Vulnerability/Malware Researcher (Reverse Engineer)

Omniscius

Arlington (VA)

On-site

USD 110,000 - 170,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Omniscius is seeking a highly skilled Vulnerability/Malware Researcher (Reverse Engineer) in the United States to identify, analyze, and understand complex software vulnerabilities and malicious code affecting systems, products, and infrastructure.

The role involves in-depth malware analysis, reverse engineering, and collaboration across Incident Response, Threat Intelligence, and Engineering to support detection, response, and remediation efforts.

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Computer Engineering, or related field, or equivalent experience.
  • 3–8 years of malware analysis, reverse engineering, vulnerability research, or offensive security.
  • Strong understanding of OS internals (Windows and Linux).
  • Experience reverse engineering compiled software with industry tools.
  • Knowledge of assembly (x86/x64/ARM) and executable formats.
  • Proficiency in at least one language such as Python, C, C++, Rust, or Go.
  • Experience analyzing malware behavior via static and dynamic analysis.
  • Understanding of software exploitation concepts and attack methodologies.

Responsibilities

  • Perform static and dynamic analysis of malicious software including ransomware, trojans, rootkits, spyware, and APT malware.
  • Reverse engineer malware samples to identify functionality, persistence, C2 communications, and attacker objectives.
  • Develop detailed malware analysis reports and technical documentation.
  • Research evolving malware techniques and adversary capabilities.
  • Identify and analyze software, OS, firmware, and application vulnerabilities.
  • Perform code analysis to discover security weaknesses and exploit paths.
  • Validate security findings through PoC testing and exploit analysis.
  • Collaborate with remediation teams to prioritize and mitigate identified risks.
  • Investigate adversary TTPs and analyze exploit kits, attack frameworks, and intrusion methods.
  • Support intelligence-driven security initiatives through research and threat assessments.
  • Create and maintain IOCs, YARA rules, Sigma rules, and detection signatures.
  • Develop detections for SOC use and assist threat hunting with indicators.
  • Develop custom scripts and tooling to support malware analysis and vulnerability research.
  • Present findings to security leadership and engineering stakeholders.

Skills

Malware analysis
Reverse engineering
Operating system internals
Programming languages
Exploit development concepts
Behavioral analysis of malware
Analytical problem solving

Education

Bachelor's degree in Computer Science or related field
Equivalent experience

Job description

We are seeking a highly skilled Vulnerability/Malware Researcher (Reverse Engineer) to identify, analyze, and understand complex software vulnerabilities and malicious code that may impact organizational systems, products, and infrastructure. This role will conduct in-depth malware analysis, reverse engineer software and firmware, uncover exploitable weaknesses, and provide actionable intelligence to support detection, response, and remediation efforts.

The ideal candidate possesses strong low-level programming knowledge, reverse engineering expertise, and experience analyzing sophisticated malware, exploit techniques, and advanced adversary tradecraft.

Key Responsibilities
Malware Analysis & Reverse Engineering
  • Perform static and dynamic analysis of malicious software, including ransomware, trojans, rootkits, spyware, and advanced persistent threat (APT) malware.
  • Reverse engineer malware samples to identify functionality, persistence mechanisms, command-and-control (C2) communications, and attacker objectives.
  • Develop detailed malware analysis reports and technical documentation.
  • Research evolving malware techniques and adversary capabilities.
Vulnerability Research
  • Identify and analyze software, operating system, firmware, and application vulnerabilities.
  • Perform code analysis to discover security weaknesses and exploit paths.
  • Research emerging vulnerabilities and assess organizational exposure.
  • Validate security findings through proof-of-concept testing and exploit analysis.
  • Collaborate with remediation teams to prioritize and mitigate identified risks.
Security Research & Threat Analysis
  • Investigate adversary tactics, techniques, and procedures (TTPs).
  • Analyze exploit kits, attack frameworks, and intrusion methods used by threat actors.
  • Support intelligence-driven security initiatives through technical research and threat assessments.
  • Correlate research findings with threat intelligence and incident response investigations.
Detection Development
  • Create and maintain Indicators of Compromise (IOCs), YARA rules, Sigma rules, and detection signatures.
  • Develop behavioral detections and analytic content for Security Operations Center (SOC) use.
  • Assist threat hunting teams by providing technical indicators and adversary insights.
  • Enhance detection coverage based on research findings and threat trends.
Research Tool Development
  • Develop custom scripts, automation tools, and utilities to support malware analysis and vulnerability research.
  • Improve reverse engineering workflows through automation and tooling enhancements.
  • Maintain secure malware analysis laboratories and research environments.
  • Evaluate emerging security research technologies and platforms.
Collaboration & Reporting
  • Partner with Incident Response, Threat Intelligence, SOC, Product Security, and Engineering teams.
  • Present technical findings to security leadership and engineering stakeholders.
  • Produce technical reports, white papers, and research briefings.
  • Contribute to internal knowledge bases and security best practices.
Required Qualifications
  • Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical field, or equivalent experience.
  • 3-8 years of experience in malware analysis, reverse engineering, vulnerability research, or offensive security.
  • Strong understanding of operating system internals, including Windows and Linux.
  • Experience reverse engineering compiled software using industry-standard tools.
  • Knowledge of assembly language (x86, x64, ARM) and executable file formats.
  • Proficiency in at least one programming language such as Python, C, C++, Rust, or Go.
  • Experience analyzing malware behavior through static and dynamic analysis techniques.
  • Understanding of software exploitation concepts, memory corruption vulnerabilities, and attack methodologies.
  • Strong analytical, problem-solving, and investigative skills.
Preferred Qualifications
  • Experience researching zero-day vulnerabilities or advanced exploitation techniques.
  • Knowledge of cloud platforms including Azure, AWS, and Google Cloud.
  • Experience with mobile application, embedded system, or firmware analysis.
  • Familiarity with nation-state threat actor methodologies and advanced cyber campaigns.
  • Experience supporting government, defense, intelligence community, or critical infrastructure environments.
  • Understanding of exploit development methodologies.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vulnerability/Malware Researcher (Reverse Engineer)
Vulnerability/Malware Researcher (Reverse Engineer)

Omniscius Consulting • Arlington (VA)

On-site
USD 120,000 - 160,000
Vulnerability & Malware Researcher (Reverse Engineer)
Vulnerability & Malware Researcher (Reverse Engineer)

Rippling, Inc. • Arlington (VA)

On-site
USD 120,000 - 180,000
Senior Vulnerability & Malware Researcher (Reverse Engineer)
Senior Vulnerability & Malware Researcher (Reverse Engineer)

Rippling, Inc. • Arlington (VA)

On-site
USD 120,000 - 180,000
Malware Researcher & Vulnerability Investigator
Malware Researcher & Vulnerability Investigator

Omniscius Consulting • Arlington (VA)

On-site
USD 120,000 - 160,000
Cyber Threat Detection Engineer (Reverse Engineering)
Cyber Threat Detection Engineer (Reverse Engineering)

Partner Forces LLC • Arlington (VA)

On-site
USD 120,000 - 180,000
Reverse Engineer
Reverse Engineer

Synergy ECP • Columbia (MD)

On-site
USD 120,000 - 180,000
Senior Reverse Engineer, BS+ 11 yrs
Senior Reverse Engineer, BS+ 11 yrs

Link, LLC • Fort Meade (MD)

On-site
USD 100,000 - 130,000
Senior Malware & Vulnerability Researcher
Senior Malware & Vulnerability Researcher

Omniscius • Arlington (VA)

On-site
USD 110,000 - 170,000
Senior Malware Analyst - Cyber Defense & Mission Assurance
Senior Malware Analyst - Cyber Defense & Mission Assurance

Strategic Ventures Consulting Group • Fort Meade (MD)

On-site
USD 85,000 - 180,000
X-Day Offensive Research (XOR) Vulnerability Researcher
X-Day Offensive Research (XOR) Vulnerability Researcher

JPMorgan Chase & Co. • Jersey City (NJ)

On-site
USD 150,000 - 230,000