Job Description
WHAT MAKES THE ROLE SPECIAL?
Group-IB is a partner of INTERPOL, Europol, and a cybersecurity solutions provider, recommended by SWIFT and OSCE. Such partnerships give us advantages in our everyday duties.
We make deep research of malware and public presentation of complex research. We participate in IR and perform as experts at conferences and in mass media.
Our reports are used by thousands of people all over the world.
TASKS TO SOLVE
- Research malicious files, conduct reverse engineering, and develop methods and approaches for detecting malicious files based on their behaviorEmulate attacker actions in a virtual environment to test and improve detection capabilities.
- Implement detection logic within an existing framework (using Python, Rust, Yara, Sigma, Suricata).
- Independently identify problematic cases, evasion techniques for dynamic analysis systems, and solutions to these issues.
- Analyze detection logic for false positives and minimize such occurrences.
- Conduct analysis of similar solutions to compare system behavior in different scenarios.
- Test detection logic rules for functionality and performance.
THIS ROLE IS PERFECT FOR YOU IF YOU HAVE:
- Experience with IDA Pro, ring-3 debuggers, sandboxes, and other static and dynamic analysis tools.
- You have x86 and x64 assembly knowledgeYou understand Windows architecture, WinAPI, and the PE file format.
- You have good understanding of PDF and MS-CFB formats.
- You can analyze obfuscated code written in scripting languages.
- You know how to set up a virtual machine for malware analysis.
- You have experience in Python.
- You have a keen interest in diverse tasks and the ability to quickly learn new things.
- You possess persistence and the ability to see complex tasks through to completion.
WHAT ELSE WE APPRECIATE IN OUR TEAM
- Experience in exploit analysis (Flash, PDF, DOCX, etc.).
- Experience in network traffic analysis.
- Penetration testing experience.
- Knowledge of Rust.
WHY CHOOSE GROUP-IB
- Your happiness is important to us: We want every single team member to be happy.
- Continuing professional development: At Group-IB, you can choose from various paths to growth: progress as an expert, advance to a management position, try your hand in another department, relocate abroad, or launch a new business area at Group-IB.
- A team with extensive international expertise: Do you have experience but are looking for exciting challenges? By choosing us, you will be choosing complex tasks and continuously improving your skills in a fast-growing international company.
- Globally recognized technologies: Group-IB’s members are located in 25 countries and our products and services are sold in 60 countries. What’s more, Gartner, IDC, and Forrester have ranked our technologies among the best in their class. We work with over 450 international partners and about 500 clients.
- A culture created by each of us: Group-IB’s employees speak many different languages and understand one another. We respect each other’s beliefs, share common values, and strive toward the happiness of every employee.
- Economic stability: Group-IB’s sustainable growth helps rapidly develop careers that would take years to progress as far as most other companies.
WHAT ELSE YOU SHOULD KNOW
- Flexible schedule: Group-IB does not have fixed working hours. You choose your own schedule. We adhere to the principle advocated by Steve Jobs: “We have to work not 12 hours, and head.”
- Health: If anything goes wrong, don’t worry — we offer health insurance.
- Challenges: A wide selection of GIB programmes helps you improve soft skills, gain new competencies, and receive monetary rewards.
- The initiative is rewarded: At Group-IB, you can bring your most daring ideas to life. The company encourages technical blogging, writing articles, building sports teams, and other creative activities.