Zscaler
About this role
This sits in ThreatLabz, Zscaler's threat research group, and it is malware analysis work with a new target attached. You pull apart malicious software statically and dynamically, build detection signatures, and track how attackers operate. The twist is that the brief now explicitly includes malicious AI agents and command and control frameworks, and part of the job is producing the training and test datasets that Zscaler's machine learning detection models learn from, then validating what those models output. You also publish: the posting asks you to contribute threat analysis blogs and research papers to the security community. It is a hybrid role reporting into the Threat Detection Group. At 4 to 7 years it is the one genuinely mid level opening on today's board.
Who this is for
What the posting requires: four to seven years in cyber security research (the posting spells the numbers out in words rather than digits). Strong proficiency in reverse engineering and debugging with tools such as IDA Pro or x64dbg. Deep understanding of Windows internals, web application security, malware categories, and network protocols across TCP/IP and the OWASP frameworks. Proven experience creating detection signatures with IDS or IPS and YARA. Strong programming in Python, Shell, Perl or Ruby for building automation tooling. Demonstrated curiosity about AI tools is again listed under minimum qualifications.
Nice to have: experience designing AI powered automation or prompt engineering workflows to scale threat research and analyse malicious AI agents; certifications in AI, prompt engineering or agentic AI workflows; familiarity with the MCP protocol; and a B.E, M.E, B.Tech or M.Tech in computer science or IT, or advanced cybersecurity certifications.
The day to day: static and dynamic malware analysis against emerging threats, C2 frameworks and malicious AI agents; building automation tools, prototypes and detection signatures that ship into Zscaler products; tracking attacker tactics and running reputation analysis on extracted indicators; validating AI and ML model output and feeding that back to engineering; and publishing research.
Location and office reality: listed for Bangalore, Hyderabad, Mohali or Pune, and tagged hybrid in the posting itself.
Who this is for: a malware analyst or detection engineer with real reverse engineering hours who wants to move toward the AI side of security research without leaving hands on analysis behind. Note the reporting line is into a leader in the Threat Detection Group, and despite the Staff title the years asked for are 4 to 7, which is lower than most Staff titles on this board.
Nice to have: experience designing AI powered automation or prompt engineering workflows to scale threat research and analyse malicious AI agents; certifications in AI, prompt engineering or agentic AI workflows; familiarity with the MCP protocol; and a B.E, M.E, B.Tech or M.Tech in computer science or IT, or advanced cybersecurity certifications.
The day to day: static and dynamic malware analysis against emerging threats, C2 frameworks and malicious AI agents; building automation tools, prototypes and detection signatures that ship into Zscaler products; tracking attacker tactics and running reputation analysis on extracted indicators; validating AI and ML model output and feeding that back to engineering; and publishing research.
Location and office reality: listed for Bangalore, Hyderabad, Mohali or Pune, and tagged hybrid in the posting itself.
Who this is for: a malware analyst or detection engineer with real reverse engineering hours who wants to move toward the AI side of security research without leaving hands on analysis behind. Note the reporting line is into a leader in the Threat Detection Group, and despite the Staff title the years asked for are 4 to 7, which is lower than most Staff titles on this board.
Apply on company site
Opens job-boards.greenhouse.io, the employer's own application page. Applying is always free.