02 Oct
|
Quick Heal
|
Chennai
02 Oct
Quick Heal
Chennai
:
Designation / Title
Principal Security Researcher I – Malware Research & Detection Engineering
Experience (Years)
8+ Years
Joining Location
Pune
About Quick Heal
Quick Heal Technologies Ltd, founded in 1995 and headquartered in Pune, is India’s leading listed cybersecurity solutions provider with 23 offices and 1,000+ professionals. Through its enterprise arm Seqrite, the company delivers cutting-edge Zero Trust solutions to secure endpoints, data, networks, and users across industries and geographies.
Seqrite Labs powers its offerings with advanced threat research, intelligence, and real-time detection. Notably, Seqrite secured ISRO’s command & control center during the Chandrayaan 3 mission. Its services division provides consulting to corporates, PSUs, government, and law enforcement agencies worldwide.
Core Purpose: Innovate to simplify digital security
Vision: To be trusted globally as a cybersecurity leader
Mission: Empower teams to solve business problems
Seqrite stands out as a purpose-led organization that invests in people, fosters innovation, and offers opportunities to work on new technologies while building a safer digital world.
Job Summary
***(*A brief overview of the role, its purpose, and key responsibilities.)
Principal Security Researcher with expertise in malware analysis, behavioral detection, threat research, and detection engineering for enterprise endpoint security products. Experienced in agile malware analysis, reverse engineering, Non-PE threat investigation, behavioral signature writing, YARA rule development, threat hunting, Root Cause Analysis (RCA), and MITRE ATT&CK; mapping across Windows environments. Proficient in researching emerging malware families, attacker tradecraft, and developing behavioral, signature-based, and telemetry-driven detections for EDR/XDR platforms.
Hands-on experience with IDA Pro, Ghidra, x64dbg, Process Monitor, Process Explorer, Wireshark, sandbox environments, and Windows internals debugging tools for malware investigation and runtime analysis. Experienced in technical documentation, technical blog and white paper authoring, quarterly threat reporting, mentoring researchers, collaborating with engineering teams, presenting technical findings to stakeholders, delivering customer-facing product demonstrations, and leveraging AI-assisted workflows to accelerate malware research, detection development, and validation.
Job Responsibilities
(The key tasks and duties you will be expected to perform in this role.)
- Perform dynamic and behavioral analysis of malware samples, scripts, droppers, loaders, LolBins, Ransomware and fileless threats.
- Reverse engineer suspicious binaries and scripts to identify execution flow, persistence mechanisms, and evasion techniques.
- Analyze obfuscated PowerShell scripts, encoded payloads, and multi-stage attack chains.
- Perform runtime analysis using process, memory, registry, and network monitoring tools.
- Investigate process injection, registry abuse, scheduled tasks, WMI activity, and command-line based attacks.
- Research Windows internals including process creation, token manipulation, services, drivers, COM, WMI, Scheduled Tasks, Registry, etc.
- Research malware families, attacker tradecraft, and emerging threat techniques affecting Windows endpoints.
- Research MITRE ATT&CK; techniques and map detections to ATT&CK; coverage.
- Perform threat hunting for similar malware family using endpoint telemetry and behavioral indicators.
- Evaluate public threat intelligence reports and convert them into product detections.
- Write behavioral and string-based detection signatures for PE and Non-PE threats, malicious scripts, and suspicious runtime activities.
- Validate detection coverage and tune behavioral policies to reduce false positives.
- Analyze false positives/false negatives and continuously improve detection efficacy.
- Document the complete attack chain, map techniques to the MITRE ATT&CK; framework, and develop or recommend comprehensive detection coverage using behavioral, signature-based, and telemetry-driven detection mechanisms.
- Perform Root Cause Analysis (RCA) for customer-reported security incidents by investigating malware behavior, attack vectors, and affected systems.
- Collaborate with threat research and endpoint protection teams on detection improvements.
- Collaborate with engineering teams during implementation of detection logic.
- Prepare technical analysis reports for newly identified malware families and attack techniques.
- Create technical documentation, playbooks, knowledge base articles, and detection documentation.
- Write and publish technical blogs, white papers, and quarterly threat intelligence reports.
- Attend and present at international and local cybersecurity conferences, workshops, and technical events.
- Mentor junior researchers, conduct technical knowledge-sharing sessions, and review detection content to maintain research quality.
- Consolidate team deliverables, prepare progress reports using pivot tables and other reporting tools, and present project status and key metrics to management.
- Present technical reports, project updates, research findings, and progress updates to management and internal stakeholders during review meetings.
- Deliver technical product demonstrations, explain product capabilities, and address technical queries from customers and stakeholders when required.
- Comfortable with content generation related to EDR/XDR technology including Policy writing, Simulation, Playbooks and automation.
Use AI-assisted workflows to accelerate malware triage, detection generation, and research validation.
Must Have Skills
(The essential skills and expertise required to succeed in this role.)
Technical Expertise
- Malware Analysis & Reverse Engineering
- Static & Dynamic Malware Analysis & Signature Writing
- Behavioral Detection Engineering
- YARA Rule Development
- Non-PE Threat Analysis
- PowerShell & Script Analysis
- LOLBins Detection
- Fileless Threat Investigation
- Memory Analysis & Forensics
- Windows Internals
- Process Injection & Persistence Analysis
- Root Cause Analysis of Incidents
- Threat Hunting & Threat Intelligence
- MITRE ATT&CK; Mapping
- IOC Extraction & Threat Intelligence
- Detection Validation & False Positive Reduction
- Threat Pattern Correlation
- EDR/XDR Detection Content Development
- Technical Documentation & Threat Reporting
AI-assisted Malware Research Nice / Good to have skills
(Additional skills that are not mandatory but give you an added advantage in this role.)
(Benefits to be added)
Job Snapshot
Updated Date
30-09-2026
Job ID
QH_2502
Department
SEQRITE LABS
Location
Chennai, Chennai, Tamil Nadu, India
Experience
8 - 10 Years
Employee Type
Full Time
📌 Principal Software Engineer I (Chennai)
🏢 Quick Heal
📍 Chennai