Senior Security Research Engineer, SONAR (Security Operations and Novel Adversary Research)
Core
Reverse engineer novel malware, operate global data systems to identify threats, and build automated protections and tooling for Elastic Security customers.
Role type
Senior Security Research Engineer (Adversary Research)
Builds
Malware protections, detection signatures, automated investigation workflows, and public research artifacts.
Domain
Cybersecurity, Malware Analysis, Threat Intelligence
Deliverable
production ML models | product features
Required skills
Malware reverse engineering (static/dynamic), Python development, C/C++ reading, YARA authorship, Windows/Linux internals, Network protocols (HTTP/TLS), Applied cryptography, Technical writing
Preferred skills
Vulnerability research, CTF participation, Open-source security tool maintenance, Conference speaking, Attribution tradecraft, Behavioral detection engineering, Elastic Stack familiarity
Technologies
Python, C, C++, Rust, Go, NodeJS, YARA, Elasticsearch, Kibana, MISP, OpenCTI
Responsibilities
Reverse engineer undocumented malware across Windows/macOS/Linux; Analyze millions of endpoint data points to surface threats; Author detection signatures and build automation/AI workflows; Publish research and tools to public repositories; Collaborate on shared threat intelligence projects; Mentor junior researchers and lead technical investigations
Seniority
Senior, hands-on IC with mentorship responsibilities