SentinelOne

SentinelOne

·Today

Senior security researcher- ai detection

Apply now

Location

onsite, Tel-Aviv, Israel

Commitment

Full Time

Level

Senior (5+ years)

Required skills

Security researchThreat huntingDetection engineeringWindows internalsEDR telemetryPythonSQLKQLSplunkMachine learningLLMsTTPsMalware analysisReverse engineeringRed-teamingData analysis

Job Description

Our Purpose

At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them becomes more critical than ever. When you join SentinelOne, your work helps protect global enterprises, critical infrastructure, and the technologies shaping tomorrow. If you are motivated by meaningful challenges and want your impact to be real, measurable, and global, you will find purpose here.

About Us

SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response with clarity and speed. By combining real-time analytics, intelligent automation, and a unified data foundation, we reduce noise, simplify complexity, and empower security teams to focus on what truly matters.

Our teams are builders, problem-solvers, and innovators committed to shaping the future of security. If you are excited to solve hard problems alongside talented, mission-driven people, we invite you to help us build a safer future for humanity.

What Are We Looking For?

We’re looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes.

Join the Detection AI Research team, where security research meets machine learning. We use SentinelOne's EDR telemetry from millions of endpoints to hunt for sophisticated, highly evasive attacks and to close the coverage gaps they expose, using ML models and LLM-based agents that we design, build, and run in production. As a Senior Security Researcher in our AI Detection research team, you will bring the attacker's-eye view: which techniques matter, how they look in endpoint data, and what separates a real intrusion from benign noise at scale. You will work alongside the data scientists who build our models, and your detections will reach real customers through SentinelOne's Wayfinder analysts, threat hunters and detection engines.

What Will You Do?

  • Research attack techniques and TTPs and how they manifest in our EDR telemetry, and turn that research into detection hypotheses that hold across millions of endpoints.
  • Design, build, own, and maintain AI-powered detections end to end: turn a detection hypothesis into a production pipeline that analyzes fleet-wide EDR data, applies the team's ML models and LLMs to separate real intrusions from benign activity, and surfaces advanced attacks that analysts and threat hunters can triage and act on.
  • Drive the development of LLM-based agents that automate detection authoring: define what a correct, robust detection looks like, and expand our agent's detection coverage autonomously.
  • Analyze detection gaps and false positives together with MDR analysts, threat hunters and detection engineering teams, and feed the findings back into the detections.
  • Write high-quality production Python and own your code in production.
  • Stay current with APTs, attacker methodologies, and emerging TTPs.

What Skills and Knowledge Will You Bring?

  • 5+ years of experience in security research, threat hunting, or detection engineering, with a track record of detections deployed in production.
  • Deep understanding of the cybersecurity landscape, attack vectors, TTPs, and detection methods, especially on Windows.
  • In-depth knowledge of Windows internals and of how attacker behavior appears in EDR telemetry: process, file, registry, and network events.
  • Comfortable researching and hunting over very large telemetry datasets using SQL, KQL, Splunk, EDR query languages, or similar.
  • Python software development experience, including working with data and writing production-quality code.
  • Ability to drive and own research projects end to end; independent, critical thinker, team player.
  • Interest in applying machine learning and LLMs to detection, and fluency with modern AI tools in your daily work.

Advantages

  • Hands-on experience applying machine learning or LLMs to security problems.
  • Experience writing detection content: behavioral rules, Sigma, YARA, EDR query languages.
  • Malware analysis, reverse engineering, or red-team experience.
  • Experience with EDR/XDR products and their telemetry.

Why SentinelOne?

AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI-native platform designed to operate at machine speed, not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place.

We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family:

  • Medical, Vision, Dental, 401(k), Commuter, Health and Dependent FSA
  • Unlimited PTO
  • Leading Total Rewards including Restricted Stock Program
  • 16-weeks of gender-neutral parental leave
  • Paid company holidays and sick time
  • Flexible working hours
  • Employee stock purchase program
  • Disability and life insurance
  • Employee assistance program
  • Gym membership reimbursement
  • Internet/Mobile allowance
  • Learning & development at every level for every function
  • Opportunity to strengthen communities globally through our S Foundation

SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. SentinelOne participates in the E-Verify Program for all U.S. based roles.

Ready to join the team?

Apply now