Résumé du poste / Summary
Support ESET Threat Research by building and maintaining internal tools, automation, and data pipelines that accelerate the delivery of actionable threat intelligence. This is a support role embedded in the research team. You will not reverse malware yourself. You will remove the friction around how researchers work: unifying scattered metadata, automating the path from analysis to customer deliverables, and giving researchers one good interface instead of ten.
Description du poste /
Meet the Team
ESET Research is a team of 30+ researchers all over the world who analyze complex cyber-espionage and cybercrime operations. We work in collaboration with other internal teams to improve ESET products and create resilient malware detections. Our primary goal is to understand how threat groups operate in order to better protect our customers and disrupt malicious activities.
We write private reports that are available to ESET Threat Intelligence customers. We share our knowledge publicly on ESET’s blog, https://www.welivesecurity.com/research/, and at technical conferences all around the world (Virus Bulletin, BlackHat, RSA, Botconf, etc.).
About the Role
Build and maintain internal tools that unify sample metadata across multiple internal and external systems (network telemetry, sandbox, malware repository, TI platform) and make threat intelligence data searchable and reusable. Develop and maintain automated pipelines that move analysis outputs into TI platforms (e.g. MISP) and generate customer-facing deliverables such as IOC tables, indicator packages, and report skeletons. Create researcher-facing web applications and workflows for sample lookup, triage status, analysis tracking, and tagging. Own the tooling backlog in partnership with researchers. Collaborate with engineering teams owning upstream systems (telemetry, sandbox, etc.). Proactively identify reliability, performance, and correctness issues services before they become incidents — improve runbooks, dashboards, alerting, and automation.
Essential Requirements
- Experienced in Python and JavaScript, with a proven track record of designing, building and maintaining Python systems with real operational accountability, not solely scripting or automation
- Create and maintain APIs, databases, queues, and data integration across multiple systems, including schema design, and query optimization.
- Familiarity with threat intelligence workflows — enough to understand what researchers do across internal systems, without needing to be a malware reverser.
- Experience building web applications.
- Experience with container technology (e.g. Docker), CI/CD, Git, and test automation.
- Secure coding practices for systems that handle malicious files and sensitive data.
- Strong collaboration and discovery skills —turning pain points into shipped tooling.
Desirable Requirements
- Familiarity with malware analysis workflows and common sample metadata (hashes, file type, packers, strings, imports, network indicators, sandbox behavior), including experience with sandboxes (CAPE, Cuckoo, Joe Sandbox, Any.Run, or internal equivalents) as data sources.
- Familiarity with MITRE ATT&CK; and mapping malware behavior to techniques.
- Experience using AI-assisted tooling thoughtfully — both to accelerate development backed by sound planning and to power researcher-facing features (report generation, structured extraction), with strong judgment about validation, code quality and security limitations.
- Familiarity with building modern CLI/TUI/WebUI tooling.
- Prior work delivering tooling to threat intelligence or security research teams.
- Participation to CTFs
Avantages du poste / Benefits
- Santé et bien-être
- Régime d'assurance privée collective
- Plan d'épargne retraite collectif
- Programme d'activité physique
- Supports à vélos intérieurs et programme de partage de vélos
- Bureau à domicile
- Jours de congé supplémentaires
- Horaires de travail flexibles
- Bureau Rafraîchissements au bureau (fruits, snacks, boissons et café)
- Petit-déjeuner 5 à 7 / Réunions après le travail
- Activités de renforcement de l'esprit d'équipe
- Salon commun ("Living room") avec PlayStation, ping-pong et baby-foot
- Activités de Noël
- Autres
- Apprentissage LinkedIn/ Udemi
- Programme de fidélisation (jours de vacances supplémentaires, bonus financier, gâteaux)
- Recommandation d'un ami
- Licence ESET gratuite pour les amis et la famille
- Cadeaux de Noël
- Health & well-being
- Group private insurance plan
- Group retirement savings plan
- Physical activity program
- Interior bike racks and bike sharing program
- Home office
- Extra days off
- Flexible work hours
- Office Refreshments in office (fruit, snacks, drinks & coffee)
- Breakfast 5 à 7 / Afterwork get togethers
- Teambuilding activities
- Common lounge ("Living room") with PlayStation, ping-pong and foosball tables
- Christmas activities
- Other LinkedIn Learning/ Udemi
- Loyalty program (extra vacation days, financial bonus, cake/cupcakes)
- Friend referral
- Christmas gifts
Locations
Primary location: Montreal
Additional locations: Bratislava, Prague
Type d'heure / Time type
Full time
Compensation
- Basic wage component for Bratislava location (brutto): from 2700 EUR
- The final basic wage component can be increased accordingly to individual skills and experience of the selected candidate.
- Performance bonus 2 times per year up to 10% of the basic salary paid for the evaluation period (usually 6 months).
ESET Values and Diversity
ESET® provides cutting-edge digital security to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of known and emerging cyberthreats — securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. Driven by science, ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users secure and businesses running without interruption. An ever-evolving digital landscape demands a progressive, evidence-based approach to security. ESET is committed to world‑class scientific research and powerful threat intelligence, backed by R&D; centers and a strong global partner network. ESET's purpose is not only to provides cutting‑edge digital security, but also to actively contribute to a more innovative and responsible society in terms of education, science and research. At ESET, diversity, equity, and inclusion (DEI) are integral to our corporate culture. We believe in creating a respectful environment, where everyone feels valued and respected, welcoming applications from individuals of all backgrounds, including race, gender, age, religion, disability, and sexual orientation. Learn more about ESET.
📌 Threat Research Software Engineer (m/f/n) (Montreal)
🏢 ESET
📍 Montreal