous cybersecurity for enterprisesSentinelOne provides cybersecurity software for endpoint, cloud and identity protection, threat detection and automated response.
See all 66 roles at SentinelOneMore roles at SentinelOne
See all 66- Sr. Director, Sales Systems & ProcessesUnited States · Director · RemoteSales · Director · RemoteUnited States9h
- Marketing InternBengaluru · InternMarketing · InternBengaluru, India1d
- Senior MSSP Partner Contracts ManagerUnited States · Senior · RemoteSales · Senior · RemoteUnited States2d
- MSSP Project ManagerUnited States · RemoteSales · RemoteUnited States2d
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.