Offensive Security Researcher(Malware and Red Teaming)
Summary
Malware & Threat Intelligence Researcher on an Offensive Security team, reverse-engineering malware (PE, .NET, Golang, Rust), tracking APT groups, monitoring darknet forums, and building YARA/Sigma detections and red team tooling.
- Conduct in-depth malware reverse engineering (PE, .NET, Golang, Rust, PowerShell,
Batch, VBS, etc.) - Track APT groups, develop TTP profiles, and perform contextual threat intelligence.
- Develop malware emulators or PoCs and scripts for red team simulations or cyber
ranges. - Monitor darknet forums and marketplaces, and stealer logs for actor trends and breach
intelligence. - Create YARA rules, hunting signatures, and detection logic based on static/dynamic
analysis. - Support threat hunting and detection engineering teams with enriched IOC and
behavioural insights. - Collaborate with internal teams to simulate real-world threats, analyze telemetry, and
produce attack playbooks.
Requirements
- Knowledge of packers, obfuscation, encryption, and anti-debugging techniques
- 5-9 years of hands-on experience in malware analysis, threat research, or reverse
engineering. - Experience with APT tracking, malware campaign documentation, or C2 hunting.
- Published research/blogs on threat campaigns is a plus
- Bachelor's degree in engineering, Computer Applications, Cybersecurity, or related field.
- Certifications like GIAC GREM, CRTIA, or similar are a plus
- Reverse engineering: Ghidra, IDA Pro, x64dbg, OllyDbg
- Scripting: C++, Golang, Python
- Malware Analysis: PEStudio, ProcMon, Wireshark, FakeNet, Any.Run
- Threat Intel: FOFA, Validin, Censys, VirusTotal, Telegram, Darknet forums
- YARA, Sigma, OSINT tools
- Familiarity with MITRE ATT&CK framework and Threat Intel Platforms (TIPs)
- Understanding of EDR tampering, living-off-the-land binaries (LOLBins), C2
infrastructure
Benefits
- Work on high-impact cyber defense and cyberwarfare initiatives.
- Publish and present your research to a global audience.
- Collaborate with National Cybersecurity Coordinator’s Office, CERT-IN, DRDO, and
- other National Security Agencies focused on Cybersecurity.
- Enjoy flexibility, innovation-driven culture, and recognition for thought leadership.