Senior Threat Intelligence Researcher

SentinelOne

Polska

On-site

PLN 180,000 - 300,000

Full time

14 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Competitive leave benefits
Gender-neutral parental leave
Medical and insurance benefits
Pension
Global home office allowance
Wellbeing allowance
MultiSport benefit program

Job summary

SentinelOne is seeking a Senior Threat Intelligence Researcher to lead deep-dive investigations into emerging and known threats, while monitoring malware developments to keep defenses ahead of attackers. You will synthesize complex data into actionable intelligence for senior management and develop refined hunting strategies to counter evolving techniques.

You will track adversary infrastructure and map threat actor activity across internal networks, cloud environments, and endpoints,

Qualifications

  • Background in threat research, threat intelligence or hunting.
  • Knowledge of cyber threat landscape, TTPs, and threat actors.
  • Strong analytical skills for large datasets.
  • Understanding of telemetry and product operation internals.
  • Familiarity with MITRE ATT&CK, CISA KEV, AMITT and MISP Galaxy.
  • Experience with static/dynamic malware analysis, sandboxing, debugging.
  • Proven technical writing and content development ability.
  • Knowledge of how EDR works is preferred.

Responsibilities

  • Synthesize data into actionable threat briefings for leadership.
  • Lead in-depth threat hunts across networks, cloud, and endpoints.
  • Map threat actor footprints via EDR telemetry.
  • Analyze TTPs and shifts in execution, persistence, and lateral movement.
  • Trace adversary infrastructure via domain registrations and DNS.

Skills

Threat research
Threat intelligence
Threat hunting
Analytical skills
Telemetry understanding
EDR knowledge
MITRE ATT&CK
Malware analysis
Technical writing

Education

CMA
CREA
GREM

Tools

YARA
Sandboxing
Debugging
Malware analysis tools

Job description

Our Purpose

At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them becomes more critical than ever. When you join SentinelOne, your work helps protect global enterprises, critical infrastructure, and the technologies shaping tomorrow. If you are motivated by meaningful challenges and want your impact to be real, measurable, and global, you will find purpose here.

About Us

SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response with clarity and speed. By combining real-time analytics, intelligent automation, and a unified data foundation, we reduce noise, simplify complexity, and empower security teams to focus on what truly matters.

Our teams are builders, problem-solvers, and innovators committed to shaping the future of security. If you are excited to solve hard problems alongside talented, mission-driven people, we invite you to help us build a safer future for humanity.

What Are We Looking For?

We’re looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes.

As a Senior Threat Intelligence Researcher, you will be tasked with leading deep-dive investigations into both emerging and known threats, while maintaining a vigilant watch over malware developments to ensure defenses remain a step ahead of evolving attack methods. You will synthesize complex data into actionable intelligence and provide senior management with the clear briefings necessary to understand and mitigate potential risks. You will also develop refined hunting strategies to adapt to and anticipate shifts in threat actor tactics and techniques, and track adversary infrastructure to effectively counteract shifts in threat actor tradecraft through detail-oriented investigation.

What Will You Do?

Primary responsibilities include:

  • Synthesize complex data, from internal hunt findings to intelligence gathered from dark web forums, leak sites, and research repositories, into actionable threat briefings and risk assessments for security leadership and senior stakeholders.
  • Lead in-depth, hypothesis-driven threat hunts across internal networks, cloud environments, and endpoints to uncover sophisticated intrusions that evade traditional security controls.
  • Map threat actor footprints internally by pivoting through EDR telemetry.
  • Analyze adversary tactics, techniques, and procedures (TTPs) within the environment, identifying shifts in execution, persistence, and lateral movement.
  • Trace adversary infrastructure externally by pivoting through domain registrations, SSL certificates, and passive DNS.
What Skills and Knowledge Will You Bring?

Ideal candidates will have:

  • A background in threat research, threat intelligence or threat hunting.
  • Knowledge of the cyber threat landscape, including threat actors and their tactics, techniques, and procedures (TTPs).
  • Strong analytical skills, with the ability to identify patterns and trends in large datasets.
  • Knowledge of how our products operate internally and how to maximize their telemetry.
  • Strong knowledge of YARA to track new malware families, along with knowledge of validation best practices.
  • An understanding of software vulnerabilities and the ability to implement internal hunting strategies to track their exploitation across the estate.
  • Knowledge of MITRE ATT&CK, CISA KEV, EPSS, AMITT, and MISP Galaxy.
  • Knowledge of malware analysis tools and techniques, including static and dynamic analysis, sandboxing, and debugging.
  • Technical writing and content development skills.
  • A solid technical understanding of how EDR works is preferred.
  • Relevant certifications, such as Certified Malware Analyst (CMA), Certified Reverse Engineering Analyst (CREA), or GIAC Certified Malware Reverse Engineer (GREM), are preferred.
Why SentinelOne?

AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI-native platform designed to operate at machine speed, not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place.

We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family:

Equity & Rewards
  • Restricted Stock Units (RSUs)
  • Employee Stock Purchase Plan (ESPP)
Time Off & Wellbeing
  • Competitive leave benefits
  • Gender-neutral parental leave
Insurance & Financial Security
  • Medical and insurance benefits
  • Pension
Work Perks & Flexibility
  • Global home office allowance
Wellness & Lifestyle
  • Wellbeing allowance
  • MultiSport benefit program

SentinelOne is proud to be an Equal Employment Opportunity and affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

SentinelOne participates in the E-Verify Program for all U.S. based roles.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DFIR Analyst
DFIR Analyst

SentinelOne • Poland

On-site
PLN 120,000 - 180,000
RSUs
ESPP
Competitive leave benefits
+6
Staff Product Manager - AI SIEM, Detection and Response
Staff Product Manager - AI SIEM, Detection and Response

SentinelOne • Poland

On-site
PLN 240,000 - 340,000
RSUs
ESPP
Leave benefits
+6
Staff Technical Account Manager
Staff Technical Account Manager

SentinelOne • Poland

On-site
PLN 230,000 - 320,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Medical benefits
+4
Senior Software Architect
Senior Software Architect

SentinelOne • Wrocław

On-site
PLN 300,000 - 420,000
RSUs
ESPP
Leave benefits
+5
Senior DevOps Engineer / Platform Engineer - Streaming, Caching, DBaaS
Senior DevOps Engineer / Platform Engineer - Streaming, Caching, DBaaS

SentinelOne • Poland

On-site
PLN 200,000 - 320,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Competitive leave benefits
+7
Senior Infrastructure Engineer - Streaming, Caching, DBaaS
Senior Infrastructure Engineer - Streaming, Caching, DBaaS

SentinelOne • Poland

On-site
PLN 250,000 - 350,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Competitive leave benefits
+6
Expert MDR Sentinel (Managed Services)
Expert MDR Sentinel (Managed Services)

SoftwareOne • Poland

On-site
PLN 120,000 - 180,000
Global company culture
Mentor who supports your start
President’s Club
+2
Expert MDR Sentinel (Managed Services)
Expert MDR Sentinel (Managed Services)

SoftwareONE Deutschland GmbH • Warszawa

On-site
PLN 190,000 - 270,000
Global culture
Mentor program
President's Club
+2
Staff Windows Low Level C++ Engineer - Endpoint security
Staff Windows Low Level C++ Engineer - Endpoint security

SentinelOne • Poland

Remote
PLN 298,000 - 385,000
Flexible working hours
Generous employee stock plan
Yearly performance bonus
+1
Senior Security Research Engineer, SONAR (Security Operations and Novel Adversary Research)
Senior Security Research Engineer, SONAR (Security Operations and Novel Adversary Research)

Elastic • Poland

On-site
PLN 346,000 - 547,000
Health coverage
Flexible locations & schedules
Generous vacation
+3