1

Malware Reverse Engineer Jobs in California (NOW HIRING)

Solid background in malware analysis and reverse engineering using IDA, HIEW, OllyDbg, or Windbg * Multi-threaded client/server application development experience Additional Information All your ...

Security Engineer

Burbank, CA ยท On-site

$70 - $80/hr

GIAC Reverse Engineering Malware (GREM) * GIAC Network Forensics Analyst (GNFA) * Offensive Security certifications (OSCP, OSCE, or similar) * Other relevant cybersecurity certification #SNIT

Malware reverse engineering skills. * Expertise with incident response frameworks. * Experience in the financial sector. * SANS, CHFI, OSCP or similar certification. This role requires working from a ...

... reverse engineer, and de-obfuscate content related to security incidents. * Maintain and enhance ... Malware analysis technical report writing. * Adherence to SOC standard operating procedures.

... reverse engineer, and de-obfuscate content related to a security incident. * Maintain the Digital ... Malware analysis technical report writing. * Adherence to SOC Standard Operating Procedures.

Senior Manager, Endpoint Protections

Mountain View, CA ยท On-site

$136K - $186K/yr

Hands-on reverse engineering and malware analysis experience. You have done this work yourself, and can still read a disassembly, assess a research finding on its merits, and judge which threats ...

New

Showing results 21-40

Malware Reverse Engineer information

See California salary details

$80.9K

$134.5K

$192.4K

How much do malware reverse engineer jobs pay per year?

As of Aug 18, 2026, the average yearly pay for malware reverse engineer in California is $134,501.00, according to ZipRecruiter salary data. Most workers in this role earn between $87,800.00 and $175,700.00 per year, depending on experience, location, and employer.

What does a malware reverse engineer do?

A Malware Reverse Engineer analyzes malicious software to understand its functionality, origin, and potential impact. They use tools like debuggers, disassemblers, and virtual environments to deconstruct malware and identify vulnerabilities or attack patterns. Their work helps in developing security defenses, creating detection signatures, and improving incident response. This role requires strong knowledge of programming, operating systems, and cybersecurity principles.

What are the key skills and qualifications needed to thrive as a malware reverse engineer?

To thrive as a Malware Reverse Engineer, you need strong expertise in reverse engineering, assembly language, and programming, often backed by a degree in computer science or cybersecurity and experience with malware analysis. Familiarity with tools such as IDA Pro, Ghidra, OllyDbg, and relevant certifications like GREM or OSCP is highly valued. Analytical thinking, meticulous attention to detail, and clear written communication are important soft skills in this field. These skills ensure accurate identification, dissection, and documentation of malicious code, supporting effective threat response and mitigation.

What are some typical challenges faced by malware reverse engineers in their daily work?

Malware Reverse Engineers frequently encounter highly complex or obfuscated malware designed to resist analysis, which can make the process both time-consuming and mentally demanding. Staying ahead of constantly evolving attack techniques requires ongoing learning and adaptability. The role often involves collaborating with incident response teams, threat intelligence analysts, and security researchers to provide clear, actionable insights on emerging threats. Successfully overcoming these challenges is critical for protecting organizational assets and staying current with the ever-changing cybersecurity landscape.

Can you reverse engineer malware?

A malware reverse engineer analyzes malicious software to understand its behavior, techniques, and purpose. This process involves using specialized tools like disassemblers and debuggers and requires strong knowledge of programming, assembly language, and cybersecurity principles.

How much do malware reverse engineers make?

Malware reverse engineers typically earn between $80,000 and $130,000 annually, depending on experience, location, and industry. Senior professionals with specialized skills in reverse engineering tools and techniques can earn higher salaries, especially in cybersecurity-focused roles or with certifications like GREM or OSCP.

What are the most commonly searched types of Malware Reverse Engineer jobs in California?

The most popular types of Malware Reverse Engineer jobs in California are:

What job categories do people searching Malware Reverse Engineer jobs in California look for?

The top searched job categories for Malware Reverse Engineer jobs in California are:

What cities in California are hiring for Malware Reverse Engineer jobs?

Cities in California with the most Malware Reverse Engineer job openings:

Infographic showing various Malware Reverse Engineer job openings in California as of August 2026, with employment types broken down into 95% Full Time, 2% Part Time, and 3% Contract. Highlights an 85% Physical, 6% Hybrid, and 9% Remote job distribution, with an average salary of $134,501 per year, or $64.7 per hour.

Principal Researcher, Botnet & DDoS Threats

Osv_a10networks

San Jose, CA โ€ข On-site

$200K - $215K/yr

Full-time

Re-posted 13 days ago


Job description

Principal Researcher, Botnet & DDoS Threats

The DDoS threat landscape has crossed a threshold. Botnets like Aisuru and Kimwolf-comprising millions of compromised Android TV and IoT devices and capable of attacks exceeding 24 Tbps and 9 billion packets per second-are no longer edge cases. They are the baseline.

Defeating these threats requires more than external observation. It requires deep visibility into how they are built, how they execute on the wire, and what that means for the systems designed to stop them.

This role sits at the intersection of binary exploitation research and real-world defensive impact. You will reverse engineer active IoT botnet malware, translate findings into detection logic and packet-level attack signatures, and work across engineering, product, and research to ensure insights directly improve detection and customer defense.

What you will do

  • Reverse engineer IoT botnet malware families (Mirai lineage, Go-based L7 flooders, multi-architecture binaries) to understand attack behavior at the implementation and network level. You will reconstruct command structures, decode obfuscation, recover control flows from stripped binaries, and build precise models of how attacks manifest on the wire

  • Perform dynamic malware analysis in sandboxed and purpose-built lab environments to validate static analysis and observe runtime behavior

  • Design and contribute to novel detection and mitigation approaches based on malware internals and traffic behavior

  • Collaborate with AI/ML teams to integrate automated analysis into research workflows. This is not passive tool usage-you will actively shape how automation is applied to real malware analysis problems

  • Partner with product engineering to translate research into shipped detection capabilities

  • Lead external-facing research: threat reports, technical blogs, and conference presentations. At principal level, you own the narrative and direction of research output

  • Engage directly with customers in post-incident analysis, architectural guidance, and strategic threat briefings-clearly explaining both attacker behavior and defensive actions

  • Work alongside senior researchers focused on IoT botnets and large-scale DDoS systems, contributing to and benefiting from a deeply technical peer environment

What you need

  • Strong foundation in binary reverse engineering using tools such as Ghidra or IDA, including static analysis across multiple architectures and experience with stripped binaries and compiler-generated code; you should be comfortable working close to raw assembly and control flow, not dependent on tooling abstraction

  • Hands-on experience with dynamic malware analysis in sandbox or isolated lab environments, using runtime observation to validate and extend static findings

  • Working proficiency in Python and Go

  • Strong understanding of network protocols at the implementation level, including the ability to interpret PCAPs and reconstruct protocol behavior

  • Familiarity with DDoS botnet architectures (e.g., Mirai lineage or equivalent), ideally with direct analysis of binaries rather than secondary reporting. Experience tracking variant evolution across malware families is a strong plus

  • Ability to communicate complex technical findings clearly across engineering, product, and customer audiences; at this level, communication quality is a core part of technical impact

Nice to have

  • Experience with high-performance packet processing or mitigation systems at the network and transport layers

  • Experience analyzing Go binaries in depth

  • Exposure to malware source code

  • Experience applying ML-assisted or vector-based approaches to malware classification, clustering, or lineage attribution

Tools & environment

Ghidra(headless + GUI), Capstone,GoReSym Python 3, Go,Scapy,tsharkAny.run, Joe Sandbox, Cuckoo (or equivalent) custom detonation lab infrastructure honeypot infrastructure MalwareBazaar,VirusTotal macOS or Linux

AI Use Guidelines for Interviews:Our interviews are designed to reflect your own skills and thinking. The use of AI or recording tools during live interviews is not permitted unless explicitly invited by the interviewer or approved in advance as part of a reasonable accommodation. If these tools are used inappropriately or in a way that misrepresents your work, your application may not move forward in the process.

Targeted compensation guideline: $200,000 - $215,000. Compensation will vary based on number of factors, including market demand for specific skills, role type, job level, and individual qualifications. Final salary offers are determined by considerations including, but not limited to, subject matter expertise, demonstrated skill level, relevant experience, geographic location, education, certifications, and training.A10 Networks is an equal opportunity employer and a VEVRAA federal subcontractor. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law. A10 also complies with all applicable state and local laws governing nondiscrimination in employment.#LI-AN1 - Hybrid