Vulnerability/Malware Researcher (Reverse Engineer)

Arlington, VA
Full Time
Experienced

We are seeking a highly skilled Vulnerability/Malware Researcher (Reverse Engineer) to identify, analyze, and understand complex software vulnerabilities and malicious code that may impact organizational systems, products, and infrastructure. This role will conduct in-depth malware analysis, reverse engineer software and firmware, uncover exploitable weaknesses, and provide actionable intelligence to support detection, response, and remediation efforts.

The ideal candidate possesses strong low-level programming knowledge, reverse engineering expertise, and experience analyzing sophisticated malware, exploit techniques, and advanced adversary tradecraft.

Key Responsibilities

Malware Analysis & Reverse Engineering

  • Perform static and dynamic analysis of malicious software, including ransomware, trojans, rootkits, spyware, and advanced persistent threat (APT) malware.

  • Reverse engineer malware samples to identify functionality, persistence mechanisms, command-and-control (C2) communications, and attacker objectives.

  • Develop detailed malware analysis reports and technical documentation.

  • Research evolving malware techniques and adversary capabilities.

Vulnerability Research

  • Identify and analyze software, operating system, firmware, and application vulnerabilities.

  • Perform code analysis to discover security weaknesses and exploit paths.

  • Research emerging vulnerabilities and assess organizational exposure.

  • Validate security findings through proof-of-concept testing and exploit analysis.

  • Collaborate with remediation teams to prioritize and mitigate identified risks.

Security Research & Threat Analysis

  • Investigate adversary tactics, techniques, and procedures (TTPs).

  • Analyze exploit kits, attack frameworks, and intrusion methods used by threat actors.

  • Support intelligence-driven security initiatives through technical research and threat assessments.

  • Correlate research findings with threat intelligence and incident response investigations.

Detection Development

  • Create and maintain Indicators of Compromise (IOCs), YARA rules, Sigma rules, and detection signatures.

  • Develop behavioral detections and analytic content for Security Operations Center (SOC) use.

  • Assist threat hunting teams by providing technical indicators and adversary insights.

  • Enhance detection coverage based on research findings and threat trends.

Research Tool Development

  • Develop custom scripts, automation tools, and utilities to support malware analysis and vulnerability research.

  • Improve reverse engineering workflows through automation and tooling enhancements.

  • Maintain secure malware analysis laboratories and research environments.

  • Evaluate emerging security research technologies and platforms.

Collaboration & Reporting

  • Partner with Incident Response, Threat Intelligence, SOC, Product Security, and Engineering teams.

  • Present technical findings to security leadership and engineering stakeholders.

  • Produce technical reports, white papers, and research briefings.

  • Contribute to internal knowledge bases and security best practices.

Required Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical field, or equivalent experience.

  • 3-8 years of experience in malware analysis, reverse engineering, vulnerability research, or offensive security.

  • Strong understanding of operating system internals, including Windows and Linux.

  • Experience reverse engineering compiled software using industry-standard tools.

  • Knowledge of assembly language (x86, x64, ARM) and executable file formats.

  • Proficiency in at least one programming language such as Python, C, C++, Rust, or Go.

  • Experience analyzing malware behavior through static and dynamic analysis techniques.

  • Understanding of software exploitation concepts, memory corruption vulnerabilities, and attack methodologies.

  • Strong analytical, problem-solving, and investigative skills.

Preferred Qualifications

  • Experience researching zero-day vulnerabilities or advanced exploitation techniques.

  • Knowledge of cloud platforms including Azure, AWS, and Google Cloud.

  • Experience with mobile application, embedded system, or firmware analysis.

  • Familiarity with nation-state threat actor methodologies and advanced cyber campaigns.

  • Experience supporting government, defense, intelligence community, or critical infrastructure environments.

  • Understanding of exploit development methodologies.

Share

Apply for this position

Required*
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

Human Check*