Malware Analyst 2
Summary
Analyzes malicious code and emerging cyber threats using static/dynamic methods, reverse engineering, and forensic tools to identify threats and recommend mitigations for a defense-focused cyber team.
Responsibilities:
- Conduct static and dynamic analysis of suspicious and malicious code to determine capabilities, behavior, and potential impact.
- Analyze malware execution through host and network monitoring to identify propagation techniques and intrusion-related artifacts.
- Examine audit logs, network traffic, and captured data to identify indicators of compromise and support incident investigations.
- Research operating system-specific exploitation techniques and malware attack vectors.
- Utilize scripting languages, reverse engineering tools, and virtual environments to analyze malicious code.
- Develop technical reports documenting malware capabilities, vulnerabilities, indicators of compromise, and recommended mitigation strategies.
- Create malware signatures, detection rules, and analytical techniques to improve identification and response efforts.
- Correlate data from multiple sources to identify threat actors and emerging threats.
- Collaborate with internal and external partners to develop new malware detection methodologies, processes, and tools.
- Communicate technical findings clearly through written reports and verbal briefings.
- Support continuous monitoring of malware threats across enterprise networks, hosts, mission platforms, and boundary systems.
- Five (5) years of cybersecurity experience.
- Three (3) years of malware analysis experience, including static and dynamic analysis.
- Experience using malware analysis or reverse engineering tools such as Ghidra, Sysinternals, FireEye AX, or similar technologies.
- Experience developing scripts or software using Python, C/C++, Lua, Ruby, or similar languages.
- Experience analyzing host artifacts, network traffic, system logs, and malware behavior to identify indicators of compromise.
- Strong written and verbal communication skills with the ability to produce technical reports and recommend mitigation strategies.
- US citizenship and an active TS/SCI with Polygraph security clearance required
Required Certifications:
- Active DoD 8570 compliance with:
- CSSP Analyst baseline certification
- IAT Level II or Level III certification
- GIAC Certified Forensic Analyst (GCFA) or GIAC Reverse Engineering Malware (GREM) certification.
- Reverse engineering of malware using industry-standard tools.
- Threat hunting and malware detection engineering.
- Development of malware detection signatures and analytical methodologies.
- Experience supporting enterprise cyber defense or Security Operations Center (SOC) environments.