← Back to jobs
P

Senior Windows Malware Security Researcher

On-siteFull-timeSecurity EngineeringCybersecurity

Research advanced Windows malware and APT threats, analyze operating system internals, and develop production-ready protection capabilities for an endpoint detection and response product.

Responsibilities

  • Research Windows operating system internals and advanced malware
  • Analyze malware samples using static and dynamic reverse-engineering techniques
  • Design protection components and prevention rules for an EDR agent
  • Develop and validate malware and APT mitigation capabilities
  • Lead protection concepts from research and proof of concept to production-ready specifications
  • Respond to malware-related security events in client networks
  • Track emerging malware and APT techniques
  • Provide product feedback based on customer feature requests
  • Create test cases and analyze edge cases for handoff to engineering teams
  • Collaborate with researchers and engineers on complex Windows internals and reverse-engineering problems

Requirements

  • At least 5 years of cybersecurity research experience
  • At least 3 years of hands-on Windows user-mode and kernel-mode research
  • Strong C/C++ and Win32 API development experience on Windows
  • Experience with anti-debugging, anti-virtualization, and unpacking techniques
  • Strong knowledge of APTs and modern malware techniques
  • Dynamic analysis experience with Windows debuggers
  • Static analysis experience with IDA Pro, Ghidra, or similar tools
  • Proficiency in Python
  • Knowledge of networking and internet protocols
  • Ability to independently lead research from scoping through proof of concept and production handoff

Nice to have

  • Experience with EDR or XDR products
  • Windows kernel development experience
  • Low-level security solution development
  • Windows exploitation or vulnerability research experience

Relevance

More opportunities

Similar jobs

The newest open roles in Security Engineering.

Questions, answered

Frequently asked questions