Lead Engineer - Malware Reverse Engineering (CTI team)

TargetBrooklyn Park, MN
$132,000 - $238,000Hybrid

About The Position

This role is within the Cyber Fusion Center (CFC) and focuses on investigating, researching, and implementing AI-assisted tooling for malware analysis. The goal is to triage samples, validate machine-generated analysis, and investigate complex or evasive malware where automation falls short. The position involves developing a strong foundation in reverse engineering, analyzing attacker tradecraft, thinking adversarially about malware and analysis systems, and translating reverse engineering insights into durable detections across the CFC. Job duties may change at any time due to business needs.

Requirements

  • 4 year degree or equivalent experience
  • 7+ years of software or security engineering experience preferably in malware labs, CTFs or with personal research projects
  • Demonstrated understanding of reverse engineering concepts (x86/x64, assembly, calling conventions)
  • Familiarity with common malware techniques (packing, persistence, process injection)
  • Demonstrated programming knowledge in C/C++ and Python
  • Familiarity with YARA or other detection frameworks
  • Experience with tools like Ghidra, IDA Pro, Binary Ninja or similar
  • Exposure to dynamic analysis (debugging, sandboxing, instrumentation)
  • Understanding of OS internals (Windows or Linux), including processes, memory, and system calls
  • Basic networking knowledge (protocols, common attack surfaces)
  • Ability to reason about unfamiliar code and derive behavior from partial information
  • Basic knowledge of exploitation concepts (i.e. buffer overflows, ROP)
  • Curiosity when things don’t match expectations—willingness to dig deeper and analyze
  • Comfort working with incomplete or noisy data at scale
  • Willingness to rely on automation without blindly trusting it
  • Ability to critically evaluate machine-generated analysis
  • Interest in how adversaries may evade or manipulate automated systems
  • Maintains technical knowledge within areas of expertise
  • Stays current with new and evolving technologies via formal training and self-directed education

Responsibilities

  • Review and validate AI-generated static and dynamic analysis results.
  • Identify inaccuracies, gaps or adversarial manipulation in automated outputs.
  • Refine analysis by guiding tools toward deeper behavioral understanding.
  • Analyze large sample sets and cluster malware into families and campaigns.
  • Distinguish commodity noise from high-impact or novel threats.
  • Escalate edge cases requiring deeper manual investigation.
  • Perform focused reversing on critical code paths (i.e. loaders, unpacking routines, injection logic).
  • Analyze obfuscation, packing and anti-analysis techniques.
  • Investigate unusual or non-standard execution environments (custom VMs, staged payloads).
  • Recognize common exploitation patterns (memory corruption, logic flaws, sandbox escapes).
  • Assist in reconstructing exploit chains and post-exploitation behavior.
  • Support root-cause understanding for vulnerabilities observed in the wild.
  • Contribute to high-quality detection logic (YARA, behavioral rules, heuristics).
  • Extract stable, meaningful indicators from reversed samples.
  • Collaborate with detection engineers to ensure resilience against evasion.
  • Work with automated analysis pipelines (static, dynamic, emulation).
  • Assist in improving analysis workflows and signal quality.
  • Leverage Python scripting to extend or customize tooling.

Benefits

  • Comprehensive health benefits and programs
  • Medical insurance
  • Vision insurance
  • Dental insurance
  • Life insurance
  • 401(k)
  • Employee discount
  • Short term disability
  • Long term disability
  • Paid sick leave
  • Paid national holidays
  • Paid vacation
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service