
Principal Software Engineer I
Quick Heal Technologies Ltd1 day ago
Chennai, IndiaStaff+
Responsibilities
- Perform static, dynamic, behavioral, and runtime analysis of malware, scripts, droppers, loaders, LOLBins, ransomware, and fileless threats.
- Reverse engineer binaries and scripts to identify execution flows, persistence mechanisms, evasion techniques, and multi-stage attack chains.
- Develop behavioral, string-based, telemetry-driven, and YARA detections for PE and non-PE threats, malicious scripts, and suspicious runtime activity.
- Research Windows internals, malware families, attacker tradecraft, and emerging endpoint threat techniques.
- Map detections to MITRE ATT&CK, perform threat hunting, extract IOCs, and convert threat intelligence into product detections.
- Validate detection coverage, tune behavioral policies, investigate false positives and false negatives, and improve detection efficacy.
- Perform root cause analysis for customer-reported security incidents and document attack chains, affected systems, and attack vectors.
- Collaborate with threat research and endpoint protection teams and engineering teams implementing detection logic.
- Prepare technical analysis reports, documentation, playbooks, knowledge base articles, detection documentation, blogs, white papers, and quarterly threat reports.
- Present research findings and project updates, mentor junior researchers, review detection content, and deliver technical product demonstrations.
- Use AI-assisted workflows to accelerate malware triage, detection generation, research, and validation.
- Consolidate team deliverables and prepare progress reports, metrics, and management updates.
Requirements
- 8+ years of experience in malware analysis, security research, reverse engineering, behavioral detection, and detection engineering.
- Expertise in static and dynamic malware analysis, signature writing, behavioral detection engineering, YARA rule development, non-PE threat analysis, PowerShell and script analysis, and LOLBins detection.
- Experience investigating fileless threats, memory, Windows internals, process injection, persistence, root cause analysis, threat hunting, and threat intelligence.
- Experience with MITRE ATT&CK mapping, IOC extraction, detection validation, false-positive reduction, threat pattern correlation, and EDR/XDR detection content development.
- Hands-on experience with IDA Pro, Ghidra, x64dbg, Process Monitor, Process Explorer, Wireshark, sandbox environments, and Windows internals debugging tools.
- Ability to analyze obfuscated PowerShell, encoded payloads, process, memory, registry, and network activity, including WMI, scheduled tasks, services, drivers, COM, and token manipulation.
- Strong technical documentation, threat reporting, presentation, stakeholder communication, mentoring, and customer-facing demonstration skills.
- Experience with EDR/XDR policy writing, simulations, playbooks, automation, and AI-assisted malware research is required or advantageous.
Tech Stack
PowerShellWindows