Role Summary
What You Will Do
Research & Analysis
- Investigate how threat actors are leveraging AI across the attack lifecycle, including: AI assisted social engineering, AI-generated malware, automated reconnaissance, and adversarial attacks against ML-based defenses.
- Research real-world threats to agentic AI systems, AI supply chains, and enterprise AI deployments, assessing risk and developing detection strategies.
- Help instrument and tune telemetry to identify indicators of AI-driven attacker behavior at scale.
- Analyze global telemetry, case data, and OSINT to surface emerging AI-related threat trends and early-warning indicators.
Automation & Efficiency
- As a practitioner of the technology you research, identify opportunities to automate repetitive research and reporting workflows using LLMs, scripting, and internal tooling.
- Help the team evolve its operating model as new AI capabilities become available.
- Cross-Functional Collaboration
- Work closely with CTU researchers, SophosLabs analysts, MDR threat hunters, data
- scientists, and engineering teams to synthesize findings into unique reporting with actionable intelligence.
- Contribute to the joint task-force intelligence cycle, ensuring insights flow rapidly into protections, detection rules, and operational systems.
Content & Publication
- Produce high-quality written intelligence outputs, including deep-dive research, rapid
- analyses, and strategic forecasting.
- Author work that is suitable for external publication via Sophos blogs, industry reports,
- and conference presentations.
- Present findings to internal stakeholders, external partners, and the broader security
- community.
What You Will Bring
- Ability to interpret data from diverse telemetry sources and transform it into actionable
intelligence. - Exceptional written communication skills suitable for both technical and executive
audiences. - Demonstrated experience in at least two of the following: threat intelligence, malware analysis, detection engineering, or AI/ML research.
- Strong knowledge of threat actor ecosystems, modern attack techniques, and the MITRE ATT&CK framework.
- Hands-on proficiency with Python and modern AI development patterns, including building and orchestrating multi-agent systems, working with LLM APIs, and designing agentic workflows with sub-agents, tool use, and retrieval-augmented generation.
- Experience building or using automation tools to streamline analytical or reporting
workflows.
Preferred Qualifications
- Experience working in MDR, incident response, or real-time security operations environments.
- Prior authorship of externally published threat research (blogs, reports, conference presentations).
- Experience with LLMs, prompt engineering, or building AI-assisted analytical tools.
- Familiarity with large-scale telemetry pipelines, security data lakes, or SIEM/SOAR platforms.