Full-Time

Threat Researcher

Detection Engineer, Windows OS / Mac OS

Posted on 10/17/2024

Sophos

Sophos

1,001-5,000 employees

Provides cybersecurity solutions for businesses

Cybersecurity

Junior, Mid

Remote in UK

Category
Cybersecurity
IT & Security
Required Skills
Redshift
Python
Data Science
SQL
Elasticsearch
Lua
Kibana
Requirements
  • Strong knowledge of Windows or MAC operating system, internals & forensic tools
  • Demonstrated programming experience. Preferred: Python, Lua, RegEx and/or SQL.
  • Excellent grasp of MITRE ATT&CK tactics, techniques & procedures in order to create simulation
  • Familiar with computational cost analysis & problem solving to minimize impact
  • Bachelor degree in Computer Software (Computer Security preferable)
  • Big data experience, Elastic Search, Kibana, Redshift
  • SDLC or CI/CD Knowledge is a plus
  • Bachelor’s degree in computer software (Computer Security preferable) or equivalent experience
Responsibilities
  • Understand malware kill chain and lifecycle & hands-on-keyboard attacks
  • Mapping TTPs to MITRE ATT&CK matrix
  • Accurate & efficient classification of malicious & suspicious behaviour
  • Author classification rules, for both Endpoint & Cloud scenarios, to identify malicious & suspicious use of TTPs
  • Analyse real world kill chains to discover new TTPs and gaps in coverage
  • Measure and tune TTP coverage through data mining, customer telemetry & internal sandbox feeds
  • Build & maintain playbooks on threat actor TTPs

Sophos provides cybersecurity solutions to protect businesses from digital threats like malware, ransomware, and phishing attacks. Their products include endpoint protection for individual devices, network security for entire systems, and mobile security for smartphones and tablets. A key feature is Sophos Central, a cloud-based management console that allows users to oversee all security measures from one platform, making it easier to manage and respond to threats. Additionally, Sophos offers Managed Detection and Response (MDR) services, where experts monitor and address security incidents for clients who may not have in-house capabilities. Unlike many competitors, Sophos focuses on an integrated approach to security, combining various services and products to enhance overall protection. The company's goal is to provide comprehensive security solutions that are accessible and effective for businesses of all sizes.

Company Stage

Acquired

Total Funding

$81.3M

Headquarters

Abingdon, United Kingdom

Founded

N/A

Simplify Jobs

Simplify's Take

What believers are saying

  • Sophos' recognition as a leader in multiple categories by G2 highlights its strong market position and credibility.
  • The company's strategic partnerships, such as with GAC Group, enhance its ability to deliver specialized cybersecurity solutions across various industries.
  • The appointment of Joe Levy as CEO and Jim Dildine as CFO signals a strong leadership team poised to drive future growth and innovation.

What critics are saying

  • The increasing complexity and frequency of ransomware attacks, as highlighted in their reports, could strain Sophos' resources and response capabilities.
  • The cybersecurity skills gap, particularly among Managed Service Providers (MSPs), could limit the effectiveness of Sophos' solutions and services.

What makes Sophos unique

  • Sophos offers a unified cloud-based management console, Sophos Central, which simplifies the management of multiple security solutions from a single platform, unlike many competitors who offer fragmented solutions.
  • Their Managed Detection and Response (MDR) services provide expert monitoring and incident response, a critical advantage for organizations lacking in-house cybersecurity expertise.
  • Sophos' comprehensive product suite, covering endpoint, network, and mobile security, positions it as a one-stop-shop for cybersecurity needs, unlike competitors who may specialize in only one area.

Help us improve and share your feedback! Did you find this helpful?

INACTIVE