Full-Time

Senior Threat Behavior Researcher

Sophos

Sophos

5,001-10,000 employees

Subscription-based cybersecurity for endpoints, networks, MDR

No salary listed

Remote in UK

Remote

Remote-first role; some positions may require hybrid work. Must have legal authorization to work in the United Kingdom.

Bachelor's

Category
IT & Security (1)
Required Skills
Malware Analysis
Python
WinDBG
Lua

Get referred to Sophos

See people who can refer or advise you

Requirements
  • Strong knowledge of Windows Internals including Memory management, Processes, Threads.
  • Proficiency in both static and dynamic analysis of threats, using tools such as IDAPro, WinDbg.
  • Demonstrated programming experience. Preferred: Python, Lua.
  • Excellent communication skills with the ability to demonstrate complex technical problem to peer researchers as well as to product engineering team.
  • Excellent analytical and problem-solving skills with the ability to think strategically and creatively.
  • Bachelor’s degree in computer software (Computer Security preferable) or equivalent experience.
Responsibilities
  • Conduct in-depth behavioral analysis of Windows threats.
  • Develop Behavioral rules for various threat behaviors including hands-on keyboard attack, malware payloads, initial attack vectors and Advanced Persistent Threats (APTs).
  • Produce quality threat analysis reports for both internal and external audience.
  • Assist in sandbox improvements by analyzing malware that hinders the sandbox environment in running the threat, which deploys various anti-analysis techniques.
  • Develop Cleanup rules to remove artifacts that are left behind by the behavioral protection rules.
  • Collaborate with other cross-functional teams to improve behavioral protection capability based on the threat analysis.
  • Guide and train junior team members in assisting malware analysis, peer code review.
  • Assist in the development of tools wherever necessary to improve day-to-day task.
Desired Qualifications
  • Python
  • Lua

Sophos provides cybersecurity solutions for businesses, covering endpoint, network, and mobile security, with a cloud-based management console called Sophos Central. Its products protect devices, networks, and mobile endpoints, and include Managed Detection and Response (MDR) where experts monitor and respond to threats. The company differentiates itself by offering an integrated, single-vendor security stack—covering endpoint, network, and mobile protection—managed from one platform. Its goal is to help organizations prevent digital threats while simplifying security operations.

Company Size

5,001-10,000

Company Stage

Acquired

Total Funding

$208.6M

Headquarters

Abingdon, United Kingdom

Founded

1985

Get referred to Sophos

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Sophos Fusion GA on August 15, 2026 removed product uncertainty.
  • OpenAI partnership and AI Defense strengthen channel demand for August 2026.
  • August 10, 2026 promotions installed Milan Patel and Lisa Moorhead to accelerate execution.

What critics are saying

  • Sophos faces a March 2027 refinancing on $2.1 billion of debt.
  • Thoma Bravo refused new equity, forcing lender concessions and tighter covenants.
  • If lenders balk, Sophos needs a restructuring before March 2027.

What makes Sophos unique

  • Sophos Fusion unifies endpoint, SIEM, MDR, and XDR on one data layer.
  • Secureworks Taegis powers Sophos XDR, adding thousands of detectors and playbooks.
  • Sophos sells through 25,000 partners, including 7,000 MSPs, reaching 625,000 organizations.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Disability Insurance

Remote Work Options

Wellness Program

Mental Health Support

Growth & Insights and Company News

Headcount

6 month growth

14%

1 year growth

14%

2 year growth

14%
GFM Limited
Aug 19th, 2026
Thoma Bravo considers lender-friendly terms in $2bn Sophos refinancing.

Thoma Bravo considers lender-friendly terms in $2bn Sophos refinancing. * August 19, 2026 * - 9:26 am Thoma Bravo-backed cybersecurity company Sophos is turning to its existing leveraged-loan lenders as it seeks to refinance or extend more than $2bn of debt, after attempts to secure private credit financing failed to gain traction, according to a report by Bloomberg. The company could offer investors more attractive terms, including a higher interest coupon, additional amortisation and tighter financial covenants, according to people familiar with the discussions. A transaction could be launched as soon as next month, although the terms remain under negotiation and could change. Thoma Bravo, which acquired Sophos in 2020, has indicated that it does not intend to provide additional equity capital as part of the refinancing, despite some lenders raising concerns about the impact of artificial intelligence on the software business, the people said. Sophos has been working for several months on the refinancing of a $2.1bn term loan due in March 2027. Several private credit investors previously declined to participate despite being offered a substantial increase in yield. The company is now hoping that improved operating performance will help attract support from the syndicated loan market. Sophos reported 6% year-on-year growth in annual recurring revenue for the three months to the end of June, while adjusted EBITDA increased 10% to around $120m. Its term loan has also recovered from levels seen during the sharp sell-off in software credit earlier this year. The debt was recently trading at about 96.88 cents on the dollar, compared with 92.69 cents in February. The refinancing represents another important test for Thoma Bravo, one of private equity's largest software-focused investors, as lenders continue to scrutinise the sector's vulnerability to AI-driven disruption. The firm was forced to offer significant concessions to lenders last month to complete a roughly $5bn refinancing for another portfolio company, Proofpoint. Thoma Bravo's software exposure has also come under pressure following the loss of control of customer-experience software provider Medallia, after creditors took over the company earlier this year. Sophos' effort to return to the broadly syndicated loan market therefore comes at a sensitive point for the sponsor and the wider software buyout sector. The willingness of lenders to accept revised terms without fresh sponsor equity is likely to be closely watched as investors assess refinancing risk across highly leveraged technology companies.

Tech in Asia
Aug 19th, 2026
UK cybersecurity firm Sophos weighs $2b debt refinancing.

UK cybersecurity firm Sophos weighs $2b debt refinancing. Thoma Bravo-backed Sophos, a UK-based cybersecurity software company, is in talks with existing lenders to refinance or extend more than US$2 billion of debt as soon as next month after efforts to secure private credit support faltered, according to people familiar with the matter. The talks cover Sophos' US$2.1 billion term loan due in March 2027 and a revolving credit facility. The company could offer a higher coupon, amortization payments, and tighter covenants to win lender support, the people said. Thoma Bravo has indicated it does not plan to inject fresh capital, they added. Sophos was taken private by Thoma Bravo in March 2020 in a cash deal valued at about US$3.9 billion. At the time, the Oxford-based company said it protected more than 400,000 organizations in more than 150 countries. Some private credit firms passed on the refinancing despite Sophos reporting 6% annual recurring revenue growth for the three months ended June 30. The company's adjusted earnings before interest, taxes, depreciation, and amortization reached about US$120 million, while its term loan recovered to about 96.88 cents on the dollar from 92.69 in February, the people said. Stay updated on the go with our mobile app. Get latest insights with smoother, more personalized experience through TIA mobile app. How would you feel if you could no longer use Tech in Asia? Share, tag us, and land on our Wall of!

Orange Tech Center
Aug 16th, 2026
Sophos makes new SIEM, MDR, and XDR tools generally available.

Sophos makes new SIEM, MDR, and XDR tools generally available. Sophos has opened access to three Fusion security tools. Here is what the August 15 rollout means for small organizations and their IT providers. Sophos made three parts of its Fusion cybersecurity platform generally available on August 15, 2026: Sophos Next-Gen SIEM, an expanded Sophos Managed Detection and Response service, and a rebuilt Sophos XDR platform. The company originally announced Fusion in July, so the news this week is not a new product reveal - it is the point when these specific capabilities became available to customers. The SIEM product is designed to collect and analyze security information in one place, support longer-term data retention, and help with compliance reporting. Sophos says its expanded MDR service adds continuous, AI-assisted threat hunting and broader response across endpoints, firewalls, cloud services, email, and identity systems. The rebuilt XDR product is intended to help security teams investigate higher-confidence alerts with less manual work. Sophos built these offerings on technology from Secureworks Taegis, following its acquisition of Secureworks. For an everyday Orange Tech customer, the practical takeaway is simpler than the product names: connected security tools can reduce the number of separate screens an IT team must watch and may help it respond faster when an account, laptop, server, or cloud service behaves suspiciously. That does not make the system automatic or risk-free. AI-generated findings still need human review, permissions must be kept narrow, and backups, software updates, multifactor authentication, and staff training remain essential. Small businesses considering the platform should ask their provider which data sources will be connected, how long logs will be retained, who can authorize a response, what happens during an outage, and what the full operating cost will be. Orange Tech's interpretation is that the strongest value will come from disciplined setup and clear response procedures - not from the AI label alone.

CODE3 Technologies
Aug 15th, 2026
Top 10 IT companies in Dubai, UAE in 2026: why CODE3 stands out.

Top 10 IT companies in Dubai, UAE in 2026: why CODE3 stands out. Deen | Code3 Date Published 08/15/2026 Introduction. Dubai's technology landscape is evolving rapidly, with businesses investing in IT infrastructure, cybersecurity, cloud computing, managed IT services, AI, digital transformation, and workplace technology. With hundreds of technology providers serving businesses across the UAE, finding the right IT partner requires more than comparing prices. Businesses need technical expertise, reliable support, security, scalability, and long-term service. Why CODE3 is a strong IT partner for Dubai businesses. CODE3 Technologies provides end-to-end technology solutions designed to help businesses operate securely, efficiently, and with less downtime. Its key capabilities. - Managed IT Services - IT AMC & Preventive Maintenance - Cybersecurity Solutions - Cloud & Microsoft Solutions - IT Infrastructure & Networking - Backup & Business Continuity - Audio Visual & Video Conferencing - Security & Surveillance - Professional IT Services Leading technology partnerships. CODE3 works with leading technology brands including Cisco, Microsoft, Dell, Fortinet, Sophos, Logitech, Yealink, AWS, Acronis, Synology, Ubiquiti and other global technology partners. What makes CODE3 different? One Technology Partner Instead of managing multiple vendors for IT, cybersecurity, infrastructure and AV, businesses can work with one integrated technology partner. Proactive IT Support CODE3 focuses on preventive maintenance, monitoring and rapid support to help reduce downtime and keep business operations running smoothly. Security-Focused Solutions From network security and endpoint protection to backup and business continuity, cybersecurity is built into the technology environment. Scalable Solutions CODE3 supports both growing businesses and established organizations with solutions designed to scale as technology requirements evolve. Choosing a top IT company in Dubai. When evaluating IT companies in Dubai, businesses should consider: - Technical expertise - Range of IT services - Cybersecurity capabilities - Response and SLA commitments - Vendor partnerships - Preventive maintenance - Scalability - After-sales support Final thoughts. Being among the leading IT companies in Dubai is not simply about the number of services offered. It is about reliability, expertise, customer support and the ability to solve real business technology challenges. With its integrated approach to Managed IT, Cybersecurity, Cloud, IT Infrastructure, AMC, AV and Digital Solutions, CODE3 continues to build its position as a trusted technology partner for businesses across Dubai and the UAE. Contact CODE3. Technology Discover how managed IT services help Dubai businesses reduce downtime, improve security, and boost productivity with CODE3 Technologies.

PR Newswire
Aug 13th, 2026
Nozomi Networks and Sophos unite IT and OT security through new Fusion integration

Nozomi Networks and Sophos have partnered to integrate their security platforms, combining Nozomi's AI-enabled Vantage operational technology (OT) platform with Sophos Fusion's cybersecurity defence system. This marks one of the first major third-party integrations following Sophos Fusion's launch. The integration aims to enhance visibility and threat detection across IT and OT environments, addressing the growing vulnerability of critical infrastructure to cyberattacks. Many OT outages originate from compromised IT systems, making unified visibility increasingly important. The partnership brings Nozomi's OT telemetry, asset intelligence and threat data directly into Sophos Fusion, allowing security teams to correlate information from both environments without switching contexts. This enables faster investigations and better-informed decisions when assessing expanding attack surfaces. The collaboration demonstrates Sophos' commitment to creating an open ecosystem that unifies best-of-breed security technologies.