
Sophos · Romania
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organization...
About Us
Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response.
Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats.
Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.
Role Summary
We are seeking a detail-oriented and technically skilled Detection Engineer to join our X-OPS team. In this role, you will be responsible for analyzing advanced security threats—ranging from malware to complex web attacks—and translating threat intelligence into high-fidelity detections across our platform. Your work will help ensure our analysts and clients receive highly accurate, actionable alerts with minimal noise.
You will leverage data from over 40 third-party and internal sources, partner with our CTU Threat Intelligence team, and use a range of scripting and automation tools to strengthen detection capabilities. The ideal candidate is a hands-on security practitioner with a deep understanding of endpoint behavior, malware analysis, and detection development who thrives in fast-paced, technical environments.
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com. Role Summary Malware Researcher? Red/Blue/Purple team member? We have a fantastic opportunity here at Sophos Labs for a Threat Researcher role to join our global team of Behavioral Protection engineers, to hunt, to research, and to add real-time protection for suspicious activity across our customer environments. Our team of skilled security experts combine their passion to detect & disrupt cyber-attacks with their capability to develop protection rules that can cut through the noise in modern computing environments to tease out attacker’s nefarious activities. You are intrinsically motivated to understand the core logic behind malware and hacking attacks, to find & predict new ways attackers will modify their techniques and take great satisfaction in developing robust protection logic that is immune to evasive actions. You will be responsible for writing behavioral protection rules that are able to block malicious activities across all types of TTP (even if a Mitre Technique doesn’t exist yet). This is the foundation of Sophos next-gen approach. Above all - you enjoy thinking creatively; combining your deep technical knowledge, your tenacity for innovation, and your can-do attitude to solve complex and challenging problems on daily basis. Additionally, you will also be supporting our remediation effort to remove artifacts left behind, by writing cleanup rules, and supporting our Sandbox development, such as (but not limited to) creating signatures, identifying evasion techniques that prevent the sandbox from running the threat smoothly.
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com. Role Summary We are seeking a detail-oriented and technically skilled Detection Engineer to join our X-OPS team. In this role, you will be responsible for analyzing advanced security threats—ranging from malware to complex web attacks—and translating threat intelligence into high-fidelity detections across our platform. Your work will help ensure our analysts and clients receive highly accurate, actionable alerts with minimal noise. You will leverage data from over 40 third-party and internal sources, partner with our CTU Threat Intelligence team, and use a range of scripting and automation tools to strengthen detection capabilities. The ideal candidate is a hands-on security practitioner with a deep understanding of endpoint behavior, malware analysis, and detection development who thrives in fast-paced, technical environments.
YOUR MISSION About the Job Title: Senior JavaScript Security Researcher Position: Full-time | 40 hours per week Location: Amsterdam, Netherlands | Work From home (2-3 days per week in the office) Salary Range: 80.000,- to 100.000,- annually At ThreatFabric, we help the world's leading banks stay ahead of fraudsters, scammers, and cybercriminals. Our technology protects millions of users every day by detecting fraud, malware, and emerging attack techniques before damage is done. As a Senior JavaScript Security Researcher, you'll explore new browser capabilities, uncover detection methods, and turn cutting-edge research into real-world protection used at global scale. Your discoveries won't remain on a whiteboard, they'll directly help safeguard people and businesses around the world As a senior JavaScript Security Researcher, you’ll be responsible for maintaining our FRS web SDKs. Next to that you’ll be driving the new (detection) capabilities of our SDK. This includes detecting and investigating fraud patterns & trends. You’ll be working closely with Threat Analysts and Product teams to enhance fraud detection. Part of your job is exploring and experimenting with (new and upcoming) browser APIs, and research how these APIs can be used to create new and novel detections mechanism. This requires a creative and out-of-the-box mindset. Proven experience with browser and JavaScript security research is a plus. The position You should have the ability to research, develop, manage, test, and deploy browser-based JavaScript code in the following areas: * Latest browser fingerprinting tactics * Ability to research the underlying working of browser APIs * Ability tocome up withnovel to use these APIs for detection; this includes looking for anomalies, side channels, and other side effects of these APIs * Creating a production ready web SDK Your daily work is to collaborate with the behaviour and device risk analytics tech team including backend engineers, data scientists and product managers. You are expected to be able to work with minimal guidance as lead research and JavaScript engineer. Since you will be working in a startup environment, passion and motivation are key to success and pleasure at work. Responsibilities Your key responsibilities will include: * Maintaining our FRS web SDKs * Driving the new (detection) capabilities of our SDK * Detecting and investigating fraud patterns & trends * Working closely with Threat Analysts and Product teams to enhance fraud detection * Exploring and experimenting with (new and upcoming) browser APIs * Researching how these APIs can be used to create new and novel detections mechanism What We Offer * A 12-month employment contract with the intention to extend. Subject to mutual satisfaction, this may lead to a permanent position. * A competitive salary that reflects your skills and experience with a salary range between:80.000,- to 100.000,- annually. * 25 Holidays per year * 8% holiday allowance (included in annual salary). * A Pension Scheme. * A stimulating and supportive work environment that encourages growth and development. * The opportunity to make a meaningful impactina rapidly growing tech company. * Flexible Remote / Hybrid work from home options to promote work-life balance. * Flexible working hours. * ActiveThreatFabric events and FitFabric bootcamps. * Active knowledge sharing huddles. YOUR PROFILE Skills and qualifications * 8+ years relevant experience in JavaScript and or framework development. * Familiar with Browser APIs including APIs needed for browser, mouse, keystroke, scroll dynamics. * Able to work with Open Source development workflow using git. * Excellent debugging and problem-solving skills. * Knowledge of Docker is a nice to-have. * Proficient English writing skills to document work and communicate project status. * Be a team player and feel comfortable communicating and collaborating with other team members. Creativity and Innovation: * Generates and implements creative, innovative solutions to complex problems. Problem-Solving: * Communicates solutions clearly and concisely. * Possesses a scale-up mentality where flexibility and adaptability are key. Communication and Interpersonal Skills: * Communicates technical concepts effectively to diverse audiences. * Thrives in collaborative environments, fostering teamwork and cooperation. * Demonstrates empathy and understanding in interpersonal interactions. Continuous Improvement: * Actively seeks opportunities to enhance workplace practices and product quality. * Embraces a mindset of ongoing learning and development to stay ahead of industry trends. Information Security, Business Continuity & Privacy: * Proactively engages in maintaining information security and privacy standards. WHY US? About ThreatFabric At ThreatFabric, we're not just shaping the future of cybersecurity - we're defining it. With our headquartered in the vibrant city of Amsterdam, ThreatFabric stands at the forefront of combating online fraud, mobile malware, and threat intelligence. Costly online scams, fraud and malware attacks are rampant. Victims’ life savings are stolen, but so are their confidence and trust. On top of this, financials' brand and reputation are damaged. Many lack online visibility to trigger prompt reaction, and the industry faces regulatory reimbursement pressure. This is why ThreatFabric provides web and mobile security: scam, fraud and malware detection and prevention, and threat intelligence to be proactive. We help the biggest financial brands protect their customers and their reputation in a world where attacks escalate, and trust erodes. Join Our Dynamic Team Ready to dive into the heart of innovation? Our team is a melting pot of talent, passion, and expertise from all corners of the globe. Behind ThreatFabric's success lies a diverse ensemble of technical experts, data scientists, and thought leaders united by a passion for innovation. With a global perspective and a collaborative spirit, our team leverages innovative technology and thousands of data points to deliver security solutions. As a scale-up, we embrace a scale-up mentality where flexibility, adaptability, and a dynamic approach are essential. Our Core Values At ThreatFabric, our culture is defined by three guiding principles: * One Team: Collaboration fuels our success as we work together to tackle complex challenges. * Continuous Excellence: We're committed to pushing boundaries and exceeding expectations in everything we do. * Customers at the Heart: Our customers are not just clients — they're partners. Their success is our priority. Interested? Are you as excited about this opportunity as we are? We can't wait to hear from you! Apply through the Personio link, and let's make innovation happen together! We aim to fill this vacancy in 2025. What's next? So, you've hit send - what happens now? First, we'll do a screening to ensure we're a good match. If all goes well, you'll be invited for an initial chat with us. Then, there's a second interview, and we may include an assessment to better understand your skills. Ready to take the plunge? Please note: Pre-employment screening is part of our selection proces, together with an technical assessment. We do not accept unsolicited resumes from recruiters or employment agencies.