Senior Incident Response & Malware Reverse Engineer

Elite Workforce Partners

Manila

On-site

PHP 1,200,000 - 2,000,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Elite Workforce Partners is seeking a deeply technical incident responder and malware reverse engineer. This hands-on role investigates sophisticated security incidents, analyzes malicious code, and translates findings into containment actions and durable detections.

The position is a hands-on individual contributor role, not focused on SOC management, governance, or vulnerability management. You will investigate compromises across endpoints, identities, networks, cloud, email and applications.

Qualifications

  • Five or more years hands-on in incident response, forensics, malware analysis or threat hunting.
  • Led significant cybersecurity investigations from alert to recovery.
  • Hands-on malware analysis using static and dynamic techniques.

Responsibilities

  • Serve as primary technical investigator for complex incidents across endpoints, identities, networks and cloud.
  • Analyze telemetry from endpoints, networks, email, SIEM/EDR and cloud services.
  • Develop detections, write code to automate response and containment actions.
  • Produce detailed investigative reports and post-incident reviews.
  • Mentor analysts and contribute to playbooks and tooling improvements.

Skills

Incident response
Malware analysis
Threat hunting
Digital forensics
Reverse engineering
Python scripting
PowerShell
SOC tooling
Communication

Tools

Ghidra
IDA Pro
Binary Ninja
x64dbg
WinDbg

Job description

We are seeking a deeply technical incident responder and malware reverse engineer who can independently investigate sophisticated security incidents, analyze malicious code, and translate findings into containment actions and durable detections.

This is a hands‑on individual-contributor role. It is not primarily a SOC management, governance, compliance, vulnerability‑management, or alert‑monitoring position.

You will personally investigate compromises across endpoints, identities, networks, cloud platforms, email, and applications. When malware is involved, you will perform static and dynamic analysis to determine its capabilities, execution flow, persistence, command‑and‑control behavior, and impact.

You will also develop detections and write code that makes investigations and response actions faster, more reliable, and repeatable.

What You’ll DoIncident Response and Digital Forensics
  • Serve as the primary technical investigator for complex incidents involving malware, compromised accounts, phishing, lateral movement, unauthorized access, persistence, data exfiltration, insider threats, and cloud environments.
  • Lead investigations from initial triage through scoping, containment, eradication, recovery, and post-incident review.
  • Analyze endpoint, identity, network, cloud, application, email, firewall, authentication, SIEM, and EDR telemetry.
  • Build detailed incident timelines and determine root cause, affected systems, attacker actions, persistence mechanisms, and business impact.
  • Acquire and analyze relevant forensic evidence, including memory, disk, event logs, registry artifacts, file-system metadata, process activity, authentication records, and network communications.
  • Recommend and execute containment and remediation actions while preserving evidence and minimizing operational impact.
  • Conduct proactive threat hunts based on attacker behaviors, intelligence, malware findings, and observed gaps in visibility.
Malware Analysis and Reverse Engineering
  • Triage suspicious files, scripts, documents, executables, libraries, and other payloads to determine whether they are malicious.
  • Perform static and dynamic malware analysis in controlled environments.
  • Reverse engineer malicious code using disassemblers, decompilers, debuggers, sandboxes, and supporting analysis tools.
  • Analyze malware execution flow, APIs, configuration data, persistence, process injection, credential access, evasion, encryption, network protocols, and command-and-control behavior.
  • Identify packing, obfuscation, anti-analysis, and anti-debugging techniques and work through them when necessary.
  • Produce clear technical findings, behavioral indicators, IOCs, YARA rules, detection logic, and response recommendations.
  • Connect malware behavior to host and network evidence to determine how an intrusion occurred and what the attacker accomplished.
Detection Engineering and Automation
  • Develop and tune SIEM queries, correlation rules, behavioral detections, alerts, dashboards, and enrichment workflows.
  • Translate incident and malware-analysis findings into durable endpoint, identity, network, email, and cloud detections.
  • Write maintainable Python and PowerShell code to automate evidence collection, enrichment, triage, containment, and reporting.
  • Build integrations among security platforms using REST APIs, webhooks, JSON, and other structured data.
  • Develop and maintain SOAR workflows and automated incident-response actions.
  • Review existing telemetry, detections, and response processes to identify visibility gaps and opportunities for improvement.
  • Apply sound engineering practices, including Git-based version control, testing, code review, structured logging, documentation, reusable design, and error handling.
Collaboration and Technical Leadership
  • Work directly with security, infrastructure, cloud, application, and software-engineering teams during investigations and remediation.
  • Provide technical leadership during major incidents while remaining directly involved in evidence analysis.
  • Produce detailed incident reports, malware-analysis reports, investigative notes, and response playbooks.
  • Conduct post-incident reviews and translate lessons learned into improved detections, tools, processes, and security controls.
  • Mentor analysts and share technical knowledge while remaining a hands‑on practitioner.
Required Qualifications
  • Five or more years of hands‑on experience in incident response, digital forensics, malware analysis, threat hunting, or a closely related technical security discipline.
  • Demonstrated experience personally leading significant cybersecurity investigations from initial alert through containment and recovery.
  • Hands‑on malware‑analysis experience, including both static and dynamic analysis of malicious or suspicious files.
  • Practical reverse‑engineering experience using tools such as Ghidra, IDA Pro, Binary Ninja, x64dbg, WinDbg, or comparable tools.
  • Working knowledge of assembly language, executable formats, Windows internals, processes, threads, memory, APIs, and common malware behaviors.
  • Experience analyzing persistence, process injection, command execution, credential access, lateral movement, defense evasion, and command‑and‑control activity.
  • Strong understanding of Windows forensic artifacts and working knowledge of Linux systems.
  • Experience analyzing memory, disk, endpoint telemetry, authentication records, network traffic, or other forensic evidence.
  • Ability to convert investigative and malware findings into IOCs, behavioral detections, hunting queries, or YARA rules.
  • Proficiency in Python, PowerShell, or another language used to develop investigation and response tooling.
  • Experience developing security scripts, integrations, or automation—not solely operating commercial security products.
  • Advanced experience with SIEM and EDR technologies and the ability to write complex investigative queries and detection logic.
  • Strong understanding of the incident‑response lifecycle, MITRE ATT&CK, attacker tradecraft, evidence handling, containment, and remediation.
  • Ability to explain complex technical findings clearly to technical teams, leadership, and business stakeholders.
  • Strong written English and experience producing detailed technical reports and investigative documentation.
Preferred Qualifications
  • Advanced malware reverse engineering involving packed or obfuscated samples, custom network protocols, ransomware, loaders, credential stealers, remote‑access tools, or multi‑stage payloads.
  • Experience with memory forensics using tools such as Volatility or comparable frameworks.
  • Experience with network forensics and tools such as Wireshark, Zeek, or comparable technologies.
  • Experience creating YARA, Sigma, or platform‑specific endpoint and SIEM detections.
  • Familiarity with Microsoft Sentinel, Microsoft Defender, CrowdStrike, Carbon Black, Splunk, QRadar, or comparable platforms.
  • Experience with Azure, AWS, Microsoft 365, Entra ID, Active Directory, and cloud audit logging.
  • Experience developing SOAR playbooks, internal security applications, enrichment services, or case‑management integrations.
  • Familiarity with secure development, DevOps, or CI/CD practices.
  • Relevant certifications such as GREM, GCIH, GCFA, GCIA, GNFA, OSCP, CISSP, SC-200, or equivalent demonstrated expertise.

Certifications are valued, but demonstrated investigative and reverse‑engineering ability is more important.

About the Role

We are seeking a deeply technical incident responder and malware reverse engineer who can independently investigate sophisticated security incidents, analyze malicious code, and translate findings into containment actions and durable detections.

This is a hands‑on individual‑contributor role. It is not primarily a SOC management, governance, compliance, vulnerability‑management, or alert‑monitoring position.

You will personally investigate compromises across endpoints, identities, networks, cloud platforms, email, and applications. When malware is involved, you will perform static and dynamic analysis to determine its capabilities, execution flow, persistence, command‑and‑control behavior, and impact.

You will also develop detections and write code that makes investigations and response actions faster, more reliable, and repeatable.

What Strong Candidates Can Demonstrate

During the interview process, candidates should be prepared to discuss:

  • A complex incident they personally investigated from initial detection through containment and recovery.
  • The evidence and forensic artifacts they personally examined.
  • How they established the incident’s scope, timeline, root cause, and attacker actions.
  • A malware sample they personally analyzed or reverse engineered, including the tools and methodology they used.
  • How they identified the malware’s behavior, persistence, communications, or evasion capabilities.
  • How their analysis resulted in containment actions, detections, hunting logic, IOCs, or preventive controls.
  • A security tool, integration, or automation they personally designed and coded.

Candidates may describe prior work in a sanitized form and should not disclose confidential, proprietary, or classified information.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Incident Response & Malware Analysis Engineer
Lead Incident Response & Malware Analysis Engineer

Elite Workforce Partners • Manila

On-site
PHP 1,200,000 - 2,000,000
Senior Malware Reverse Engineer
Senior Malware Reverse Engineer

IBM • Quezon City

On-site
PHP 900,000 - 1,500,000
Junior Cyber Threat Analyst
Junior Cyber Threat Analyst

Infinit-O • Philippines

On-site
PHP 300,000 - 540,000
Cybersecurity and Incident Response Specialist
Cybersecurity and Incident Response Specialist

Accenture in the Philippines • Mandaluyong

On-site
PHP 900,000 - 1,400,000
IT Security Analyst
IT Security Analyst

CallTek • Cebu City

On-site
PHP 200,000 - 360,000
Senior Incident Response (IR) Analyst
Senior Incident Response (IR) Analyst

TrendMicro • Manila

On-site
PHP 1,200,000 - 1,800,000
IT Security Analyst
IT Security Analyst

IBEX Global Solutions (Philippines) Inc. • Davao del Sur

On-site
PHP 420,000 - 560,000
IT Security Analyst
IT Security Analyst

Ibex Limited • Davao del Sur

On-site
PHP 480,000 - 840,000
IT Security Specialist
IT Security Specialist

Ibex Limited • Manila

On-site
PHP 600,000 - 900,000
Technical Writer
Technical Writer

Create Synergies Inc. • Pasay

On-site
PHP 400,000 - 800,000