Senior Malware Detection Engineer

SentinelOne

India

On-site

INR 2,500,000 - 5,000,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

RSUs
ESPP
Competitive leave benefits
Parental leave
Medical benefits
EAP
Global home office allowance
Internet allowance
LinkedIn Learning license
Meal vouchers

Job summary

SentinelOne seeks a Senior Malware Detection Engineer with deep Linux/macOS expertise to analyze threats, develop detection content, and mentor teams. You will own end-to-end detection coverage, build tooling, and contribute to research outputs.

Ideal candidates will have 5+ years of static/dynamic malware analysis, experience with disassemblers like IDA/Ghidra, and a strong background in MITRE ATT&CK TTPs, automation, and container tech.

Qualifications

  • 5+ years of experience in static and dynamic malware analysis and reverse engineering.
  • Proficiency with reverse engineering tools such as disassemblers and debuggers.
  • Strong background in malware analysis and advanced techniques (anti-tampering, persistence, ransomware).
  • Good understanding of MITRE ATT&CK TTPs.

Responsibilities

  • Research Linux/macOS threats including ELF/Mach-O and malware to close detection gaps.
  • Analyze endpoint telemetry and binaries to validate detections and prioritize coverage.
  • Share findings with detection teams and collaborate across groups.
  • Own detection coverage end-to-end, ensuring FP/FN quality and performance.
  • Design and maintain CI/testing infrastructure for detection content.
  • Build tooling to monitor rule performance and FP/FN trends, leveraging AI/LLM-assisted workflows.
  • Mentor other engineers in macOS/Linux malware analysis and detection practices.
  • Write whitepapers, blogs, and articles.

Skills

Malware analysis
Reverse engineering
Linux
macOS
YARA
Python
C/C++
Disassemblers
MITRE ATT&CK
Automation
Containers/Kubernetes

Tools

IDA
Ghidra
Hopper
LLDB
GDB

Job description

Our Purpose

At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them becomes more critical than ever. When you join SentinelOne, your work helps protect global enterprises, critical infrastructure, and the technologies shaping tomorrow. If you are motivated by meaningful challenges and want your impact to be real, measurable, and global, you will find purpose here.

About Us

SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response with clarity and speed. By combining real-time analytics, intelligent automation, and a unified data foundation, we reduce noise, simplify complexity, and empower security teams to focus on what truly matters.

Our teams are builders, problem-solvers, and innovators committed to shaping the future of security. If you are excited to solve hard problems alongside talented, mission-driven people, we invite you to help us build a safer future for humanity.

What Are We Looking For?

We’re looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes.

As a Senior Malware Detection Engineer with deep expertise in Linux and macOS — someone who is always looking to analyze and break things while pursuing a complete understanding of how they work, who lives to beat the system and challenge it, and who is driven to outsmart malware to protect our customers.

What Will You Do?

Primary responsibilities include:

  • Research
    • Perform in-depth analysis and research (through reverse engineering and other methods) of Linux and macOS threats, TTPs, exploits, and malware — including ELF and Mach-O binaries, shell/script-based malware, and software supply-chain / malicious open-source packages — to understand how they operate and close detection gaps.
    • Analyze endpoint telemetry alongside binaries and samples to validate detections, hunt telemetry and use security platforms for emerging malware families, and prioritize new coverage.
    • Share research findings with other detection teams and collaborate across internal/external groups to strengthen detection capability.
  • Development
    • Own detection coverage end to end: write and maintain detection assets, be accountable for FP/FN quality, detection efficacy and performance.
    • Design and maintain the CI/testing infrastructure used to build, test, and ship detection content safely.
    • Build and improve tooling that gives the team visibility into rule performance, coverage, and FP/FN trends — increasingly leveraging AI/LLM-assisted pipelines to speed up triage and analysis for covering the detection gap.
    • Respond quickly to emerging threats and customer detection escalations for malware requests.
    • Support detection coverage validation against BAS (Breach and Attack Simulation) frameworks.
    • Mentor other engineers on Linux/macOS malware analysis and detection engineering practices.
    • You'll also be encouraged to write whitepapers, blogs, and articles.
What Skills and Knowledge Will You Bring?
  • A dedication to continuous learning and skill development to meet evolving job demands.
  • 5+ years of experience in both static and dynamic malware analysis and reverse engineering, with proven depth on Linux and working knowledge of macOS (or vice versa).
  • Proficiency with reverse engineering and analysis tools, such as disassemblers, compilers, and debuggers like IDA, Ghidra, Hopper, LLDB, GDB.
  • Strong background in malware analysis and understanding its behavior, including advanced techniques such as anti-tampering, defense evasion, lateral movement, persistence, and ransomware activity.
  • Good understanding of MITRE ATT&CK TTPs.
  • A strong inclination toward automating routine analysis and detection workflows.
  • Excellent and deep understanding of Linux (both user-mode and kernel-mode):
    • Core system internals — processes and threads, IPC, tracing (including eBPF), security, virtual memory — and how they work behind the scenes.
    • Understanding of containers and Kubernetes, including common container escape and cloud-native attack techniques.
  • For macOS:
    • Understanding of ARM64/Apple Silicon architecture.
    • Understanding of sandbox internals/escapes, and Transparency, Consent and Control (TCC) internals/escapes.
    • Understanding of security mechanisms such as File Quarantine, XProtect, and Gatekeeper.
    • Programming experience: Assembly, C/C++, Objective-C (for macOS), Python.
    • Experience creating production detection rules using YARA/plist or similar engines.
Preferred / Advantages (One Or More)
  • Exposure to AI/LLM-assisted reverse engineering or detection-authoring tooling.
  • Good understanding of existing AV/EDR/EPP internals and detection mechanisms.
  • Experience building CI/CD pipelines (Jenkins, GitHub Actions, or similar) for shipping detection content.
  • Familiarity with attack simulation frameworks (BAS) and their TTPs.
  • Experience querying large-scale telemetry (SQL, EventDB/DataSet, Redash, or similar) to validate detections.
Why SentinelOne?

AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI-native platform designed to operate at machine speed, not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place.

We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family:

Equity & Rewards
  • Restricted Stock Units (RSUs)
  • Employee Stock Purchase Plan (ESPP)
Time Off & Wellbeing
  • Competitive leave benefits
  • Gender-neutral parental leave
Insurance & Financial Security
  • Medical and insurance benefits
  • Employee Assistance Program (EAP)
Work Perks & Flexibility
  • Global home office allowance
  • Internet allowance
  • LinkedIn Learning license
  • Social Connect program
  • Food allowance (Bangalore office)
  • Meal vouchers (Sodexo)
Wellness & Lifestyle
  • Health & wellness benefit

SentinelOne is proud to be an Equal Employment Opportunity and Affinitive Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

SentinelOne participates in the E-Verify Program for all U.S. based roles.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

MDR Analyst
MDR Analyst

SentinelOne • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Competitive leave benefits
+10
Senior Software Engineer
Senior Software Engineer

SentinelOne • India

On-site
INR 3,000,000 - 5,500,000
Equity & Rewards: RSUs
Employee Stock Purchase Plan (ESPP)
Competitive leave benefits
+6
Staff MDR Investigator
Staff MDR Investigator

SentinelOne • India

On-site
INR 2,500,000 - 4,000,000
RSUs
ESPP
Competitive leave benefits
+10
Senior DevOps Engineer
Senior DevOps Engineer

SentinelOne • India

On-site
INR 5,725,000 - 9,065,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Global home office allowance
+4
Staff Software Engineer
Staff Software Engineer

SentinelOne • India

Hybrid
INR 2,000,000 - 3,000,000
Global home office allowance
Internet allowance
LinkedIn Learning license
+2
Staff Software Engineer - Frontend
Staff Software Engineer - Frontend

SentinelOne • India

On-site
INR 1,500,000 - 2,500,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Global home office allowance
+4
Senior Solutions Engineer
Senior Solutions Engineer

SentinelOne • India

On-site
INR 3,000,000 - 5,400,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Global home office allowance
+6
Security Operations Engineer
Security Operations Engineer

NextGenEnergyJobs • Bengaluru

On-site
INR 2,500,000 - 5,200,000
Flexible time off
Wellness resources
Team events
AI Detection Engineer - SOC Analyst IV
AI Detection Engineer - SOC Analyst IV

Ten Eleven Ventures • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Senior Security Engineer - Microsoft Sentinel SIEM
Senior Security Engineer - Microsoft Sentinel SIEM

Cyderes • Bengaluru

Hybrid
INR 3,000,000 - 5,000,000
Medical Insurance
Life Insurance
Retirement Match Program
+7