
Threat Researcher
Posted Jul 9

Posted Jul 9
This is a fully remote position, open to applicants in United States.
• Conduct both static and dynamic malware analysis utilizing tools like Detect It Easy, System Informer, and API Monitor to construct attack chains and assist in the development of emulations.
• Reverse engineer payloads and scripts to thoroughly document their execution behaviors.
• Develop emulations in programming languages such as C++, PowerShell, C#, and others to simulate malware activities identified during analysis.
• Create detection logic informed by emulations and findings from malware analysis.
• Identify telemetry deficiencies in Sysmon, auditd, EDR, and other data sources to enhance detection capabilities.
• Generate comprehensive technical reports that include executive-level summaries of the findings.
• Debug malware and emulations using tools like x64dbg, WinDbg, or other debugging utilities.
• Assess applications for vulnerabilities using reverse engineering and debugging methodologies.
• Correlate events across incidents and malware activities identified during malware analysis.
• Execute hunt activities from the perspective of detection engineering.
• In-depth knowledge of Splunk Search Processing Language (SPL).
• Proficient in programming languages such as C++, C#, Python, and Perl.
• Skilled in scripting languages including PowerShell, JavaScript, and VBScript.
• Strong grasp of networking principles.
• Solid understanding of Windows and Linux operating system internals.
• Comprehensive health and wellness packages.
• Opportunities for professional development and training.
• Flexible work arrangements.
• Supportive and inclusive work environment.
Julesetmoi
National University
MeridianLink
Get handpicked remote jobs straight to your inbox weekly.