Sr Malware Detection Engineer (Bengaluru)

Sr Malware Detection Engineer (Bengaluru)

19 Aug
|
SentinelOne
|
Bengaluru

19 Aug

SentinelOne

Bengaluru

Job Summary

As a Senior Malware Detection Engineer with deep expertise in Linux and macOS - someone who is always looking to analyze and break things while pursuing a complete understanding of how they work, who lives to beat the system and challenge it, and who is driven to outsmart malware to protect our customers.

Responsibilities

- Research: Perform in-depth analysis and research (through reverse engineering and other methods) of Linux and macOS threats, TTPs, exploits, and malware - including ELF and Mach-O binaries, shell/script-based malware, and software supply-chain / malicious open-source packages - to understand how they operate and close detection gaps.
- Analyze endpoint telemetry alongside binaries and samples to validate detections, hunt telemetry and use security platforms for emerging malware families, and prioritize new coverage.
- Share research findings with other detection teams and collaborate across internal/external groups to strengthen detection capability.
- Development: Own detection coverage end to end: write and maintain detection assets, be accountable for FP/FN quality, detection efficacy and performance.
- Design and maintain the CI/testing infrastructure used to build, test, and ship detection content safely.
- Build and improve tooling that gives the team visibility into rule performance, coverage, and FP/FN trends - increasingly leveraging AI/LLM-assisted pipelines to speed up triage and analysis for covering the detection gap.
- Respond quickly to emerging threats and customer detection escalations for malware requests.
- Support detection coverage validation against BAS (Breach and Attack Simulation) frameworks.
- Mentor other engineers on Linux/macOS malware analysis and detection engineering practices.
- You'll also be encouraged to write whitepapers, blogs, and articles.

Requirements

Ideal candidates will have:

- A dedication to continuous learning and skill development to meet evolving job demands.




- 5+ years of experience in both static and dynamic malware analysis and reverse engineering, with proven depth on Linux and working knowledge of macOS (or vice versa).
- Proficiency with reverse engineering and analysis tools, such as disassemblers, compilers, and debuggers like IDA, Ghidra, Hopper, LLDB, GDB.
- Strong background in malware analysis and understanding its behavior, including advanced techniques such as anti-tampering, defense evasion, lateral movement, persistence, and ransomware activity.
- Good understanding of MITRE ATTCK TTPs.
- A robust inclination toward automating routine analysis and detection workflows.
- Excellent and deep understanding of Linux (both user-mode and kernel-mode): Core system internals - processes and threads, IPC, tracing (including eBPF), security, virtual memory - and how they work behind the scenes.
- Understanding of containers and Kubernetes, including common container escape and cloud-native attack techniques.
- Understanding of ARM64/Apple Silicon architecture.
- Understanding of sandbox internals/escapes, and Transparency, Consent and Control (TCC) internals/escapes.
- Understanding of security mechanisms such as File Quarantine, XProtect, and Gatekeeper.
- Programming experience: Assembly, C/C++, Objective-C (for macOS), Python.
- Experience creating production detection rules using YARA/plist or similar engines.

Preferred / Advantages

- Exposure to AI/LLM-assisted reverse engineering or detection-authoring tooling.
- Good understanding of existing AV/EDR/EPP internals and detection mechanisms.
- Experience building CI/CD pipelines (Jenkins, GitHub Actions, or similar) for shipping detection content.
- Familiarity with attack simulation frameworks (BAS) and their TTPs.
- Experience querying large-scale telemetry (SQL, EventDB/DataSet, Redash, or similar) to validate detections.

Disclaimer: This job posting & Location has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 Sr Malware Detection Engineer (Bengaluru)
🏢 SentinelOne
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: sr malware detection engineer (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: sr malware detection engineer (bengaluru) / bengaluru