Elastic logo
Elastic·Verified

Senior Security Research Engineer - Elastic

Remote-firstFull-timeSenior$133K - $253KUTC-8–-4US#c++#python#securityBonus

About the Role

Elastic is looking for a Senior Security Research Engineer to join the Elastic Security Endpoint Protections team. You will research, design, and build visibility and prevention capabilities for Elastic Defend, our core endpoint and SIEM security solution. You will collaborate with a global, diverse team of researchers, data scientists, and engineers to secure users against emerging threats.

What You Will Be Doing

  • Research & Protection: Analyze real-world attacker tradecraft (in-memory threats, injection, ransomware, kernel tampering) and develop robust protections.
  • Endpoint Visibility: Instrument new event sources across Windows, macOS, and Linux to deepen telemetry.
  • Production Development: Write performant, stable C/C++ code that executes on millions of endpoints.
  • Reverse Engineering: Study malware and evasion techniques to harden security controls.
  • Efficacy Ownership: Investigate customer telemetry, false positives, and performance regressions at scale.
  • Technical Leadership: Mentor junior engineers, lead multi-release initiatives, and contribute to Elastic Security Labs and open-source projects.

What You Bring

  • 6+ years of professional experience in security research, TTP analysis, and detection engineering.
  • 6+ years of development experience in C, C++, and Python.
  • Deep knowledge of OS internals (Windows preferred, with macOS/Linux experience).
  • Strong reverse engineering and malware analysis skills.
  • An adversarial mindset with a focus on resilience and evasion prevention.
  • Experience using AI to accelerate development and optimize complex systems.
  • Ability to work autonomously in a distributed, asynchronous environment.

Bonus Points

  • Vulnerability research and exploit development experience.
  • Red teaming or offensive security background.
  • Kernel-mode development and driver debugging.
  • Established record of conference speaking (Black Hat, DEF CON, etc.) or open-source contributions.
  • Experience with machine learning in endpoint security or the Elastic Stack.

Timezone overlap

UTC-8–-4

Benefits

Bonus

Open to

US

Sign in to track applications and earn points.

More roles at Elastic

Similar remote roles