Senior Threat Behavior Researcher (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Threat Behavior Researcher (Cybersecurity): Researching and developing behavioral protection rules to detect and disrupt cyber-attacks across customer environments with an accent on Windows threat analysis and TTP detection. Focus on creating robust protection logic, analyzing malware evasion techniques, and optimizing sandbox environments.
Location: Remote; applicants must have legal authorization to work in the jurisdiction where the position is posted (UK or Romania) without requiring employer sponsorship.
Company
Global leader in advanced security solutions and the largest pure-play Managed Detection and Response (MDR) provider.
What you will do
- Conduct in-depth behavioral analysis of Windows threats.
- Develop behavioral rules for hands-on keyboard attacks, malware payloads, and APTs.
- Produce quality threat analysis reports for internal and external audiences.
- Improve sandbox capabilities by analyzing anti-analysis and evasion techniques.
- Create cleanup rules to remove artifacts left by malicious activities.
- Mentor and guide junior team members through malware analysis and code reviews.
Requirements
- Strong knowledge of Windows Internals, including Memory management, Processes, and Threads.
- Proficiency in static and dynamic analysis using tools such as IDAPro and WinDbg.
- Demonstrated programming experience, preferably in Python and Lua.
- Bachelor’s degree in computer software (Computer Security preferred) or equivalent experience.
- Legal authorization to work in the UK or Romania without sponsorship.
Culture & Benefits
- Remote-first working model.
- Employee-led diversity and inclusion networks.
- Annual charity and fundraising initiatives and volunteer days.
- Global fitness and trivia competitions.
- Global wellbeing days and monthly health webinars.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →