PrincipalSecurity Researcher I – Malware Research & Detection Engineering
SeqriteLabs powers its offerings with advanced threat research, intelligence, andreal-time detection. Notably, Seqrite secured ISRO’s command & controlcenter during the Chandrayaan 3 mission. Itsservices division provides consulting to corporates, PSUs, government, andlaw enforcement agencies worldwide.
CorePurpose: Innovate to simplify digital security
Vision: To be trustedglobally as a cybersecurity leader
Mission: Empower teamsto solve business problems
Seqritestands out as a purpose-led organization that invests in people, fostersinnovation, and offers opportunities to work on new technologies whilebuilding a safer digital world.
Job Summary
( A brief overview of the role, its purpose, and keyresponsibilities. )
Principal Security Researcherwith expertise in malware analysis, behavioral detection, threat research,and detection engineering for enterprise endpoint security products.Experienced in dynamic malware analysis, reverse engineering, Non-PE threatinvestigation, behavioral signature writing, YARA rule development, threathunting, Root Cause Analysis (RCA), and MITRE ATT&CK mapping acrossWindows environments. Proficient in researching emerging malware families,attacker tradecraft, and developing behavioral, signature-based, andtelemetry-driven detections for EDR/XDR platforms.
Hands-on experience with IDAPro, Ghidra, x64dbg, Process Monitor, Process Explorer, Wireshark, sandboxenvironments, and Windows internals debugging tools for malware investigationand runtime analysis. Experienced in technical documentation, technical blogand white paper authoring, quarterly threat reporting, mentoring researchers,collaborating with engineering teams, presenting technical findings tostakeholders, delivering customer-facing product demonstrations, andleveraging AI-assisted workflows to accelerate malware research, detectiondevelopment, and validation.
Job Responsibilities
(The key tasks and duties you will be expected to perform in thisrole.)
- Perform dynamic and behavioral analysis ofmalware samples, scripts, droppers, loaders, LolBins, Ransomware andfileless threats.
- Reverse engineer suspicious binaries andscripts to identify execution flow, persistence mechanisms, and evasiontechniques.
- Analyze obfuscated PowerShell scripts,encoded payloads, and multi-stage attack chains.
- Perform runtime analysis using process,memory, registry, and network monitoring tools.
- Investigate process injection, registryabuse, scheduled tasks, WMI activity, and command-line basedattacks.
- Research Windows internals includingprocess creation, token manipulation, services, drivers, COM, WMI,Scheduled Tasks, Registry, etc.
- Research malware families, attackertradecraft, and emerging threat techniques affecting Windowsendpoints.
- Research MITRE ATT&CK techniques andmap detections to ATT&CK coverage.
- Perform threat hunting for similar malwarefamily using endpoint telemetry and behavioral indicators.
- Evaluate public threat intelligencereports and convert them into product detections.
- Write behavioral and string-baseddetection signatures for PE and Non-PE threats, malicious scripts, andsuspicious runtime activities.
- Validate detection coverage and tunebehavioral policies to reduce false positives.
- Analyze false positives/false negativesand continuously improve detection efficacy.
- Document the complete attack chain, maptechniques to the MITRE ATT&CK framework, and develop or recommendcomprehensive detection coverage using behavioral, signature-based, andtelemetry-driven detection mechanisms.
- Perform Root Cause Analysis (RCA) forcustomer-reported security incidents by investigating malware behavior,attack vectors, and affected systems.
- Collaborate with threat research andendpoint protection teams on detection improvements.
- Collaborate with engineering teams duringimplementation of detection logic.
- Prepare technical analysis reports fornewly identified malware families and attack techniques.
- Create technical documentation, playbooks,knowledge base articles, and detection documentation.
- Write and publish technical blogs, whitepapers, and quarterly threat intelligence reports.
- Attend and present at international andlocal cybersecurity conferences, workshops, and technical events.
- Mentor junior researchers, conducttechnical knowledge-sharing sessions, and review detection content tomaintain research quality.
- Consolidate team deliverables, prepareprogress reports using pivot tables and other reporting tools, andpresent project status and key metrics to management.
- Present technical reports, projectupdates, research findings, and progress updates to management andinternal stakeholders during review meetings.
- Deliver technical product demonstrations,explain product capabilities, and address technical queries fromcustomers and stakeholders when required.
- Comfortable with content generationrelated to EDR/XDR technology including Policy writing, Simulation,Playbooks and automation.
- Use AI-assisted workflows to acceleratemalware triage, detection generation, and research validation.
Must Have Skills
(The essential skills andexpertise required to succeed in this role.)
Technical Expertise
- MalwareAnalysis & Reverse Engineering
- Static& Dynamic Malware Analysis & Signature Writing
- BehavioralDetection Engineering
- YARARule Development
- Non-PEThreat Analysis
- PowerShell& Script Analysis
- LOLBinsDetection
- MemoryAnalysis & Forensics
- WindowsInternals
- RootCause Analysis of Incidents
- MITREATT&CK Mapping
- DetectionValidation & False Positive Reduction
- ThreatPattern Correlation
- EDR/XDRDetection Content Development
- TechnicalDocumentation & Threat Reporting
- AI-assistedMalware Research
Nice / Good to have skills
(Additional skills that are not mandatory but give you an addedadvantage in this role.)