SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Recorded Future is the world's largest intelligence company, serving 1,900+ clients with 1,000+ intelligence professionals. You'll join the team behind Triage, Recorded Future's state-of-the-art malware analysis sandbox, as a Senior Malware Analyst.
In this role, you will analyze the latest malware samples and implement new signatures, YARA rules, and features in the sandbox platform. Your research becomes operational intelligence and detection coverage used by security teams worldwide.
Key responsibilities:
- Triage and investigate malware samples surfaced by the sandbox to discover new and emerging malware families
- Perform static and dynamic analysis of malicious samples across Windows, macOS, and/or Android platforms
- Write and maintain YARA rules to reliably detect malware families and variants
- Develop and maintain configuration extractors to pull actionable intelligence (C2 servers, campaign IDs, encryption keys, etc.) from malware samples
- Validate and tune detections to minimize false positives
- Improve analysis methodology and tooling
- Influence sandbox features based on malware research findings
You'll work asynchronously and independently, contributing to a platform used by security teams globally. The role offers the opportunity to shape the future of malware detection and analysis capabilities.
REQUIREMENTS:
- Solid understanding of how sandbox systems work (behavioral analysis, hooking, monitoring, evasion detection)
- Strong knowledge of internals of Windows, Android, or macOS (multiple platforms a plus): process/memory model, file formats, APIs, OS-level mechanisms abused by malware
- Practical experience writing YARA rules, behavioral detection, and config extractors
- Comfortable working asynchronously and independently
- Familiarity with the Go programming language
- Prior experience contributing to public or private detection rule sets