Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
TikTok USDS logo

Malware Analyst

TikTok USDS
  • 🇺🇸 United States
  • On-site
  • Staff / Principal
  • 1 week ago
  • Incident Response
  • triage
  • Threat Intelligence
  • Windows
  • Linux
  • TCP/IP
  • DNS
  • TLS
  • Python
  • PowerShell
  • Bash
  • JavaScript
  • Ghidra
  • Wireshark
  • Git
  • GCIH
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

About the Team

The USDS JV Threat Detection and Response team is responsible for protecting TikTok’s people, data, and systems from threats that originate within the organization. We partner across Security, Legal, HR, IT, and Engineering to detect, investigate, and mitigate insider risks ranging from data exfiltration and policy violations to fraud and unauthorized access.

About the Role

As a Senior Analyst on the USJV Forensics & Response team, you will be at the forefront of our organization's digital investigations and incident response (DFIR) efforts. In this critical position, you will lead complex forensic investigations across a diverse technical landscape, including enterprise endpoints, servers, mobile devices, data platforms, and cloud infrastructure.

Responsibilities

  • Malware Triage & Analysis: Perform initial triage and basic static and dynamic analysis of suspicious files, scripts, and executables under the guidance of senior analysts to identify malicious capabilities and behavior.
  • Artifact & Indicator Extraction: Extract and validate indicators of compromise, including file hashes, domains, IP addresses, URLs, registry changes, and persistence mechanisms to support investigations and detection.
  • Incident Investigation Support: Assist incident responders by analyzing suspicious artifacts, reviewing endpoint and network activity, and documenting findings relevant to incident scope and containment.
  • Reverse Engineering Support: Use disassemblers, debuggers, and script analysis tools to investigate basic program logic, encoded content, and execution flows. Escalate complex samples for advanced analysis.
  • Threat Intelligence & Detection Support: Research malware families and related techniques, map observed behavior to MITRE ATT&CK, and assist with developing and validating YARA rules and other detection content.
  • Evidence Handling & Preservation: Collect, label, hash, and securely store malware samples and related evidence in accordance with evidence handling, chain-of-custody, and data protection procedures.
  • Reporting & Documentation: Prepare clear analysis reports describing methods, observed behavior, indicators, limitations, and recommended the next steps. Maintain accurate investigation notes and sample records.
  • Lab & Tool Maintenance: Assist with maintaining isolated analysis environments, virtual machines, snapshots, and analysis tools. Follow approved procedures for safely handling and executing malware.
  • Scripting & Automation: Develop and maintain basic scripts for sample triage, indicator extraction, data enrichment, and repetitive analysis tasks with guidance and code review.

Minimum Qualifications

  • 2+ years of relevant experience in malware analysis, cybersecurity operations, digital forensics, or incident response. Relevant internships, coursework, independent projects, and practical lab experience may satisfy this requirement.
  • Foundational understanding of Windows and Linux operating systems, including processes, services, file systems, permissions, and common persistence mechanisms. Basic understanding of networking concepts and protocols, including TCP/IP, DNS, HTTP, and TLS.
  • Familiarity with static and dynamic analysis concepts, including file identification, hashing, strings extraction, and behavioral monitoring. Ability to read and modify basic scripts in Python, PowerShell, Bash, or JavaScript.
  • Ability to document technical findings clearly, distinguish observed facts from assumptions, and communicate results to technical and nontechnical stakeholders. Understanding of safe malware handling and isolated analysis practices, with the ability to follow established procedures and recognize when to seek assistance.

Preferred Qualifications

  • Hands-on exposure to malware analysis tools such as Ghidra, IDA Free, x64dbg, Process Monitor, Wireshark, or equivalent tools. Familiarity with executable file formats, particularly Windows Portable Executable (PE) files, and introductory knowledge of x86/x64 assembly.
  • Exposure to analyzing malicious scripts, phishing attachments, or document-based threats, including encoded or obfuscated content. Experience creating basic YARA rules or using detection rules to identify suspicious files and behavior.
  • Familiarity with MITRE ATT&CK and researching malware families through approved threat intelligence sources. Exposure to endpoint detection and response tools, sandbox reports, memory analysis, or network traffic analysis.
  • Experience using Git and scripting to automate analysis or organize technical work. Bachelor’s degree in cybersecurity, computer science, digital forensics, or a related field; or equivalent practical experience and training. Relevant certifications such as Security+, GFACT, GCIH, GREM, or equivalent.

Malware Analyst · TikTok USDS

Auto apply with Likeremote