Staff Security Researcher- Detection AI Research

SentinelOne · Tel Aviv-Yafo, Tel Aviv District, Israel · Engineering

Posted 2026-09-23

Apply for this role →

As a Staff Security Researcher- Detection AI Research, you will be tasked with joining the Detection AI Research team, where security research meets machine learning. We use SentinelOne's EDR telemetry from millions of endpoints to hunt for sophisticated, highly evasive attacks and to close the coverage gaps they expose, using ML models and LLM-based agents that we design, build, and run in production. As a Senior Security Researcher in our AI Detection research team, you will bring the attacker's-eye view: which techniques matter, how they look in endpoint data, and what separates a real intrusion from benign noise at scale. You will work alongside the data scientists who build our models, and your detections will reach real customers through SentinelOne's Wayfinder analysts, threat hunters and detection engines.

What Will You Do?

Primary responsibilities include:

Research attack techniques and TTPs and how they manifest in our EDR telemetry, and turn that research into detection hypotheses that hold across millions of endpoints.

Design, build, own, and maintain AI-powered detections end to end: turn a detection hypothesis into a production pipeline that analyzes fleet-wide EDR data, applies the team's ML models and LLMs to separate real intrusions from benign activity, and surfaces advanced attacks that analysts and threat hunters can triage and act on.

Drive the development of LLM-based agents that automate detection authoring: define what a correct, robust detection looks like, and expand our agent's detection coverage autonomously.

Analyze detection gaps and false positives together with MDR analysts, threat hunters and detection engineering teams, and feed the findings back into the detections.

Write high-quality production Python and own your code in production.

Stay current with APTs, attacker methodologies, and emerging TTPs.

What Skills and Knowledge Will You Bring?

Ideal candidates will have:

5+ years of experience in security research, threat hunting, or detection engineering, with a track record of detections deployed in production.

Deep understanding of the cybersecurity landscape, attack vectors, TTPs, and detection methods, especially on Windows.

In-depth knowledge of Windows internals and of how attacker behavior appears in EDR telemetry: process, file, registry, and network events.

Comfortable researching and hunting over very large telemetry datasets using SQL, KQL, Splunk, EDR query languages, or similar.

Python software development experience, including working with data and writing production-quality code.

Ability to drive and own research projects end to end; independent, critical thinker, team player.

Interest in applying machine learning and LLMs to detection, and fluency with modern AI tools in your daily work

Hands-on experience applying machine learning or LLMs to security problems.

Experience writing detection content: behavioral rules, Sigma, YARA, EDR query languages.

Malware analysis, reverse engineering, or red-team experience.

Experience with EDR/XDR products and their telemetry.

Why us?

AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI-native platform designed to operate at machine speed, not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place.

We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family:

Equity & Rewards

Restricted Stock Units (RSUs)

Employee Stock Purchase Plan (ESPP)

Time Off & Wellbeing

Competitive leave benefits

Gender-neutral parental leave

Employee Assistant Program

Workout sessions and a Wellness App

Insurance & Financial Security

Medical and insurance benefits

Pension

Employee Assistance Program (EAP)

Work Perks & Flexibility

Global home office allowance

Mobile phone reimbursement

Study Fund

Apply for this role →

← Back to all jobs