368,910open jobs
9,449companies
47,822added this week
Browse all
Salary
$182k per year
Location
Remote (United States)
Seniority
Principal · 5+ years exp
Overview
Company
Impact
Profile match
Secure your critical infrastructure with Dragos, our industrial cybersecurity solutions provide unmatched visibility and threat detection for OT environments.

At Dragos, the mission is personal. The systems we protect deliver the water you drink, power your home, and keep the hospitals your community depends on running. Those critical infrastructure systems that power our civilization around the world are under attack every day by adversaries. When those systems fail, people are immediately at risk. We are the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The people here chose this work because they understand what is at stake. Here, you will find a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust. If safeguarding the systems that protect your family, friends, and community is the kind of work that matters to you, you are in the right place. 

About the Role

The Dragos Malware Analysis team provides critical defense against the most sophisticated threats targeting critical infrastructure by analyzing adversary tools, building detections, and delivering intelligence that shapes how the industry understands ICS security. As an Associate Principal Malware Analyst, you'll lead deep-dive analysis of ICS-related malware and firmware, develop novel detection methods, and produce Yara signatures and technical reports that translate findings into action. You'll partner closely with detection engineers, hunters, and intelligence analysts to turn your research into deployable defenses while helping refine the malware analysis pipeline itself. This is a role where your expertise directly impacts how Dragos and the wider industry detect and defend against the most consequential threats in the space.

Responsibilities

  • Identify and assess highly sophisticated threats targeting ICS and critical infrastructure, evaluating their operational impact and severity.
  • Develop innovative analysis methods and conduct advanced reverse engineering and deobfuscation of ICS-specific malware, software, and firmware.
  • Create Yara signatures and partner closely with detection engineers to develop novel, ICS-specific threat detections informed by deep malware analysis findings.
  • Write persuasive customer-facing technical reports and internal documentation that translates complex malware findings into clear operational impact for diverse audiences.
  • Refine and evolve the malware analysis pipeline with new methods and procedures to address emerging techniques and tooling as they surface in the threat landscape.
  • Collaborate across teams-with hunters, intelligence analysts, and detection engineers-to drive malware-related threat research and solve complex technical problems.
  • Exercise independent judgment in selecting analytical methods and serve as a trusted technical advisor on complex malware analysis and detection questions across the organization.

Qualifications

  • 5-8 years of experience in malware analysis, reverse engineering, or a related ICS/OT cybersecurity discipline.
  • Advanced proficiency in static and dynamic malware reverse engineering using tools such as disassemblers, debuggers, and decompilers (e.g., IDA Pro, Ghidra, x64dbg).
  • Demonstrated experience analyzing ICS-specific software, firmware, and embedded systems.
  • Strong Yara signature development skills, with experience building detection analytics for novel malware and attack techniques.
  • Proven ability to write clear, persuasive, customer-facing technical reports on complex malware findings.
  • Experience contributing to or improving a malware analysis pipeline, tooling, or workflow.
  • Comfortable collaborating with detection engineers, hunters, and intelligence analysts on cross-team technical problems.
  • Familiarity with ICS/OT protocols, threat groups, and the broader critical infrastructure threat landscape is a major plus. 

Compensation

  • Salary: $182,000  
  • Competitive Equity Package  
  • Comprehensive Benefits Plan 

#LI-JF1 #LI-REMOTE  

Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,910 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$67k – $171k per year (Estimated) • In office • Bachelor's Degree • Singapore
JavaScript
Python
SQL
YARA
DevOps
AWS
AWS Lambda
Azure
VMWare
Cybersecurity
Ghidra
IDA Pro
Wireshark
YARA
Apply
In office • Full-Time • Bucharest
Assembly
DevOps
Akamai
Incident Management
Cybersecurity
ISO 27001
Wireshark
Management
ServiceNow
Apply
$176k – $203k per year • Remote • Full-Time • 5+ years exp
Assembly
Python
SQL
Apply
$150k – $200k per year • Remote • Full-Time • 11+ years exp
YARA
Databases
Apache Kafka
ElasticSearch
OpenSearch
AI/ML
AI Agents
Embeddings
RAG
Semantic Search
GraphRAG
Knowledge Graph
Semantic Search
DevOps
Kubernetes
Vector
Cybersecurity
MITRE ATT&CK
STIX
TAXII
YARA
Apply
$176k – $203k per year • Remote • Internship • 5+ years exp
Assembly
Python
SQL
Cybersecurity
Censys
Apply
$165k per year • Equity • Remote/Hybrid • 5+ years exp • Norfolk
Cybersecurity
Threat Modeling
Apply
$165k per year • Equity • Remote • 5+ years exp
Python
Rust
DevOps
Ansible
AWS
Azure
CI/CD
Docker
GCP
GitHub Actions
GitLab CI
Grafana
Jenkins
Kubernetes
Prometheus
Terraform
GitHub
GitLab
Apply
$166k per year • Equity • Remote • 5+ years exp
Apply
$166k per year • Equity • Remote • 5+ years exp
Apply
$166k per year • Equity • Remote • 5+ years exp
DevOps
AWS
Azure
GCP
Apply
See all jobs
This is one of many
368,910 more open roles from verified company boards, updated every day.