About the Role
We are seeking a deeply technical incident responder and malware reverse engineer who can independently investigate sophisticated security incidents, analyze malicious code, and translate findings into containment actions and durable detections.
This is a hands-on individual-contributor role. It is not primarily a SOC management, governance, compliance, vulnerability-management, or alert-monitoring position.
You will personally investigate compromises across endpoints, identities, networks, cloud platforms, email, and applications. When malware is involved, you will perform static and dynamic analysis to determine its capabilities, execution flow, persistence, command-and-control behavior, and impact.
You will also develop detections and write code that makes investigations and response actions faster, more reliable, and repeatable.
What You'll DoIncident Response and Digital Forensics
- Serve as the primary technical investigator for complex incidents involving malware, compromised accounts, phishing, lateral movement, unauthorized access, persistence, data exfiltration, insider threats, and cloud environments.
- Lead investigations from initial triage through scoping, containment, eradication, recovery, and post-incident review.
- Analyze endpoint, identity, network, cloud, application, email, firewall, authentication, SIEM, and EDR telemetry.
- Build detailed incident timelines and determine root cause, affected systems, attacker actions, persistence mechanisms, and business impact.
- Acquire and analyze relevant forensic evidence, including memory, disk, event logs, registry artifacts, file-system metadata, process activity, authentication records, and network communications.
- Recommend and execute containment and remediation actions while preserving evidence and minimizing operational impact.
- Conduct proactive threat hunts based on attacker behaviors, intelligence, malware findings, and observed gaps in visibility.
Malware Analysis and Reverse Engineering
- Triage suspicious files, scripts, documents, executables, libraries, and other payloads to determine whether they are malicious.
- Perform static and dynamic malware analysis in controlled environments.
- Reverse engineer malicious code using disassemblers, decompilers, debuggers, sandboxes, and supporting analysis tools.
- Analyze malware execution flow, APIs, configuration data, persistence, process injection, credential access, evasion, encryption, network protocols, and command-and-control behavior.
- Identify packing, obfuscation, anti-analysis, and anti-debugging techniques and work through them when necessary.
- Produce clear technical findings, behavioral indicators, IOCs, YARA rules, detection logic, and response recommendations.
- Connect malware behavior to host and network evidence to determine how an intrusion occurred and what the attacker accomplished.
Detection Engineering and Automation
- Develop and tune SIEM queries, correlation rules, behavioral detections, alerts, dashboards, and enrichment workflows.
- Translate incident and malware-analysis findings into durable endpoint, identity, network, email, and cloud detections.
- Write maintainable Python and PowerShell code to automate evidence collection, enrichment, triage, containment, and reporting.
- Build integrations among security platforms using REST APIs, webhooks, JSON, and other structured data.
- Develop and maintain SOAR workflows and automated incident-response actions.
- Review existing telemetry, detections, and response processes to identify visibility gaps and opportunities for improvement.
- Apply sound engineering practices, including Git-based version control, testing, code review, structured logging, documentation, reusable design, and error handling.
Collaboration and Technical Leadership
- Work directly with security, infrastructure, cloud, application, and software-engineering teams during investigations and remediation.
- Provide technical leadership during major incidents while remaining directly involved in evidence analysis.
- Produce detailed incident reports, malware-analysis reports, investigative notes, and response playbooks.
- Conduct post-incident reviews and translate lessons learned into improved detections, tools, processes, and security controls.
- Mentor analysts and share technical knowledge while remaining a hands-on practitioner.
Required Qualifications
- Five or more years of hands-on experience in incident response, digital forensics, malware analysis, threat hunting, or a closely related technical security discipline.
- Demonstrated experience personally leading significant cybersecurity investigations from initial alert through containment and recovery.
- Hands-on malware-analysis experience, including both static and dynamic analysis of malicious or suspicious files.
- Practical reverse-engineering experience using tools such as Ghidra, IDA Pro, Binary Ninja, x64dbg, WinDbg, or comparable tools.
- Working knowledge of assembly language, executable formats, Windows internals, processes, threads, memory, APIs, and common malware behaviors.
- Experience analyzing persistence, process injection, command execution, credential access, lateral movement, defense evasion, and command-and-control activity.
- Strong understanding of Windows forensic artifacts and working knowledge of Linux systems.
- Experience analyzing memory, disk, endpoint telemetry, authentication records, network traffic, or other forensic evidence.
- Ability to convert investigative and malware findings into IOCs, behavioral detections, hunting queries, or YARA rules.
- Proficiency in Python, PowerShell, or another language used to develop investigation and response tooling.
- Experience developing security scripts, integrations, or automation—not solely operating commercial security products.
- Advanced experience with SIEM and EDR technologies and the ability to write complex investigative queries and detection logic.
- Strong understanding of the incident-response lifecycle, MITRE ATT&CK, attacker tradecraft, evidence handling, containment, and remediation.
- Ability to explain complex technical findings clearly to technical teams, leadership, and business stakeholders.
- Strong written English and experience producing detailed technical reports and investigative documentation.
Preferred Qualifications
- Advanced malware reverse engineering involving packed or obfuscated samples, custom network protocols, ransomware, loaders, credential stealers, remote-access tools, or multi-stage payloads.
- Experience with memory forensics using tools such as Volatility or comparable frameworks.
- Experience with network forensics and tools such as Wireshark, Zeek, or comparable technologies.
- Experience creating YARA, Sigma, or platform-specific endpoint and SIEM detections.
- Familiarity with Microsoft Sentinel, Microsoft Defender, CrowdStrike, Carbon Black, Splunk, QRadar, or comparable platforms.
- Experience with Azure, AWS, Microsoft 365, Entra ID, Active Directory, and cloud audit logging.
- Experience developing SOAR playbooks, internal security applications, enrichment services, or case-management integrations.
- Familiarity with secure development, DevOps, or CI/CD practices.
- Relevant certifications such as GREM, GCIH, GCFA, GCIA, GNFA, OSCP, CISSP, SC-200, or equivalent demonstrated expertise.
Certifications are valued, but demonstrated investigative and reverse-engineering ability is more important.
What Strong Candidates Can Demonstrate
During the interview process, candidates should be prepared to discuss:
- A complex incident they personally investigated from initial detection through containment and recovery.
- The evidence and forensic artifacts they personally examined.
- How they established the incident's scope, timeline, root cause, and attacker actions.
- A malware sample they personally analyzed or reverse engineered, including the tools and methodology they used.
- How they identified the malware's behavior, persistence, communications, or evasion capabilities.
- How their analysis resulted in containment actions, detections, hunting logic, IOCs, or preventive controls.
- A security tool, integration, or automation they personally designed and coded.
- How their work measurably improved investigation quality, response time, or detection coverage.
Candidates may describe prior work in a sanitized form and should not disclose confidential, proprietary, or classified information.