Senior Security Research EngineerPosted today$46K–$183K

The opportunity

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the…

What you'll do

  • Research emerging attacker techniques and turn them into shipped protections.: Study real-world tradecraft across in-memory threats, injection, credential theft, ransomware, and kernel tampering, then design protections that hold up against an adversary actively trying to defeat them.

  • Build and extend endpoint visibility. Instrument new event sources across: Windows, macOS, and Linux, deepen the telemetry we already collect, and close the gaps attackers rely on. Every source you add becomes a foundation for other teams.

  • Develop production code that runs everywhere. Write performant, stable C/C++: that executes on millions of endpoints, where a memory leak or a few milliseconds of overhead is a customer-visible problem.

  • Reverse engineer malware and study evasion. Learn how attackers bypass: endpoint security controls in the wild, and feed that understanding directly into the protections you design and harden.

  • Own efficacy end to end. Review customer telemetry at fleet scale,: investigate false positives and performance regressions, and establish mitigation strategies. Shipping the feature is the beginning of the job, not the end.

  • Extend protection parity across platforms. Bring the depth we have on Windows: to macOS and Linux, and support new hardware architectures as they reach the enterprise.

What they're looking for

  • Collaborate across Elastic Security. Implement endpoint code alongside peers: in multiple countries and time zones, and work with the detection engineers, malware researchers, and data scientists who rely on your telemetry.
  • Help lead the team's technical direction. Take point on initiatives that span: multiple releases, raise the bar in design and code reviews, and mentor engineers earlier in their careers.
  • Publish and present. Share your research on Elastic Security Labs, present at: conferences, and contribute to the open source projects that organizations around the world rely on.
  • + years of professional experience analyzing attacker tactics, techniques,: and procedures (TTPs) and building detection methods for real security threats.