Malware / Reverse Engineer - U

Secure Technologies Group
Washington, DC, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

C++ (Programming Language) Static Program Analysis Cyber Security Computer Networks Python (Programming Language) Lua (Scripting Language) Comptia Pentest+ CE Ruby Reverse Engineering Virtual Machines Scripting Malware
+2 more
Information Technology Fireeye

Job description

SecureTech Malware Engineers make a difference every day in support of the U.S. federal government.

We provide recommendations based on the results of malicious code analysis. We analyze and evaluate malicious code to create technical reports for indicators of compromise and to recommend mitigation and detection actions. We work and train to continually improve current malware analysis techniques, and identify new ways to improve malware identification best practices.

As a SecureTech Malware Engineer these are the types of tasks you can expect to spend your time on:

  • Conducts both dynamic and static analysis of suspicious code in order to establish malicious capability and determine potential impact.
  • Performs analysis on captured data (audit, log, network traffic, etc.) to identify any intrusion-related artifacts.
  • Analyzes malicious code by employing tools, scripting languages, and leveraging virtual machines/environments.
  • Generates documentation of vulnerabilities and exploits used by malware in written reports.
  • Communicates written and verbal information in a timely, clear, and concise manner.
  • Generates technical summary of findings in accordance with established reporting procedures.
  • Develops and recommends mitigation strategies.
  • Develops signatures, techniques, and rules to identify malware vectors.
  • Collaborate with internal and external organizations to discover new threats, develop mitigation techniques, processes, and tools which further the CSSP mission, as directed by the customer.
  • Evaluates emerging threats.
  • Correlate data from multiple sources to identify probable threat actors.

Requirements

  • Bachelor’s degree in Information Technology, Cybersecurity, or a related technical discipline is preferred, but an additional 4 yrs of related experience can substitute for the degree!
  • These positions start with a minimum of two (2) years of relevant experience, up through senior levels.
  • Some experience with with tools such as GHIDRA, SYSInternals, FireEye AX, or similar is a plus. Additionally, a strong candidate will have experience with development of code in languages such as Python, Lua, C/C++, Ruby or similar.

For positions beyond entry level, certifications such as CEH, GCIA, GCIH, CySA+, GCFA, GREM, PenTest+, or CCNA may be required.

Benefits & conditions

Pulled from the full job description

  • Paid time off, We really do consider employees first in decisions. It is hard enough to work through the personal/social/technical hurdles that come with your position as a cleared defense contractor - no need to fight your own employer’s red tape as well.
  • We offer a compensation package that is more than just commensurate with this closed contractor community. We offer generous benefits (PTO, training support, etc) in addition to the high salaries. We know that you know - salary isn’t everything.
  • SecureTech is an Equal Opportunity Employer - we hire the right people for the job - regardless of employment status such as female, minority, protected veterans, individuals with disabilities, etc. Our concern is that you are qualified for the position, and that you are placed in a position in which you can be successful!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler ¡ LIVE

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 ¡ LIVE

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 ¡ Coffee With Developers

1:45 min

Transitioning from software development to security roles

Stefania Chaplin ¡ World Congress 2022

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil ¡ LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all