AI Hacking - How Hackers Use Artifical Intelligence in Cyberattacks

Read Now
We utilize artificial intelligence for site translations, and while we strive for accuracy, they may not always be 100% precise. Your understanding is appreciated.

Threat Detection Analyst

Spain
Product Engineering
OPSWAT

Protecting the World’s Critical Infrastructure

OPSWAT, a global leader in IT, OT, and ICS critical infrastructure cybersecurity, delivers an end-to-end platform that gives public and private sector organizations and enterprises the critical advantage needed to protect their complex networks, secure their devices, and ensure compliance. Over the last 20 years our commitment to innovative technology has earned the trust of more than 1,700 organizations, governments, and institutions globally, solidifying our role in protecting the world’s critical infrastructure and securing our way of life.

The Position

The Threat Detection Analyst supports OPSWAT’s threat analysis and detection engineering efforts, leveraging our sandbox product as the primary detection engine to identify and mitigate cyber threats. You will be part of the Malware Lab, the intelligence hub behind the sandbox—researching emerging threats, enhancing detection capabilities, and ensuring high confidence in analysis results.

By combining malware analysis and signature development, you will help continuously evolve the sandbox to stay ahead of modern threats.

What You Will Be Doing

Malware Analysis & Reverse Engineering – the foundation of everything we do.

Sandbox Capability Development – implement new extraction features (filetype-specific parsers, config extractors, etc.) to enrich behavioral detection artifacts.

Threat Indicator Development – identify and flag structural and behavioral patterns of interest.

YARA Rule Vetting & Development – validate community rules and create tailored detection signatures.

Detection Accuracy – hunt for misleading sandbox reports and ensure proper sample classification.

Threat Detection Service – review, triage, and resolve detection inaccuracies reported by customers.

Technical Initiatives – drive innovation to advance OPSWAT’s threat detection capabilities and maximize sandbox effectiveness.

Knowledge Sharing – promote collaboration within the team and across OPSWAT.

Automation – develop scripts and tools to streamline analysis workflows.

Research – stay on top of evolving malware trends, TTPs, and sandbox detection techniques.

What We Need From You

Education

Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent work experience.

Advanced certifications (e.g., GREM, CEH, OSCP, or equivalent) are highly preferred.

Experience

2+ years in malware analysis, reverse engineering, or threat detection engineering.

Proven expertise in developing and tuning detection rules (YARA, SIGMA, IDS).

Skills & Competencies

Strong grasp of reverse engineering fundamentals.

Solid understanding of the cyber threat landscape and adversary techniques.

Experience with scripting for automation (Python strongly preferred).

Knowledge of malware techniques: packing, anti-analysis, injection, etc.

Familiarity with the MITRE ATT&CK framework for mapping TTPs.

Analytical mindset with a focus on actionable detection outcomes.

Clear and effective communication skills, able to present findings to both technical and non-technical stakeholders.

It Would Be Nice If You Had

Hands-on background in sandbox-based malware analysis.

Participation in reverse engineering challenges (e.g., FLARE, HackTheBox).

Contributions to open-source or security research communities.****

OPSWAT is an equal opportunity employer. We celebrate diversity and are committed to providing an environment where equal employment opportunities are extended to all employees and applicants, free of discrimination and harassment of any type. All employment decisions are based on individual qualifications, job requirements, and business needs without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other category protected by federal, state, or local laws.

Recruiting Agencies: we do not accept unsolicited resumes from third party agencies for any of our open positions. To submit resumes for our jobs, there must be a recruiting contract approved by our legal team and endorsed by both parties. We are currently not accepting additional 3rd party agencies at this time.