Malware Analyst

Company: Box
Company: Box
Location: Warsaw, Poland
Posted on: 2023-04-20 21:48
WHAT IS BOX? Box is the market leader for Cloud Content Management. Our mission is to power how the world works together. Box is partnering with enterprise organizations to accelerate their digital transformation by creating a single platform for secure content management, collaboration and workflow. We have an amazing opportunity to further establish ourselves as leaders in the space, and we need strong advocates to help us achieve that goal. By joining Box, you will have the unique opportunity to help capture a majority of this developing market and define what content management looks like for the digital enterprise. Today, Box powers 100,000+ businesses, including many top Fortune 500 companies who trust our secure collaboration platform to manage the entire content lifecycle.   WHY BOX NEEDS YOU  The Cyber Security Malware Analyst will lead team efforts to develop and extract IOCs and ATT&CK techniques from malicious binaries and use the resulting data to inform Threat Operations Team efforts to create detection logic. The Malware Analyst will also work closely with SIRT and Threat Intelligence to coordinate and integrate intelligence into operational processes. This role will also work closely with the Shield product team, performing deep analysis on malware and assisting with Shield product detection.    WHAT YOU'LL DO  Design, implement and maintain a malware lab that is both cloud and bare metal based and continue to develop customized technical solution sets to monitor and analyze malware  Lead efforts to analyze executables and malicious files  Investigate computer systems to identify malware infections or evidence of malware related activity  Preform ad hoc memory and disk forensics  Produce detailed technical reports and presentations in support of malware investigations  Maintain proper evidence custody and control procedures, documents procedures and findings  Perform malware and intrusion analysis, host-based forensics and threat intelligence collection  Perform incident response duties, including log and data collection and preservation and host and network forensics and provide collaboration and tactical communications, including situation reports for the team, management, administrators, and end-users  Act as a subject matter expert for inquiries by internal IT engineering teams  A passion for research, and uncovering the unknown about internet threats and threat actor  Shifted hours occasionally needed for collaboration with the Global Security Team   WHO YOU ARE  3+ years of recent operational security experience (SOC, Incident Response, Malware Analysis, IDS/IPS Analysis, etc) ( with 5+ years overall IT experience) Experience designing, building or using an isolated malware analysis environment Bachelor's degree in Information Technology, related discipline or relevant work experience  Experience and knowledgeable of: IDA Pro disassembler, Ollydbg or Hex-Rays Decompiler, user and kernel mode debuggers, common binary file formats, dynamic analysis tools, network analysis tools Working knowledge of full packet capture PCAP analysis and accompanying tools (Wireshark, etc.)  Nominal understanding of regular expression and fundamental knowledge of programming (.NET or C/C++) and scripting languages (e.g. Perl, Java, or Python)  Experience performing the role of a technical lead in complex IT/Security Projects  Experience in identifying and defeating malware defense mechanism such as anti-reverse, anti-debug, and anti-virtual machine  Demonstrated knowledge of Linux/UNIX, Mac & Windows operating systems  Detailed understanding of the TCP/IP networking stack & network technologies  Knowledge of memory forensics to identify and understand memory resident malware  Relevant Technical Security Certifications (GIAC, EC-Council, Offensive Security, etc) will be an asset   EQUAL OPPORTUNITY We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability, and any other protected ground of discrimination under applicable human rights legislation.    For details on how we protect your information when you apply, please see our Personnel Privacy Notice . For more details on how Box Poland protects your information, please see our Supplemental Personnel and Candidate Privacy Notice .    #LI-KS2
View Original Job Posting