Vulnerability/Malware Researcher (Reverse Engineer)

Socket.dev

Arlington (VA)

Hybrid

USD 160,000 - 180,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Everforth ECS in Arlington, VA (Hybrid) seeks a seasoned Vulnerability/Malware Researcher (Reverse Engineer) to identify, analyze, and understand complex software vulnerabilities and malicious code impacting systems and infrastructure.

You will conduct in-depth malware analysis, reverse engineer software and firmware, and perform TTP analysis to uncover exploitable weaknesses, providing actionable intelligence to improve detection, response, and remediation.

Qualifications

  • 7+ years of malware analysis, reverse engineering, vulnerability research, or offensive security.
  • Strong understanding of operating system internals (Windows & Linux).
  • Familiarity with MITRE ATT&CK framework and threat intelligence concepts.
  • Experience reverse engineering compiled software with industry-standard tools.
  • Knowledge of assembly language (x86/x64/ARM) and executable formats.
  • Proficiency in at least one language such as Python, C, C++, Rust, or Go.
  • Experience analyzing malware behavior using static and dynamic techniques.
  • Understanding of software exploitation and memory corruption concepts.

Responsibilities

  • Perform static and dynamic analysis of malware (ransomware, trojans, rootkits, spyware, APT).
  • Reverse engineer malware to identify functionality, persistence, C2, and attacker objectives.
  • Develop detailed malware analysis reports and documentation.
  • Research evolving malware techniques and adversary capabilities.
  • Identify and analyze software, OS, firmware, and application vulnerabilities.
  • Perform code analysis to discover security weaknesses and exploit paths.
  • Collaborate with remediation teams to prioritize and mitigate risks.
  • Create and maintain IOCs, YARA rules, Sigma rules, and detection signatures.
  • Develop detection content for SOC use and threat hunting support.
  • Collaborate with Incident Response, Threat Intelligence, SOC, Product Security, and Engineering teams.
  • Present findings to security leadership and engineers; produce research briefs.

Skills

Top Secret Clearance
Malware analysis
Reverse engineering
OS internals
MITRE ATT&CK
Compiled software analysis
Assembly language
Programming: Python/C/C++/Rust/Go
Static/dynamic analysis
Exploitation concepts

Education

Bachelor's degree in Computer Science/Cybersecurity/Computer Engineering or related field

Job description

Everforth ECS is seeking a Vulnerability/Malware Researcher (Reverse Engineer) to join our team in Arlington, VA (Hybrid). This position is contingent upon award.

We are seeking a highly skilled Vulnerability/Malware Researcher (Reverse Engineer) to identify, analyze, and understand complex software vulnerabilities and malicious code that may impact organizational systems, products, and infrastructure. This role will conduct in-depth malware analysis, reverse engineer software and firmware, perform exploitation and tactics, techniques, and procedures (TTPs) analysis to uncover exploitable weaknesses, and provide actionable intelligence to support detection, response, and remediation efforts.

The ideal candidate possesses strong low-level programming knowledge, reverse engineering expertise, and experience analyzing sophisticated malware, exploit techniques, and advanced adversary tradecraft.

Key Responsibilities
Malware Analysis & Reverse Engineering
  • Perform static and dynamic analysis of malicious software, including ransomware, trojans, rootkits, spyware, and advanced persistent threat (APT) malware.
  • Reverse engineer malware samples to identify functionality, persistence mechanisms, command-and-control (C2) communications, and attacker objectives.
  • Develop detailed malware analysis reports and technical documentation.
  • Research evolving malware techniques and adversary capabilities.
Vulnerability Research
  • Identify and analyze software, operating system, firmware, and application vulnerabilities.
  • Perform code analysis to discover security weaknesses and exploit paths.
  • Research emerging vulnerabilities and assess organizational exposure.
  • Validate security findings through proof-of-concept testing and exploit analysis.
  • Collaborate with remediation teams to prioritize and mitigate identified risks.
Security Research & Threat Analysis
  • Investigate adversary tactics, techniques, and procedures (TTPs) on device/service targeting procedures.
  • Analyze exploit kits, attack frameworks, and intrusion methods used by threat actors.
  • Support intelligence-driven security initiatives through technical research and threat assessments.
  • Correlate research findings with threat intelligence and incident response investigations.
Detection Development
  • Create and maintain Indicators of Compromise (IOCs), YARA rules, Sigma rules, and detection signatures.
  • Develop behavioral detections and analytic content for Security Operations Center (SOC) use.
  • Assist threat hunting teams by providing technical indicators and adversary insights.
  • Support development of MITRE ATT&CK procedure-level mapping artifacts.
  • Enhance detection coverage based on research findings and threat trends.
Research Tool Development
  • Develop custom scripts, automation tools, and utilities to support malware analysis and vulnerability research.
  • Improve reverse engineering workflows through automation and tooling enhancements.
  • Maintain secure malware analysis laboratories and research environments.
  • Evaluate emerging security research technologies and platforms.
Collaboration & Reporting
  • Partner with Incident Response, Threat Intelligence, SOC, Product Security, and Engineering teams.
  • Present technical findings to security leadership and engineering stakeholders.
  • Produce technical reports, white papers, and research briefings.
  • Contribute to internal knowledge bases and security best practices.

Salary Range: $160,000 - $180,000

General Description of Benefits

Qualifications
  • Top Secret Clearance
  • Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical field, or equivalent experience.
  • 7+ years of experience in malware analysis, reverse engineering, vulnerability research, or offensive security.
  • Strong understanding of operating system internals, including Windows and Linux.
  • Understanding and familiarity with MITRE ATT&CK framework.
  • Experience reverse engineering compiled software using industry-standard tools.
  • Knowledge of assembly language (x86, x64, ARM) and executable file formats.
  • Proficiency in at least one programming language such as Python, C, C++, Rust, or Go.
  • Experience analyzing malware behavior through static and dynamic analysis techniques.
  • Understanding of software exploitation concepts, memory corruption vulnerabilities, and attack methodologies.
  • Strong analytical, problem-solving, and investigative skills.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Malware & Vulnerability Researcher - Reverse Engineer
Malware & Vulnerability Researcher - Reverse Engineer

Socket.dev • Arlington (VA)

Hybrid
USD 160,000 - 180,000
Malware & Vulnerability Researcher (Reverse Engineer)
Malware & Vulnerability Researcher (Reverse Engineer)

Everforth ECS • Arlington (VA)

Hybrid
USD 140,000 - 180,000
Vulnerability/Malware Researcher (Reverse Engineer)
Vulnerability/Malware Researcher (Reverse Engineer)

Everforth ECS • Arlington (VA)

Hybrid
USD 140,000 - 180,000
ME00590-Reverse Engineer 3
ME00590-Reverse Engineer 3

Momentum Engineering, Inc. • Fort Meade (MD)

On-site
USD 150,000 - 180,000
11 paid holidays
3 weeks PTO
Company sponsored group medical plan
+4
Malware Analyst / Reverse Engineer
Malware Analyst / Reverse Engineer

Bytoa • Columbia (MD)

On-site
USD 200,000 - 215,000
ME00590-Reverse Engineer 4
ME00590-Reverse Engineer 4

Momentum Engineering, Inc • Fort Meade (MD)

On-site
USD 170,000 - 215,000
11 paid holidays
Minimum of 3 weeks PTO
Company sponsored group medical plan
+1
ME00590-Reverse Engineer 4
ME00590-Reverse Engineer 4

Momentum Engineering • Fort Meade (MD)

On-site
USD 170,000 - 215,000
Company sponsored group medical plan
Company paid dental and vision insurance
11 paid holidays
+2
Senior Reverse Engineer, BS+ 11 yrs
Senior Reverse Engineer, BS+ 11 yrs

Link, LLC • Fort Meade (MD)

Hybrid
USD 100,000 - 130,000
ME00590-Reverse Engineer 3
ME00590-Reverse Engineer 3

Momentum Engineering, Inc. • Fort Meade (MD)

On-site
USD 170,000 - 215,000
11 paid holidays
Minimum of 3 weeks PTO
Company sponsored group medical plan
+2
Software Reverse Engineer (TS/SCI)- Senior & Mid
Software Reverse Engineer (TS/SCI)- Senior & Mid

Vexterra Group • Bethesda (MD)

On-site
USD 100,000 - 130,000