Threat Research Software Engineer (m/f/n)

Eset — Slovakia · Posted ~21 hours ago

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Description

Résumé Du Poste / Summary Support ESET Threat Research by building and maintaining internal tools, automation, and data pipelines that accelerate the delivery of actionable threat intelligence. This is a support role embedded in the research team. You will not reverse malware yourself. You will remove the friction around how researchers work: unifying scattered metadata, automating the path from analysis to customer deliverables, and giving researchers one good interface instead of ten. Description Du Poste / Job Description Meet the Team ESET Research is a team of 30+ researchers all over the world who analyze complex cyber-espionage and cybercrime operations. We work in collaboration with other internal teams to improve ESET products and create resilient malware detections. Our primary goal is to understand how threat groups operate in order to better protect our customers and disrupt malicious activities. We write private reports that are available to ESET Threat Intelligence customers. We share our knowledge publicly on ESET’s blog, https://www.welivesecurity.com/research/, and at technical conferences all around the world (Virus Bulletin, Black Hat, RSA, Botconf, etc.). About The Role Build and maintain internal tools that unify sample metadata across multiple internal and external systems (network telemetry, sandbox, malware repository, TI platform) and make threat intelligence data searchable and reusable. Develop and maintain automated pipelines that move analysis outputs into TI platforms (e.g. MISP) and generate customer-facing deliverables such as IOC tables, indicator packages, and report skeletons. Create researcher-facing web applications and workflows for sample lookup, triage status, analysis tracking, and tagging. Own the tooling backlog in partnership with researchers. Collaborate with engineering teams owning upstream systems (telemetry, sandbox, etc.). Proactively identify reliability, performance, and correctness issues services before they become incidents — improve runbooks, dashboards, alerting, and automation. Essential Requirements Experienced in Python and JavaScript, with a proven track record of designing, building and maintaining Python systems with real operational accountability, not solely scripting or automation Create and maintain APIs, databases, queues, and data integration across multiple systems, including schema design, and query optimization. Familiarity with threat intelligence workflows — enough to understand what researchers do across internal systems, without needing to be a malware reverser. Experience building web applications. Experience with container technology (e.g. Docker), CI/CD, Git, and test automation. Secure coding practices for systems that handle malicious files and sensitive data. Strong collaboration and discovery skills —turning pain points into shipped tooling. Desirable Requirements Familiarity with malware analysis workflows and common sample metadata (hashes, file type, packers, strings, imports, network indicators, sandbox behavior), including experience with sandboxes (CAPE, Cuckoo, Joe Sandbox, Any.Run, or internal equivalents) as data sources. Familiarity with MITRE ATT&CK and mapping malware behavior to techniques. Experience using AI-assisted tooling thoughtfully — both to accelerate development backed by sound planning and to power researcher-facing features (report generation, structured extraction), with strong judgment about validation, code quality and security limitations. Familiarity with building modern CLI/TUI/WebUI tooling. Prior work delivering tooling to threat intelligence or security research teams. Participation to CTFs Ready to Make an Impact? If you’re excited about this opportunity and feel it aligns with your journey, don’t hesitate—apply and show us what drives you Basic wage component for Bratislava location (brutto): from 2700 EUR * The final basic wage component can be increased accordingly to individual skills and experience of the selected candidate. * Performance bonus 2 times per year up to 10% of the basic salary paid for the evaluation period(usually 6 months). Avantages du poste / At ESET, diversity, equity, and inclusion (DEI) are integral to our corporate culture. We believe in creating a respectful environment, where everyone feels valued and respected, welcoming applications from individuals of all backgrounds, including race, gender, age, religion, disability, and sexual orientation.