Staff Cloud Security Researcher

SentinelOne · Spain · Engineering

Posted 2026-10-01

Apply for this role →

As a Staff Cloud Workload Security Researcher, you will join a global team working across Windows, Linux, and macOS, spanning Endpoint, Cloud, and Identity. You will research evasions against our own sensors, track the offensive tooling landscape, and drive innovative research that anticipates the next generation of attacker tradecraft.

What Will You Do?

Primary responsibilities include:

Proactively look for the newest and most sophisticated attack techniques, deeply research and understand their internals, and emulate these attacks to assess and improve our detection engines.

Conduct comprehensive analysis of potential attack paths within diverse systems and networks in cloud environments.

Identify and prioritize potential vulnerabilities and weaknesses that could be exploited by cyber adversaries in cloud platforms.

Build tools to support detection assessments, create proofs of concept for the newest techniques, and contribute to the design of innovative detection strategies.

Work closely with the threat intelligence team and engineering detection teams to provide guidance and highlight gaps in detection and visibility capabilities.

What Skills and Knowledge Will You Bring?

Ideal candidates will have:

Experience in cloud attack path analysis, vulnerability assessment, and threat modeling.

Familiarity with cloud services, Kubernetes, cloud architecture, and major cloud providers (AWS, GCP, and Azure).

In-depth understanding of the cloud ecosystem, security principles, services, configurations, best practices, and relevant frameworks.

4 or more years of experience in red teaming, security research, or offensive research, with a deep understanding of OS internals (Windows/Linux).

Hands-on experience coding in Python and C/C++.

Understanding of existing EDR internals.

Experience leveraging agentic AI workflows for detection engineering tasks (reverse engineering, code auditing, signature writing).

A proven track record of conference speaking at security conferences or publications is an advantage.

Experience writing detection signatures or heuristics is an advantage.

Why SentinelOne?

AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI-native platform designed to operate at machine speed, not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place.

We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family:

Equity & Rewards

Restricted Stock Units (RSUs)

Employee Stock Purchase Plan (ESPP)

Time Off & Wellbeing

Competitive leave benefits

Gender-neutral parental leave

Insurance & Financial Security

Medical and insurance benefits

Pension

Employee Assistance Program (EAP)

Work Perks & Flexibility

Global home office allowance

Monthly home office, internet and mobile phone allowance

Wellness & Lifestyle

Meal allowance

Transportation allowence

Apply for this role →

← Back to all jobs