Malware Analyst SME

AGR, LLC

Beltsville (MD)

Hybrid

USD 140,000 - 180,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Department of State is seeking a Malware Senior Engineer, Subject Matter Expert, to support the DSCM program and provide advanced malware analysis capabilities across global networks.

The role requires a strong background in static/dynamic analysis, reverse engineering, and incident response, with the ability to operate under time pressure and deliver actionable guidance to leadership.

Qualifications

  • Bachelor’s degree with 12 years of relevant experience (or 16 years with no degree).
  • Ability to resolve highly complex malware and intrusion issues using host analysis, forensics, and reverse engineering.
  • Experience with static and dynamic malware analysis tools and techniques.
  • Knowledge of IOC and APT threat actors; familiarity with Incident Response Lifecycle.

Responsibilities

  • Provide static and dynamic malware analysis in a 24x7x365 environment.
  • Publish after-action reports, cyber defense techniques, guidance, and incident reports.
  • Respond to suspected or successful cybersecurity breaches and assist with resolution.
  • Assist in training junior analysts and share knowledge with stakeholders.
  • Review, update, and publish cyber incident response plans.

Skills

Malware analysis
Reverse engineering
EDR tools
Splunk
Incident response
Log analysis
Training junior analysts
Cross-functional collaboration
Policy development
Effective communication

Education

Bachelor’s degree
Experience in lieu of degree

Tools

Debuggers
Disassemblers
Unpacking tools
Binary analysis tools
MDE
Tanium

Job description

We are seeking an experienced Malware Senior Engineer, Subject Matter Expert to become part of the Department of State (DoS) Diplomatic Security Cyber Mission (DSCM) program to provide leading cyber and technology security experience to enable innovative, effective and secure business processes.

Location:

Beltsville, MD and Rosslyn, VA. Ideally, looking for someone that can support a hybrid and flexible schedule, in the event of significant cyber incident a continuous on-site presence will be required.

Program Overview

The DSCM program encompasses cyber security, data analytics, engineering, technical, managerial, operational, logistical and administrative support to aid and advise DOS Cyber & Technology Security (CTS) Directorate. This includes protecting a global cyber infrastructure comprising networks, systems, information, and mobile devices all while identifying and responding to cyber risks and threats. Those supporting the DSCM program strive to leverage their expert knowledge and propose creative solutions to real-world cybersecurity challenges.

About the Role
  • Provide static and dynamic malware analysis support in a 24x7x365 environment.
  • Contribute to Shift Change Document.
  • Conduct advance analysis and recommend remediation steps for cybersecurity events and incidents.
  • Publish after-action reports, cyber defense techniques, guidance, and incident reports.
  • Respond to and assist with the resolution of any suspected or successful cybersecurity breach or violation.
  • Share knowledge and intelligence gained from cybersecurity events with stakeholders.
  • Assist with training junior level analysts.
  • Perform analysis of network and host logs.
  • Perform network searches, artifact collection and timeline analysis using a variety of EDR tools.
  • Share in-depth knowledge and intelligence gained from cybersecurity events with stakeholders.
  • Protect against and prevent potential cybersecurity threats and vulnerabilities.
  • Assist in the development and implementation of training programs for malware analysts.
  • Review, draft, edit, update, and publish cyber incident response plans.
Qualifications:
  • Bachelor’s degree and 12 years of relevant experience.
  • An additional 4 years of work experience will be considered in lieu of degree.
  • Ability to resolve highly complex malware and intrusion issues using computer host analysis, forensics, and reverse engineering.
  • Ability to recommend sound counter measures to malware and other malicious type code and applications which exploit customer communication systems.
  • Has knowledge in development of policies and procedures to investigate malware incidents for the entire computer network?
  • Experience with Debuggers, Disassemblers, Unpacking Tools, and Binary analysis tools.
  • Experience with static and dynamic malware analysis tools and techniques.
  • Ability to identify remediation steps for cybersecurity events.
  • Experience with Splunk and EDR tools such as Microsoft Defender for Endpoint (MDE), Tanium.
  • Ability to analyze a variety of Operating System log types.
  • Experience in the development of policies and procedures to investigate malware incidents for the enterprise network.
  • Knowledge of IOCs and APT threat actors.
  • Knowledge of the Incident Response Lifecycle.
  • Knowledge of host and network forensic analysis.
  • Demonstrated strong organizational skills.
  • Proven ability to operate in a time sensitive environment.
  • Proven ability to communicate orally and written; ability to brief (technical/informational) senior leadership.
  • Experience collaborating with cross functional teams.
  • Experience with static and dynamic malware analysis tools and techniques.
  • At least ONE of the following as an active certification:
  • CASP+ CE, CCISO, CCNA Cyber Ops, CCNA-Security, CCNP Security, CEH, CFR, CISA, CISM, CISSP (or Associate), CISSP-ISSAP, CISSP-ISSEP, Cloud+, CySA+, GCED, GCIA, GCIH, GICSP, GSLC, SCYBER.
  • An active Interim Top Secret security clearance w/ SCI eligibility.
Preferred:
  • Understanding of Security Operations Center processes and workings.
  • Experience with ServiceNow Ticketing Software.
  • Experience in the development of policies and procedures to investigate malware incidents for the enterprise network.
  • Experience handling state and national level intrusions.
  • Demonstrated ability to utilize and leverage forensic tools to assist in determining scope and severity of a cybersecurity incident.
  • Knowledge of high- and low-level programming.
  • Experience in developing and delivering comprehensive training programs.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Malware Analyst
Malware Analyst

Peraton • Maryland

On-site
USD 90,000 - 130,000
Heavily subsidized employee benefits coverage
25 days of PTO
Participation in an attractive bonus plan
Senior Malware Analyst (Media, Malware, and Analysis – MMA) MD TS/SCI CI POLY
Senior Malware Analyst (Media, Malware, and Analysis – MMA) MD TS/SCI CI POLY

SIXGEN • Annapolis (MD)

On-site
USD 140,000 - 180,000
Senior Malware Analyst & IR SME
Senior Malware Analyst & IR SME

AGR, LLC • Beltsville (MD)

Hybrid
USD 140,000 - 180,000
Senior Malware Engineer / Active Top Secret
Senior Malware Engineer / Active Top Secret

Peraton • Virginia (IL)

Hybrid
USD 130,000 - 180,000
Cyber Security Engineer (SSB)
Cyber Security Engineer (SSB)

Twenty8 Technology, LLC • Arlington (VA), Northern (KY)

Hybrid
USD 150,000 - 175,000
Security Specialist
Security Specialist

Lcibest • Alexandria (VA)

On-site
USD 70,000 - 90,000
Media Malware Analyst, Journeyman
Media Malware Analyst, Journeyman

Leidos Inc • Odenton (MD)

On-site
USD 90,000 - 120,000
Senior Cyber Manager
Senior Cyber Manager

Peraton • Washington

On-site
USD 120,000 - 170,000
Mid-level Malware Engineer / Active Top Secret
Mid-level Malware Engineer / Active Top Secret

Peraton • Virginia (IL)

Hybrid
USD 110,000 - 150,000
Security Analyst- Forensics/Malware Analysis
Security Analyst- Forensics/Malware Analysis

SOSi • Washington

On-site
USD 80,000 - 110,000