Malware Reverse Engineer

Posted 11 Hours Ago
Be an Early Applicant
Annapolis Junction, MD, USA
In-Office
Mid level
Information Technology • Consulting • Cybersecurity
The Role
Perform static, dynamic, manual, and automated malware analysis; reverse-engineer compiled code; assess threat capabilities and intent; build analysis environments; collaborate with intelligence professionals; and produce technical reports. The role requires expertise in reverse engineering, operating systems, assembly, debugging, sandboxing, network analysis, malware forensics, and threat intelligence frameworks. Hardware reverse engineering experience is preferred.
Summary Generated by Built In
Be Challenged and Make a Difference 
 
In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched value to our customers and employees through innovative solutions and an engaging culture. 

Description of Task to be Performed:

AnaVation is looking for a talented Malware Reverse Engineer who is passionate about supporting National Security missions. The ideal candidate appreciates partnering with our customer and a group of cybersecurity experts to build environments and analyze the threat actor intent of malware in support of military intelligence missions. This position is full time on-site in Annapolis Junction, Maryland.

Position Responsibilities:

Perform surface, dynamic, static, manual, and automated analysis on malicious software to determine its nature, capabilities, and potential impact. Analyze and reverse-engineer compiled executable code to understand its interactions with the environment and gain intelligence on its function and behavior. Evaluate malware attack capabilities, including transmission characteristics, attributes, and the intended purpose of the software, to understand its threat potential. Work closely with intelligence professionals to interpret the threat's intentions and capabilities and prepare detailed reports and studies on these findings. Additionally, provide technical expertise on the necessary hardware and software environments for effective malware triage and analysis.

Required Qualifications:

  • Clearance: U.S. Citizen, SCI within last 2 years.
  • Location: Full time on-site in Annapolis Junction, Maryland.
  • Experience and knowledge:
  • Four or more years of experience in a Reverse Engineering role
  • Four years of experience with program languages such as C/C++ and Python. - Four years of experience with machine architecture, operating system internals, file system and memory management, and assembly language (x64, ARM, MIPS).
  • Proficient with static and dynamic reverse engineering techniques such as disassembly/decompilation, imports, strings, process monitoring, file system monitoring, network traffic capture, debugging, sandboxing, unpacking and deobfuscation.
  • Skilled at analyzing compiled and interpreted programming languages.
  • Experience with tools like IDA Pro, Ghidra, Hopper, Binary Ninja, Frida, PE Explorer, objdump, etc.
  • Familiar with dynamic tools used for monitoring malware behavior. Experience with tools like kernel and process debuggers, process explorer, Wireshark.
  • Familiarity with automated analysis systems (e.g. Cuckoo Sandbox) and open-source intelligence resources (e.g. VirusTotal) for initial triage and quick identification of well-known malware. 
  • Ability to write detailed technical reports on analysis findings and to present reports to stakeholders. Familiarity with MITRE ATT&CK framework, TTPs, IOCs, and CVEs to provide standard nomenclature.
  • Familiarity with threat sharing platforms (MISP) and threat intelligence interchange standards (STIX, TAXII).

Preferred Qualifications:

  • Clearance: Polygraph within last 5 years
  • Education: Bachelor's degree or higher in Computer Science, Information Systems, or a related field.
  • Certification: Certified Ethical Hacker (CEH),
  • Experience and Knowledge: Six or more years of experience in a Reverse Engineering role.
  • Malware sandbox analysis and forensics
  • Ability to construct analysis sandboxes and to simulate necessary infrastructure to enable malware samples to execute (such as simulating Internet connectivity and DNS resolution).
  • Ability to perform forensic analysis of sandbox environment to detect changes made by the malware sample during dynamic analysis. This includes detecting new, deleted, or modified files, changes to system settings, configurations, or registry entries, creation of new user accounts, open network ports, etc.
  • Ability to use hex editors to modify malware samples in order to bypass anti-reversing logic. This includes logic that detects attached debuggers, virtual environments, excessive delays in process execution, etc.
  • Ability to capture network and signals transmissions and to analyze the content of those transmissions. To include wired and wireless transmissions (Ethernet, Wi-Fi, Bluetooth, NFC, RF, etc.).
  • Hardware reverse engineering.
  • Ability to identify components and pathways attached to printed circuit boards (data and power).
  • Ability to identify and map “pin-out” configurations of chips.
  • Ability to connect to and monitor signals in and out of chips and convert those into binary data, ability to dump firmware images from hardware devices.
  • Ability to identify hardware analysis requirements and tooling needs for hardware reversing.
  • Ability to identify hardware anti-tamper mechanisms to prevent bricking or destruction of the device.

Benefits 
  •         Generous cost sharing for medical insurance for the employee and dependents 
  •         100% company paid dental insurance for employees and dependents 
  •         100% company paid long-term and short-term disability insurance 
  •         100% company paid vision insurance for employees and dependents 
  •         401k plan with generous match and 100% immediate vesting 
  •         Competitive Pay 
  •         Generous paid leave and holiday package 
  •         Tuition and training reimbursement 
  •         Life and AD&D Insurance
About AnaVation 
AnaVation is the leader in solving the most complex technical challenges for collection and processing in the U.S. Federal Intelligence Community. We are a US owned company headquartered in Chantilly, Virginia. We deliver groundbreaking research with advanced software and systems engineering that provides an information advantage to contribute to the mission and operational success of our customers. We offer complex challenges, a top-notch work environment, and a world-class, collaborative team.  
 
If you want to grow your career and make a difference while doing it, AnaVation is the perfect fit for you! 
 
AnaVation is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.

Skills Required

  • U.S. citizenship
  • SCI security clearance within the last two years
  • Four or more years of reverse engineering experience
  • Four years of experience with C, C++, and Python
  • Four years of experience with machine architecture, operating system internals, file systems, memory management, and assembly language, including x64, ARM, and MIPS
  • Proficiency with static and dynamic reverse engineering techniques
  • Skill analyzing compiled and interpreted programming languages
  • Experience with malware reverse engineering tools such as IDA Pro, Ghidra, Hopper, Binary Ninja, Frida, PE Explorer, and objdump
  • Familiarity with dynamic malware monitoring tools, including kernel and process debuggers, Process Explorer, and Wireshark
  • Familiarity with Cuckoo Sandbox and VirusTotal
  • Ability to write and present detailed technical reports
  • Familiarity with MITRE ATT&CK, TTPs, IOCs, and CVEs
  • Familiarity with MISP, STIX, and TAXII
  • Polygraph within the last five years
  • Bachelor’s degree or higher in Computer Science, Information Systems, or a related field
  • Certified Ethical Hacker certification
  • Six or more years of reverse engineering experience
  • Malware sandbox analysis and forensics experience
  • Ability to construct malware analysis sandboxes and simulate network infrastructure
  • Ability to perform forensic analysis of sandbox environments
  • Ability to modify malware samples with hex editors to bypass anti-reversing logic
  • Ability to capture and analyze wired and wireless transmissions
  • Hardware reverse engineering experience
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Reston, VA
134 Employees
Year Founded: 2013

What We Do

AnaVation is a trusted partner that delivers high-value, cost-effective solutions to solve our customers’ most complex technical and analytical problems. AnaVation believes that the future of securing, collecting, processing, and analyzing cyber data will require the development of advanced ANAlytical technologies derived via the innoVATION of current and future technologies. AnaVation believes in the “Idea of the Possible” — that it is possible for our experts, partnering with our customers in the right environment, to create innovative technical solutions that expand our customers’ capabilities. We want to do two things for our customers. We want to resolve existing challenges and we want to prepare them for the future. Our technical expertise and innovative engineering culture enable us to do those things.

Similar Jobs

In-Office
Fort Meade, MD, USA
87K-198K Annually

PNC Bank Logo PNC Bank

Technology Solution Center Analyst Lead

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
41K-83K Annually

Enverus Logo Enverus

Program Director

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
3 Locations
1800 Employees
130K-150K Annually

Wells Fargo Logo Wells Fargo

Relationship Banker - Harundale

Fintech • Financial Services
Hybrid
Glen Burnie, MD, USA
205000 Employees
25K-38K Hourly

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account