Software Engineer
Résumé du poste / Summary Description du poste / Job description Meet the Team ESET Research is a team of 30 + researchers all over the world who analyze complex cyber-espionage and cybercrime operations.
Résumé du poste / Summary
Description du poste / Job description
Meet the Team
ESET Research is a team of 30 + researchers all over the world who analyze complex cyber-espionage and cybercrime operations. We work in collaboration with other internal teams to improve ESET products and create resilient malware detections.
Our primary goal is to understand how threat groups operate in order to better protect our customers and disrupt malicious activities. We write private reports that are available to ESET Threat Intelligence customers.
We share our knowledge publicly on ESET’s blog, https://www.welivesecurity.com/research/ , and at technical conferences all around the world (Virus Bulletin, Black Hat, RSA, Botconf , etc.).
About the Role
Build and maintain internal tools that unify sample metadata across multiple internal and external systems (network telemetry, sandbox, malware repository, TI platform) and make threat intelligence data searchable and reusable .
Develop and maintain automated pipelines that move analysis outputs into TI platforms ( e.g. MISP) and generate customer-facing deliverables such as IOC tables, indicator packages, and report skeletons.
Create researcher-facing web applications and workflows for sample lookup, triage status, analysis tracking, an d tagging.
Own the tooling backlog in partnership with researchers .
Collaborate with engineering teams owning upstream systems (telemetry, sandbox, etc. ).
Proactively identify reliability, performance, and correctness issues services before they become incidents — improve runbooks, dashboards, alerting, and automation.
Essential Requirements
Experienced in Python and JavaScript, with a proven track record of designing , building and maintaining Python systems with real operational accountability, not solely scripting or automation
Create and maintain APIs , databases, queues, and data integration across multiple systems, including schema design, an d query optimization.
Familiarity with threat intelligence workflows — enough to understand what researchers do across internal systems, without needing to be a malware reverser.
Experience building web applications.
Experience with container technology ( e.g. Docker ) , CI/CD, Git, and test automation.
Secure coding practices for systems that handle malicious files and sensitive data.
Strong collaboration and discovery skills — turning pain points into shipped tooling.
Desirable Requirements
Familiarity with malware analysis workflows and common sample metadata (hashes, file type, packers, strings, imports, network indicators, sandbox behavior), including experience with sandboxes (CAPE, Cuckoo, Joe Sandbox, Any.Run , or internal equivalents) as data sources.
Familiarity with MITRE ATT&CK and mapping malware behavior to techniques.
Posted August 13, 2026