Research Systems Analyst
Build and operate scalable malware-analysis, threat-enrichment, and graph-intelligence systems that power security research and detection. The role requires 6+ years of security pipeline or threat-intelligence experience, strong Python or Go skills, and expertise in cloud and distributed systems.
About the job
Responsibilities
- Design, build, and maintain static and dynamic file analysis pipelines for processing artifacts at scale.
- Maintain and optimize YARA rule sets and tooling for rule testing, performance, and false-positive management.
- Operate and extend threat-indicator enrichment systems for real-time file metadata extraction, scanning, and enrichment.
- Build and expand threat-graph intelligence systems modeling relationships among indicators, malware, infrastructure, and actors.
- Design and maintain dynamic analysis, sandboxing, and detonation capabilities, including behavioral telemetry collection and safe execution environments.
- Build ingestion and normalization pipelines connecting internal scan data with external threat-intelligence feeds.
- Instrument pipelines for reliability and observability through logging, monitoring, alerting, and SLAs.
- Partner with threat research and detection-engineering teams to translate analytical needs into scalable systems.
- Maintain secure handling and isolation practices for malicious samples and analysis environments.
- Document architecture, runbooks, and operational procedures.
Requirements
- Bachelor's degree in Computer Science, Engineering, or equivalent practical experience.
- 6+ years of experience building security data pipelines, detection-engineering systems, or threat-intelligence platforms.
- Experience with Synapse or other graph-based threat-intelligence platforms, including graph data modeling.
- Strong programming skills in Python and/or Go.
- Working knowledge of static and dynamic malware-analysis tooling and pipelines, including disassemblers, sandboxes, and debuggers.
- Experience with distributed data pipelines, message queues, and data stores.
- Familiarity with Docker and Kubernetes for isolated execution environments.
- Experience designing and operating highly available, production-grade cloud infrastructure on AWS, Google Cloud, or Azure.
- Experience using LLM-based coding harnesses and agent-based development workflows.
Nice-to-Haves
- Experience with Synapse, MISP, OpenCTI, or other threat-intelligence platforms.
- Familiarity with STIX/TAXII.
- Experience working with internet-wide scan data.
- Open-source contributions to security tooling, YARA rules, Strelka scanners, or Synapse modules.
- CI/CD experience applied to detection content.
- Familiarity with SOC 2, ISO 27001, or similar security and compliance frameworks for sensitive data.
- Hands-on experience authoring and managing YARA rules at scale.
- Experience with Strelka or comparable file-scanning frameworks such as Assemblyline or FAME.
Compensation
- US high-cost-of-living locations: $190,000–$240,000 USD, plus bonus eligibility and equity.
- Other US locations: $170,000–$220,000 USD, plus bonus eligibility and equity.
- Compensation outside the US is based on location-specific market data.
Skills
Python, Go, Yara, Malware Analysis, Cuckoo, Cape, Kafka, RabbitMQ, Elasticsearch, Amazon S3, Docker, Kubernetes, AWS, GCP, Synapse
Similar jobs
Security Engineering jobsBuild and lead product and infrastructure security for systems that move money, creating secure defaults, automation, access controls, and vulnerability management processes. The role requires strong software engineering, cloud infrastructure expertise, risk-based judgment, and the ability to operate independently as the senior security engineer.
Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.
Leads application security initiatives across products, APIs, distributed systems, and AI-enabled applications. The role requires at least five years of security or software engineering experience, strong threat-modeling and architecture skills, and the ability to build security automation and drive remediation.
Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.
The Senior Security Engineer will secure Jasper’s AI systems, cloud infrastructure, software supply chain, and compliance workflows while building automation and security standards for a growing program. The role requires 8+ years of security engineering experience and hands-on expertise across AI, cloud, or GRC security.