Threat Research Software Engineer (m/f/n)

ESETMontreal, QC
€32,400Hybrid

About The Position

Support ESET Threat Research by building and maintaining internal tools, automation, and data pipelines that accelerate the delivery of actionable threat intelligence. This is a support role embedded in the research team. You will not reverse malware yourself. You will remove the friction around how researchers work: unifying scattered metadata, automating the path from analysis to customer deliverables, and giving researchers one good interface instead of ten. ESET Research is a team of 30+ researchers all over the world who analyze complex cyber-espionage and cybercrime operations. We work in collaboration with other internal teams to improve ESET products and create resilient malware detections. Our primary goal is to understand how threat groups operate in order to better protect our customers and disrupt malicious activities. We write private reports that are available to ESET Threat Intelligence customers. We share our knowledge publicly on ESET’s blog, https://www.welivesecurity.com/research/, and at technical conferences all around the world (Virus Bulletin, Black Hat, RSA, Botconf, etc.).

Requirements

  • Experienced in Python and JavaScript, with a proven track record of designing, building and maintaining Python systems with real operational accountability, not solely scripting or automation
  • Create and maintain APIs, databases, queues, and data integration across multiple systems, including schema design, and query optimization.
  • Familiarity with threat intelligence workflows — enough to understand what researchers do across internal systems, without needing to be a malware reverser.
  • Experience building web applications.
  • Experience with container technology (e.g. Docker), CI/CD, Git, and test automation.
  • Secure coding practices for systems that handle malicious files and sensitive data.
  • Strong collaboration and discovery skills — turning pain points into shipped tooling.

Nice To Haves

  • Familiarity with malware analysis workflows and common sample metadata (hashes, file type, packers, strings, imports, network indicators, sandbox behavior), including experience with sandboxes (CAPE, Cuckoo, Joe Sandbox, Any.Run, or internal equivalents) as data sources.
  • Familiarity with MITRE ATT&CK and mapping malware behavior to techniques.
  • Experience using AI-assisted tooling thoughtfully — both to accelerate development backed by sound planning and to power researcher-facing features (report generation, structured extraction), with strong judgment about validation, code quality and security limitations.
  • Familiarity with building modern CLI/TUI/WebUI tooling.
  • Prior work delivering tooling to threat intelligence or security research teams.
  • Participation to CTFs

Responsibilities

  • Build and maintain internal tools that unify sample metadata across multiple internal and external systems (network telemetry, sandbox, malware repository, TI platform) and make threat intelligence data searchable and reusable.
  • Develop and maintain automated pipelines that move analysis outputs into TI platforms (e.g. MISP) and generate customer-facing deliverables such as IOC tables, indicator packages, and report skeletons.
  • Create researcher-facing web applications and workflows for sample lookup, triage status, analysis tracking, and tagging.
  • Own the tooling backlog in partnership with researchers.
  • Collaborate with engineering teams owning upstream systems (telemetry, sandbox, etc.).
  • Proactively identify reliability, performance, and correctness issues services before they become incidents — improve runbooks, dashboards, alerting, and automation.

Benefits

  • Group private insurance plan
  • Group retirement savings plan
  • Physical activity program
  • Interior bike racks and bike sharing program
  • Home office
  • Extra days off
  • Flexible work hours
  • Refreshments in office (fruit, snacks, drinks & coffee)
  • Breakfast
  • 5 à 7 / Afterwork get togethers
  • Teambuilding activities
  • Common lounge ("Living room") with PlayStation, ping-pong and foosball tables
  • Christmas activities
  • LinkedIn Learning/ Udemi
  • Loyalty program (extra vacation days, financial bonus, cake/cupcakes)
  • Friend referral
  • Christmas gifts
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service