Security Researcher

Xcede
San Jose, CA

Principal Security Researcher - IoT Botnet


A Leading Provider of Secure Application Delivery and Cloud Networking Solutions are looking for a Pr. Security Researcher to sit at the intersection of deep binary research and real-world defensive impact. You will reverse engineer live IoT botnet malware, translate findings into detection primitives and wire-accurate attack traffic, and work across the organization to ensure that research reaches the product, the customer.


Overview:

  • Reverse engineer real-world botnet malware
  • Analyze IoT malware (Mirai variants, Go-based L7 flooders, multi-architecture binaries) to understand attack behavior at the wire level.
  • Translate research into real defenses
  • Develop detection techniques and mitigation strategies that directly power production systems.
  • Perform deep static and dynamic analysis
  • Use tools like Ghidra, IDA, and sandbox environments to validate and expand findings.
  • Collaborate across teams
  • Work closely with engineering, AI, and product teams to ensure research turns into shipped capabilities.
  • Leverage and shape AI-driven analysis
  • Contribute to the development of ML-assisted workflows for malware analysis and classification.
  • Publish and lead industry research
  • Author threat reports, blogs, and conference presentations — owning the narrative, not just the data.
  • Engage directly with customers
  • Provide post-incident insights, architecture guidance, and strategic advisory.


Skills required:

  • Strong hands-on experience with binary reverse engineering (Ghidra, IDA) across multiple architectures
  • Expertise in dynamic malware analysis and controlled detonation environments
  • Solid programming skills in Python and/or Go
  • Deep understanding of network protocols and packet-level behavior (PCAP analysis)
  • Experience analyzing botnet malware families (e.g., Mirai lineage or similar) at the implementation level
  • Ability to clearly communicate complex technical findings to diverse audiences

// // //