Vulnerability/Malware Researcher (Reverse Engineer)

Everforth ECS

Arlington (VA)

Hybrid

USD 140,000 - 180,000

Full time

28 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Everforth ECS in Arlington, VA (Hybrid) seeks a Vulnerability/Malware Researcher (Reverse Engineer) to identify, analyze, and understand complex software vulnerabilities and malware. You will perform reverse engineering, malware analysis, and threat hunting to support detection, response, and remediation within federal civilian or defense-focused contexts.

The ideal candidate will possess strong low-level programming knowledge, reverse engineering expertise, and experience analyzing

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, or related field or equivalent experience.
  • 7+ years of malware analysis, reverse engineering, vulnerability research, or offensive security.
  • Strong understanding of Windows and Linux internals.
  • Familiarity with MITRE ATT&CK framework and exploit techniques.
  • Experience reverse engineering software with industry-standard tools.
  • Proficiency in Python, C, C++, Rust, or Go.

Responsibilities

  • Conduct static and dynamic malware analysis of diverse threats, including ransomware and APTs.
  • Reverse engineer samples to reveal functionality, persistence, C2, and attacker goals.
  • Build malware analysis reports and technical documentation.
  • Research evolving malware techniques and adversary capabilities.
  • Identify and analyze software and firmware vulnerabilities and exploit paths.
  • Develop IOCs, YARA/Sigma rules, and detection signatures for SOC use.
  • Collaborate with remediation, threat intelligence, and engineering teams.
  • Develop automated tools to support malware analysis and vulnerability research.

Skills

Malware analysis
Reverse engineering
Low-level programming
Programming languages
OS internals
MITRE ATT&CK
Threat intelligence

Education

Bachelor's degree in CS/Cybersecurity/CE

Job description

Vulnerability/Malware Researcher (Reverse Engineer)

#5050

Job Description

Everforth ECS is seeking a Vulnerability/Malware Researcher (Reverse Engineer) to join our team in Arlington, VA (Hybrid). This position is contingent upon award.

We are seeking a highly skilled Vulnerability/Malware Researcher (Reverse Engineer) to identify, analyze, and understand complex software vulnerabilities and malicious code that may impact organizational systems, products, and infrastructure. This role will conduct in-depth malware analysis, reverse engineer software and firmware, perform exploitation and tactics, techniques, and procedures (TTPs) analysis to uncover exploitable weaknesses, and provide actionable intelligence to support detection, response, and remediation efforts.

The ideal candidate possesses strong low-level programming knowledge, reverse engineering expertise, and experience analyzing sophisticated malware, exploit techniques, and advanced adversary tradecraft.

Key Responsibilities

Malware Analysis & Reverse Engineering

  • Perform static and dynamic analysis of malicious software, including ransomware, trojans, rootkits, spyware, and advanced persistent threat (APT) malware.
  • Reverse engineer malware samples to identify functionality, persistence mechanisms, command-and-control (C2) communications, and attacker objectives.
  • Develop detailed malware analysis reports and technical documentation.
  • Research evolving malware techniques and adversary capabilities.

Vulnerability Research

  • Identify and analyze software, operating system, firmware, and application vulnerabilities.
  • Perform code analysis to discover security weaknesses and exploit paths.
  • Research emerging vulnerabilities and assess organizational exposure.
  • Validate security findings through proof-of-concept testing and exploit analysis.
  • Collaborate with remediation teams to prioritize and mitigate identified risks.

Security Research & Threat Analysis

  • Investigate adversary tactics, techniques, and procedures (TTPs) on device/service targeting procedures.
  • Analyze exploit kits, attack frameworks, and intrusion methods used by threat actors.
  • Support intelligence-driven security initiatives through technical research and threat assessments.
  • Correlate research findings with threat intelligence and incident response investigations.

Detection Development

  • Create and maintain Indicators of Compromise (IOCs), YARA rules, Sigma rules, and detection signatures.
  • Develop behavioral detections and analytic content for Security Operations Center (SOC) use.
  • Assist threat hunting teams by providing technical indicators and adversary insights.
  • Support development of MITRE ATT&CK procedure-level mapping artifacts.
  • Enhance detection coverage based on research findings and threat trends.

Research Tool Development

  • Develop custom scripts, automation tools, and utilities to support malware analysis and vulnerability research.
  • Improve reverse engineering workflows through automation and tooling enhancements.
  • Maintain secure malware analysis laboratories and research environments.
  • Evaluate emerging security research technologies and platforms.
  • Partner with Incident Response, Threat Intelligence, SOC, Product Security, and Engineering teams.
  • Present technical findings to security leadership and engineering stakeholders.
  • Produce technical reports, white papers, and research briefings.
  • Contribute to internal knowledge bases and security best practices.
  • Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical field, or equivalent experience.
  • 7+ years of experience in malware analysis, reverse engineering, vulnerability research, or offensive security.
  • Strong understanding of operating system internals, including Windows and Linux.
  • Understanding and familiarity with MITRE ATT&CK framework.
  • Experience reverse engineering compiled software using industry-standard tools.
  • Knowledge of assembly language (x86, x64, ARM) and executable file formats.
  • Proficiency in at least one programming language such as Python, C, C++, Rust, or Go.
  • Experience analyzing malware behavior through static and dynamic analysis techniques.
  • Understanding of software exploitation concepts, memory corruption vulnerabilities, and attack methodologies.
  • Strong analytical, problem-solving, and investigative skills.
Desired Skills
  • Experience researching zero-day vulnerabilities or advanced exploitation techniques.
  • Knowledge of cloud platforms including Azure, AWS, and Google Cloud.
  • Experience with mobile application, embedded system, or firmware analysis.
  • Familiarity with nation-state threat actor methodologies and advanced cyber campaigns.
  • Experience supporting government, defense, intelligence community, or critical infrastructure environments.

#EverforthECS1

ECSFederal LLCis an equal opportunity employer and does not discriminate or allow discrimination on thebasisany characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or localjurisdictionlaw.

EverforthECS is the federal segment of Everforth , a $4B global organization with over10,000 employees. Ournearly 3,500professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.
Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.
We value:

  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven


Meet the challenge. Make a difference withEverforthECS!

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Everforth ECS is the federal segment of Everforth , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

Meet the challenge. Make a difference with Everforth ECS!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability/Malware Researcher (Reverse Engineer)
Vulnerability/Malware Researcher (Reverse Engineer)

Socket.dev • Arlington (VA)

Hybrid
USD 160,000 - 180,000
Malware & Vulnerability Researcher (Reverse Engineer)
Malware & Vulnerability Researcher (Reverse Engineer)

Everforth ECS • Arlington (VA)

Hybrid
USD 140,000 - 180,000
Malware & Vulnerability Researcher - Reverse Engineer
Malware & Vulnerability Researcher - Reverse Engineer

Socket.dev • Arlington (VA)

Hybrid
USD 160,000 - 180,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

ECS • Virginia (MN)

On-site
USD 130,000 - 160,000
Enterprise Vulnerability Assessment Program- AI Focused
Enterprise Vulnerability Assessment Program- AI Focused

ECS • Washington

On-site
USD 160,000 - 205,000
Cyber Business Analyst
Cyber Business Analyst

Everforth ECS • Arlington (VA)

Hybrid
USD 85,000 - 120,000
Incident Response Lead
Incident Response Lead

ECS • Washington

Hybrid
USD 140,000 - 150,000
Cloud Security Engineer
Cloud Security Engineer

ECS • Arlington (VA)

Hybrid
USD 140,000 - 170,000
Cyber Systems Analyst/Security Specialist
Cyber Systems Analyst/Security Specialist

Everforth ECS • Washington

On-site
USD 120,000 - 180,000
Senior Security Engineer
Senior Security Engineer

ECS • Arlington (VA)

Hybrid
USD 140,000 - 180,000