- Страна
- Израиль
Откликайтесь
на вакансии с ИИ

Staff Windows Detection Engineer
SentinelOne — один из мировых лидеров в области кибербезопасности. Позиция предлагает работу с передовыми технологиями (AI, EDR), высокую степень автономности и возможность влиять на защиту миллионов пользователей.
Сложность вакансии
Роль требует экспертных знаний внутренних механизмов Windows, глубокого владения C++ и навыков реверс-инжиниринга. Уровень 'Staff' подразумевает не только техническое превосходство, но и способность влиять на архитектуру продукта.
Анализ зарплаты
Зарплата для Staff-позиций в Израиле в сфере кибербезопасности является одной из самых высоких на рынке. Указанный диапазон соответствует уровню топовых продуктовых компаний в Тель-Авиве.
Сопроводительное письмо
I am writing to express my strong interest in the Staff Windows Detection Engineer position at SentinelOne. With extensive experience in Windows Internals and a deep background in reverse engineering x86/x64 binaries, I have spent years dissecting sophisticated malware and developing robust detection logic. My proficiency in C++ and familiarity with tools like IDA Pro and WinDbg align perfectly with your team's mission to provide autonomous protection across millions of endpoints.
Throughout my career, I have focused on end-to-end detection engineering, from initial sample analysis to implementing production-ready behavioral signatures. I am particularly drawn to SentinelOne’s AI-native approach and the opportunity to work on disruptive security technologies. I am confident that my technical expertise in kernel-level research and exploit mitigation will allow me to make immediate contributions to the SentinelLabs team and help stay ahead of evolving cyber threats.
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в sentinellabs уже сейчас
Присоединяйтесь к лидерам AI-безопасности и защитите миллионы устройств по всему миру — откликнитесь сейчас!
Описание вакансии
Our Purpose
At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them becomes more critical than ever. When you join SentinelOne, your work helps protect global enterprises, critical infrastructure, and the technologies shaping tomorrow. If you are motivated by meaningful challenges and want your impact to be real, measurable, and global, you will find purpose here.
About Us
SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response with clarity and speed. By combining real-time analytics, intelligent automation, and a unified data foundation, we reduce noise, simplify complexity, and empower security teams to focus on what truly matters.
Our teams are builders, problem-solvers, and innovators committed to shaping the future of security. If you are excited to solve hard problems alongside talented, mission-driven people, we invite you to help us build a safer future for humanity.
What Are We Looking For?
We’re looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes.
As a Staff Windows Detection Engineer, you will research and detect the latest malware and exploits on the SentinelOne EPP platform. You will reverse-engineer samples to design and implement robust detection methods that prevent sophisticated attacks. Additionally, you will develop custom research tools and PoCs to strengthen protection across millions of endpoints.
Why us?
Because you will meet extraordinary challenges facing the newest attacks and tech obstacles and overcoming them.
You will work with the very BEST in the industry in a flexible and independent environment.
You will influence the design of a disruptive product that will shape the security industry of tomorrow.
What will you do?
You will be responsible for detecting the newest malware and exploits based on SentinelOne’s EPP platform. The role includes an end to end responsibility for behaviour based detection capabilities, starting from reversing the samples, designing new methods to detect or prevent those, and implementing it in the product in the end. You will be developing and using internal research tools, PoCs and discovering new ways to detect/prevent exploitation attacks (EoP, drive-by attacks and more). At the end of the day, your deliveries will enhance the security of dozens of millions of Windows endpoints which are protected by our platform.
What experience or knowledge should you bring?
- Excellent understanding of the Windows Internals - understanding how core system components (Process and Threads, Virtual Memory and more) work behind the scenes.
- 3+ years of experience in malware analysis (statically and dynamically)
- 3+ years of experience with C++
- Proven experience with reverse engineering of x86/x64/ARM binaries.
- Experienced with analysis tools, such as: IDA, WinDBG, SysInternals etc.
- Kernel development experience - advantage
- Python experience - advantage
- Advanced C++ - advantage
- Understanding of existing AVs internals - advantage.
SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
SentinelOne participates in the E-Verify Program for all U.S. based roles.
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- C++
- Reverse Engineering
- Windows Internals
- Malware Analysis
- IDA Pro
- WinDbg
- Sysinternals
- Python
- Kernel development
- x86 Assembly
- x64 Assembly
- ARM Assembly
Возможные вопросы на собеседовании
Проверка глубоких знаний архитектуры ОС, критически важных для обнаружения сложных угроз.
Расскажите подробно о механизме работы системных вызовов (syscalls) в Windows и о том, как современные EDR-решения могут перехватывать их для анализа.
Оценка практического опыта в анализе вредоносного ПО.
Опишите ваш процесс анализа упакованного или обфусцированного вредоносного ПО. Какие техники анти-отладки вы встречали чаще всего и как их обходили?
Проверка навыков разработки на C++ в контексте безопасности.
Какие меры предосторожности необходимо соблюдать при написании кода для детектора, работающего в режиме ядра (kernel mode), чтобы избежать BSOD или деградации производительности?
Оценка понимания векторов атак.
Объясните разницу между техниками Process Hollowing и Process Ghosting. Как бы вы спроектировали универсальный метод обнаружения для подобных техник внедрения кода?
Проверка умения работать с инструментарием.
В каких ситуациях вы предпочтете использовать WinDbg вместо IDA Pro, и как вы используете скрипты (например, на Python или JavaScript) для автоматизации рутинных задач при реверс-инжиниринге?
Похожие вакансии
Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)
Исследователь безопасности Android
Эксперт по защите периметра (WAF)
DevOps-инженер/ИБ (devops engineer, information security)
Application Security Еngineer (AppSec)
Инженер по сетевой безопасности
1000+ офферов получено
Устали искать работу? Мы найдём её за вас
Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!
- Страна
- Израиль