Principal Researcher

Post Date

Jul 23, 2026

Location

San Jose,
California

ZIP/Postal Code

95131
US
Oct 09, 2026 Insight Global

Job Type

Perm

Category

Network Engineer

Req #

DGW-ad41e6c7-20ee-4678-8dd1-aa044b4c3099

Pay Rate

$200k - $215k (estimate)

Job Description

Job Overview
We are seeking a Malware Reverse Engineering Researcher focused on analyzing IoT botnets and large-scale DDoS threats. This role combines malware analysis, network security research, and detection engineering to improve defensive capabilities against modern botnet-driven attacks. The researcher will investigate malware behavior, identify attack patterns, develop detection methodologies, and collaborate with engineering teams to operationalize findings into security products and services.

Key Responsibilities

Reverse engineer IoT botnet malware, including Mirai variants, Go-based malware, and multi-architecture binaries, to understand attack behavior, command structures, obfuscation techniques, and network-level activity.
Perform static and dynamic malware analysis in sandboxed and isolated lab environments to validate behavior and identify attack mechanisms.
Analyze malware-generated network traffic and develop packet-level detection signatures and mitigation strategies.
Research and contribute to new detection and defense techniques based on malware behavior, network telemetry, and threat intelligence.
Collaborate with engineering teams to translate research findings into production-ready detection and mitigation capabilities.
Partner with AI/ML teams to enhance malware analysis workflows through automation and machine learning-assisted research.
Produce technical research content, including threat reports, blog posts, and conference presentations.
Support customer engagements by providing post-incident analysis, threat briefings, and technical guidance related to DDoS activity and botnet threats.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Required Skills & Experience

Strong experience with binary reverse engineering using tools such as Ghidra or IDA Pro.
Ability to perform static analysis across multiple CPU architectures and work with stripped binaries, compiler-generated code, assembly language, and control flow reconstruction.
Hands-on experience conducting dynamic malware analysis in sandbox or isolated laboratory environments.
Proficiency in Python and Go.
Strong understanding of network protocol implementation and behavior.
Ability to analyze PCAPs, reconstruct network activity, and interpret protocol interactions.
Experience analyzing DDoS botnets, including Mirai-family malware or similar botnet architectures.
Experience investigating malware binaries directly rather than relying solely on threat reports or third-party research.

Nice to Have Skills & Experience

Experience with high-performance packet processing, traffic inspection, or DDoS mitigation systems.
Deep familiarity with reverse engineering and analyzing Go binaries.
Experience working with malware source code.
Experience tracking malware family evolution, variant analysis, and lineage attribution.
Experience applying machine learning or AI-assisted techniques to malware classification, clustering, behavioral analysis, or threat attribution.
Background in network security, large-scale DDoS defense, or threat research environments.

Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.