Malware Analyst


Box is the market leader for Cloud Content Management. Our mission is to power how the world works together. Box is partnering with enterprise organizations to accelerate their digital transformation by creating a single platform for secure content management, collaboration and workflow. We have an amazing opportunity to further establish ourselves as leaders in the space, and we need strong advocates to help us achieve that goal. 

By joining Box, you will have the unique opportunity to help capture a majority of this developing market and define what content management looks like for the digital enterprise. Today, Box powers over 97,000 businesses, including 70% of the Fortune 500 who trust Box to manage their content in the cloud


The Cyber Security Malware Analyst will lead team efforts to develop and extract IOCs and ATT&CK techniques from malicious binaries and use the resulting data to inform Threat Operations Team efforts to create detection logic. The Malware Analyst will also work closely with SIRT and Threat Intelligence to coordinate and integrate intelligence into operational processes. This role will also work closely with the Shield product team, performing deep analysis on malware and assisting with Shield product detection. 


  • Provide expertise on the design, implementation and maintenance of a malware lab that is both cloud and bare metal based and continue to develop customized technical solution sets to monitor and analyze malware 
  • Lead efforts to analyze executables and malicious files 
  • Investigate computer systems to identify malware infections or evidence of malware related activity 
  • Preform ad hoc memory and disk forensics 
  • Produce detailed technical reports and presentations in support of malware investigations 
  • Maintain proper evidence custody and control procedures, documents procedures and findings 
  • Perform malware and intrusion analysis, host-based forensics and threat intelligence collection 
  • Collaborate with SIRT to perform log and data collection and preservation and host and network forensics and provide tactical communications, including situation reports for the team, management, administrators, and end-users 
  • Act as a subject matter expert for inquiries by internal IT engineering teams 
  • A passion for research, and uncovering the unknown about internet threats and threat actors
  • Shifted hours occasionally needed for collaboration with the Global Security Team


  • 3+ years of recent operational security experience (SOC, Incident Response, Malware Analysis, IDS/IPS Analysis, etc) ( with 5+ years overall IT experience)
  • Experience designing, building or using an isolated malware analysis environment
  • Bachelor's degree in Information Technology, related discipline or relevant work experience 
  • Experience and knowledgeable of: IDA Pro disassembler, Ollydbg or Hex-Rays Decompiler, user and kernel mode debuggers, common binary file formats, dynamic analysis tools, network analysis tools
  • Working knowledge of full packet capture PCAP analysis and accompanying tools (Wireshark, etc.) 
  • Nominal understanding of regular expression and fundamental knowledge of programming (.NET or C/C++) and scripting languages (e.g. Perl, Java, or Python) 
  • Experience performing the role of a technical lead in complex IT/Security Projects 
  • Experience in identifying and defeating malware defense mechanism such as anti-reverse, anti-debug, and anti-virtual machine 
  • Demonstrated knowledge of Linux/UNIX, Mac & Windows operating systems 
  • Detailed understanding of the TCP/IP networking stack & network technologies 
  • Knowledge of memory forensics to identify and understand memory resident malware 
  • Relevant Technical Security Certifications (GIAC, EC-Council, Offensive Security, etc) will be an asset


We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability, and any other protected ground of discrimination under applicable human rights legislation. Box strives to respect the dignity and ‎‎independence of people with disabilities and is committed to giving them the same ‎‎opportunity to succeed as all other employees. Accommodations are available ‎throughout ‎the application process and an employee’s employment at Box.

For details on how we protect your information when you apply, please see our Personnel Privacy Notice.

Cyber Security Jobs by Category

Cyber Security Salaries