MacPaw

Malware Research Engineer

MacPaw

Kyiv, Ukraine (Remote)Remotefulltime_permanentPosted Jun 23, 2026

Job description

Jira ticket We are looking for a Junior Malware Research Engineer to join Moonlock — someone with a strong research mindset, curious, and attentive to detail. This role is a good fit for an ambitious person who enjoys threat analysis, values accuracy, and likes connecting the dots to understand emerging global attack trends.

You will be part of a highly collaborative malware research team, working closely with teammates to gather threat intelligence, build threat collections, share findings, and continuously improve our detection pipeline in a fast-evolving threat landscape. In this role, you will: Analyze malware samples and suspicious files under the guidance of senior engineers.

Collect, organize, and validate indicators of compromise (Io. Cs) and threat intelligence data from public, internal, and open-source intelligence (OSINT) to help maintain malware knowledge bases. Assist in creating and improving malware detection rules, such as YARA. Investigate user-reported security incidents, support Customer Support with technical investigations of typical security-related cases, and help classify threats.

Research emerging malware trends, attack techniques, and security technologies to identify broader threat trends and build collections based on similarity. Prepare research summaries and technical documentation, and assist in preparing articles or posts on the team's threat findings. Skills you’ll need to bring: 1+ year of experience in a Cybersecurity-related field (SOC, Incident Response, or Threat Intelligence) with a basic understanding of threat triage and incident handling workflows.

Basic understanding of malware concepts and analysis methodologies (specifically static and dynamic analysis concepts), along with common attack techniques (like phishing) and general cybersecurity principles. Basic knowledge of operating system fundamentals, including processes, memory management, filesystems, and permissions.

Familiarity with macOS, Linux, or UNIX-like environments. Familiarity with YARA or willingness to learn detection rule development. Strong research and analytical skills, with great attention to detail and a careful approach to work. Experience or comfort using AI tools to assist in data processing and automation. At least an Upper-Intermediate level of English and fluent Ukrainian.

As a plus: Experience with scripting or automation using Python, Bash, or a similar language. Familiarity with Threat Intelligence reports and general awareness of the latest cybersecurity threats and incidents. Understanding of Indicators of Compromise (Io. Cs), threat intelligence concepts, and the MITRE ATT&CK framework.