Malware Analyst Tech Lead

Nozomi Networks is the leader in OT and IoT cybersecurity, keeping the world's critical infrastructure cyber resilient through real-time asset visibility, threat detection, and AI-powered analysis. We protect the toughest operational environments — from energy and healthcare to manufacturing and beyond.
Job Description
As Nozomi Networks continues to expand our product portfolio and global presence, our Security Research department is looking for a Malware Analysis Tech Lead to guide and grow the team responsible for reverse engineering malicious samples, developing high-quality detection signatures, producing actionable threat intelligence, and sharing research findings with customers, partners, and the broader cybersecurity community.
This is a hands-on leadership role for someone who combines deep technical expertise in malware analysis and detection engineering with the ability to mentor others, set technical direction, and communicate complex findings clearly. You will lead a team focused on identifying, analyzing, and tracking advanced threats, with a particular emphasis on creating reliable detections that strengthen our products and help protect critical infrastructure around the world.
You could be the next “Nozomier”! If this sounds like you, read on.
In this role, you will:
- Lead the team creating and curating various detection rules within our product, acting as a manager and as an individual contributor
- Help the support team address the customer feedback associated with these detections
- Perform threat intelligence operations to collect and maintain all the required knowledge to respond efficiently to advanced threats
- Contribute to the technical material shared with the public
- Embody the Nozomi Networks Cultural Pillars and our mission to protect what matters most with transparency and trust
To be successful in this opportunity, you should have:
- Industry experience as an IT manager
- Ability to perform reverse engineering using debuggers, understanding specifics of MZ-PE and ELF executables
- Experience in creating some of these signatures: YARA, SNORT or SURICATA, STIX, and SIGMA
- Experience speaking at cybersecurity conferences presenting findings in a clear way
- Familiarity with the MITRE ATT&CK framework and cyber kill chains
- Understanding of the OSI model and an ability to use Wireshark
- Basic experience with Python
- Attitude to operate in environments including data covered by non-disclosure agreements and a high level of confidentiality
These qualifications would be a strong plus:
- Proven experience in reverse engineering using analysis tools like IDA PRO, Ghidra, OllyDBG, x64dbg, radare2, etc
- Fundamental understanding of attributes of binary files such as executable structures and packers
- Previous professional experience as a Detection Engineer, SOC Analyst or a Threat Hunter
As Nozomi Networks continues to expand our product portfolio and global presence, our Security Research department is looking for a Malware Analysis Tech Lead to guide and grow the team responsible for reverse engineering malicious samples, developing high-quality detection signatures, producing actionable threat intelligence, and sharing research findings with customers, partners, and the broader cybersecurity community.
This is a hands-on leadership role for someone who combines deep technical expertise in malware analysis and detection engineering with the ability to mentor others, set technical direction, and communicate complex findings clearly. You will lead a team focused on identifying, analyzing, and tracking advanced threats, with a particular emphasis on creating reliable detections that strengthen our products and help protect critical infrastructure around the world.
You could be the next “Nozomier”! If this sounds like you, read on.
In this role, you will:
- Lead the team creating and curating various detection rules within our product, acting as a manager and as an individual contributor
- Help the support team address the customer feedback associated with these detections
- Perform threat intelligence operations to collect and maintain all the required knowledge to respond efficiently to advanced threats
- Contribute to the technical material shared with the public
- Embody the Nozomi Networks Cultural Pillars and our mission to protect what matters most with transparency and trust
To be successful in this opportunity, you should have:
- Industry experience as an IT manager
- Ability to perform reverse engineering using debuggers, understanding specifics of MZ-PE and ELF executables
- Experience in creating some of these signatures: YARA, SNORT or SURICATA, STIX, and SIGMA
- Experience speaking at cybersecurity conferences presenting findings in a clear way
- Familiarity with the MITRE ATT&CK framework and cyber kill chains
- Understanding of the OSI model and an ability to use Wireshark
- Basic experience with Python
- Attitude to operate in environments including data covered by non-disclosure agreements and a high level of confidentiality
These qualifications would be a strong plus:
- Proven experience in reverse engineering using analysis tools like IDA PRO, Ghidra, OllyDBG, x64dbg, radare2, etc
- Fundamental understanding of attributes of binary files such as executable structures and packers
- Previous professional experience as a Detection Engineer, SOC Analyst or a Threat Hunter