Threat Analyst
HalcyonAbout the role
What we do:
Halcyon is the industry’s first dedicated, adaptive security platform that combines multiple proprietary advanced prevention engines along with AI models focused specifically on stopping ransomware.
Who we are:
Halcyon was formed in 2021 by a team of cyber industry veterans after battling the scourge of ransomware (and advanced threats) for years at some of the largest global security vendors. Comprised of leaders from Cylance (now Blackberry), Accuvant (now Optiv), Fireye and ISS X-Force (now IBM), Halcyon is focused on building products and solutions for mid-market and enterprise customers.
As a remote-native, completely distributed global team, we recognize great talent can exist anywhere. We invite you to apply to a job you’re interested in and we'll work a plan to meet your needs.
The Role:
Halcyon’s mission is to empower our customers with a solution that defeats ransomware, makes "ransomware history", and ensures operational resilience. To support this mission, we are seeking a highly skilled Threat Analyst with deep technical expertise in malware reversing, detection engineering, and security operations. This role is critical to advancing our detection, prevention, and response capabilities, ensuring broad coverage of emerging threats, eliminating false positives, and effectively responding to these threats. The right candidate will ensure that our customers are kept safe from the latest ransomware without impacting legitimate business operations.
Responsibilities
- Monitor and analyze security events to detect, investigate, contain, and escalate potential threats. Correlate data across multiple sources to identify malicious activity and patterns.
- Triage and assess events to determine impact, contain incidents, and drive threat remediation.
- Reverse engineer Windows PE files and other malicious binaries using static and dynamic techniques to uncover capabilities, persistence methods, and indicators of compromise (IOCs).
- Design, develop, and maintain internal tools to support threat triage, correlation, and research (log parsers, incident tracking systems, custom sandboxes, etc.).
- Conduct malware analysis in disassemblers, debuggers, and sandbox environments to understand payloads, infection chains, and evasion techniques.
- Research and track evolving ransomware techniques, publishing findings to improve detection logic and response processes.
- Collaborate closely with Customers, Incident Response, Engineering and Customer Success to improve product resilience and ensure smooth customer communication during security events.
Skills and Qualifications
- 10+ years of combined experience in reverse engineering, detection engineering, threat research, incident response, or security operations related roles.
- High proficiency in malware reversing, with demonstrated expertise in analyzing Windows PE files, unpacking obfuscated samples, and extracting behavioral and static indicators.
- Experience with Artificial Intelligence / Machine Learning methodologies and their practical use cases to enhance cybersecurity strategies and operational efficiency.
- Hands-on experience with Yara, Python, and scripting languages (PowerShell, Bash/Shell, Batch).
- Advanced knowledge of static and dynamic analysis using tools such as IDA Pro, Ghidra, x64dbg, WinDbg, Cuckoo or similar sandboxes.
- Familiarity with EDR evasion techniques, persistence mechanisms, and exploitation methods.
- Cloud Service Provider experience preferred (cloud l
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s