Vulnerability/Malware Researcher (Reverse Engineer)

Posted 2 Hours Ago
Be an Early Applicant
Arlington, VA, USA
In-Office
160K-180K Annually
Senior level
Artificial Intelligence • Cloud • Information Technology • Security • Software
The Role
Conduct malware analysis, reverse engineering, vulnerability research, exploit analysis, and adversary TTP investigations. Develop detection content such as IOCs, YARA and Sigma rules, MITRE ATT&CK mappings, and SOC analytics. Build research automation tools, maintain secure analysis environments, collaborate with incident response and security teams, and produce technical reports. The role requires strong operating system internals, assembly, programming, exploitation, and reverse engineering expertise.
Summary Generated by Built In
Job Summary & Responsibilities

Everforth ECS is seeking a Vulnerability/Malware Researcher (Reverse Engineer) to join our team in Arlington, VA (Hybrid).  This position is contingent upon award.


We are seeking a highly skilled Vulnerability/Malware Researcher (Reverse Engineer) to identify, analyze, and understand complex software vulnerabilities and malicious code that may impact organizational systems, products, and infrastructure. This role will conduct in-depth malware analysis, reverse engineer software and firmware, perform exploitation and tactics, techniques, and procedures (TTPs) analysis to uncover exploitable weaknesses, and provide actionable intelligence to support detection, response, and remediation efforts.

The ideal candidate possesses strong low-level programming knowledge, reverse engineering expertise, and experience analyzing sophisticated malware, exploit techniques, and advanced adversary tradecraft.

Key Responsibilities

Malware Analysis & Reverse Engineering

  • Perform static and dynamic analysis of malicious software, including ransomware, trojans, rootkits, spyware, and advanced persistent threat (APT) malware.
  • Reverse engineer malware samples to identify functionality, persistence mechanisms, command-and-control (C2) communications, and attacker objectives.
  • Develop detailed malware analysis reports and technical documentation.
  • Research evolving malware techniques and adversary capabilities.

Vulnerability Research

  • Identify and analyze software, operating system, firmware, and application vulnerabilities.
  • Perform code analysis to discover security weaknesses and exploit paths.
  • Research emerging vulnerabilities and assess organizational exposure.
  • Validate security findings through proof-of-concept testing and exploit analysis.
  • Collaborate with remediation teams to prioritize and mitigate identified risks.

Security Research & Threat Analysis

  • Investigate adversary tactics, techniques, and procedures (TTPs) on device/service targeting procedures.
  • Analyze exploit kits, attack frameworks, and intrusion methods used by threat actors.
  • Support intelligence-driven security initiatives through technical research and threat assessments.
  • Correlate research findings with threat intelligence and incident response investigations.

Detection Development

  • Create and maintain Indicators of Compromise (IOCs), YARA rules, Sigma rules, and detection signatures.
  • Develop behavioral detections and analytic content for Security Operations Center (SOC) use.
  • Assist threat hunting teams by providing technical indicators and adversary insights.
  • Support development of MITRE ATT&CK procedure-level mapping artifacts.
  • Enhance detection coverage based on research findings and threat trends.

Research Tool Development

  • Develop custom scripts, automation tools, and utilities to support malware analysis and vulnerability research.
  • Improve reverse engineering workflows through automation and tooling enhancements.
  • Maintain secure malware analysis laboratories and research environments.
  • Evaluate emerging security research technologies and platforms.

Collaboration & Reporting

  • Partner with Incident Response, Threat Intelligence, SOC, Product Security, and Engineering teams.
  • Present technical findings to security leadership and engineering stakeholders.
  • Produce technical reports, white papers, and research briefings.
  • Contribute to internal knowledge bases and security best practices.

Salary Range: $160,000 - $180,000

General Description of Benefits 


Preferred Qualifications
  • Top Secret Clearance
  • Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical field, or equivalent experience.
  • 7+ years of experience in malware analysis, reverse engineering, vulnerability research, or offensive security.
  • Strong understanding of operating system internals, including Windows and Linux.
  • Understanding and familiarity with MITRE ATT&CK framework.
  • Experience reverse engineering compiled software using industry-standard tools.
  • Knowledge of assembly language (x86, x64, ARM) and executable file formats.
  • Proficiency in at least one programming language such as Python, C, C++, Rust, or Go.
  • Experience analyzing malware behavior through static and dynamic analysis techniques.
  • Understanding of software exploitation concepts, memory corruption vulnerabilities, and attack methodologies.
  • Strong analytical, problem-solving, and investigative skills.

Skills Required

  • Top Secret clearance
  • Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical field, or equivalent experience
  • 7+ years of experience in malware analysis, reverse engineering, vulnerability research, or offensive security
  • Strong understanding of Windows and Linux operating system internals
  • Familiarity with the MITRE ATT&CK framework
  • Experience reverse engineering compiled software using industry-standard tools
  • Knowledge of x86, x64, and ARM assembly language and executable file formats
  • Proficiency in at least one of Python, C, C++, Rust, or Go
  • Experience analyzing malware using static and dynamic analysis techniques
  • Understanding of software exploitation concepts, memory corruption vulnerabilities, and attack methodologies
  • Strong analytical, problem-solving, and investigative skills

ECS Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about ECS and has not been reviewed or approved by ECS.

  • Healthcare Strength ECS advertises multiple national-network medical plan options with HSA eligibility alongside dental and vision coverage. Coverage generally begins quickly and is paired with company-paid short- and long-term disability, adding stability to the health package.
  • Retirement Support A 401(k) with Safe Harbor and immediate vesting on employer contributions is emphasized, with an employer match available. Access to an employee stock purchase plan via the parent company provides an additional savings avenue.
  • Parental & Family Support Paid parental leave up to 30 days, adoption assistance, and other family-oriented leaves are highlighted. Feedback suggests these offerings add meaningful value beyond base pay for many roles.

ECS Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Elkhorn, NE
2,129 Employees
Year Founded: 1993

What We Do

ECS, a segment of ASGN (NYSE: ASGN), delivers advanced solutions and services in cloud, cybersecurity, artificial intelligence (AI), machine learning (ML), application and IT modernization, and science and engineering. The company solves critical, complex challenges for customers across the U.S. public sector, defense, intelligence and commercial industries. ECS maintains partnerships with leading cloud, cybersecurity, and AI/ML providers and holds specialized certifications in their technologies. Headquartered in Fairfax, Virginia, ECS has more than 3,400 employees throughout the U.S. and has been recognized as a Top Workplace by The Washington Post for the last five years.

Similar Jobs

BAE Systems, Inc. Logo BAE Systems, Inc.

Business Operations Manager

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Sterling, VA, USA
40000 Employees
118K-201K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Cloud Pipeline Deployment Engineer (Expert)

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Herndon, VA, USA
40000 Employees
150K-254K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Cloud Identity Engineer (Expert)

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Herndon, VA, USA
40000 Employees
150K-254K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Software Engineer

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Herndon, VA, USA
40000 Employees
150K-254K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account