Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Team Lead - Reverse Engineering

Group-IB
CompanyGroup-IB
CategoryEngineering
LocationCairo
RemoteOn-site (inferred)
EmploymentNot stated
LevelManager
SalaryNot stated by the employer
Posted24 Jun 2026
Last verified30 Jul 2026
SourceEmployer career page (greenhouse)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
Founded in 2003 and headquartered in Singapore, Group-IB is a leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime. Combating cybercrime is in the company’s DNA, shaping its technological capabilities to defend businesses, citizens, and support law enforcement operations. Group-IB’s Digital Crime Resistance Centers (DCRCs) are located in the Middle East, Europe, Central Asia, and Asia-Pacific to help critically analyze and promptly mitigate regional and country-specific threats. These mission-critical units help Group-IB strengthen its contribution to global cybercrime prevention and continually expand its threat-hunting capabilities. ABOUT THE ROLE We are looking for a Team Lead - Reverse Engineering to lead a small but high-impact squad of reverse engineers focused on supporting customer-driven investigations, DFIR engagements with malware reversing expertise, and threat intelligence production. The role is responsible for managing and mentoring a squad of reverse engineers, ensuring high-quality technical analysis, and enabling the team to deliver actionable intelligence and reversing support across customer RFIs, incident response cases, malware investigations, and Middle East threat landscape research. This position combines deep technical reverse engineering expertise , team leadership , and research-driven threat intelligence contribution . YOUR MISSION 1. Squad Leadership and Technical Management Lead and mentor a squad of reverse engineers, ensuring clear priorities, quality output, and continuous technical growth. Responsibilities include: Assigning and prioritizing reverse engineering tasks based on customer RFIs, DFIR needs, and threat intelligence requirements. Reviewing technical analysis, reports, YARA rules, configuration extractors, and malware capability assessments. Defining analysis depth based on case priority, from basic triage to deep code-level reversing. Ensuring the squad maintains strong documentation, reusable knowledge, and consistent analytical standards. Coaching team members on advanced reversing techniques, tooling, automation, and research methodology. 2. Threat Intelligence Generation Contribute to threat intelligence production focused on the Middle East threat landscape , including cybercriminal, hacktivist, and APT activity. The role should help transform reverse engineering findings into intelligence outcomes such as: Malware profiles. Threat actor capability assessments. Campaign or cluster analysis. Technical blogs, spot reports, and internal intelligence notes. Detection logic and hunting leads. Comparisons between new samples and known regional threat activity. A key expectation is to connect technical malware findings with broader intelligence context, including victimology, targeting, infrastructure, tactics, and regional relevance. 3. R&D and Capability Development Drive improvements in software reverse engineering workflows through tooling, automation, and process development. Areas of contribution may include: Automated malware triage pipelines. Configuration extractors. Similarity analysis workflows. YARA generation and validation pipelines. Sandbox integration. IDA/Ghidra/Binary Ninja scripting. Internal knowledge bases and malware profile enrichment. AI-assisted reverse engineering experiments. Repeatable workflows for L1/L2/L3 malware analysis. The ideal candidate should be able to identify bottlenecks in the reversing process and propose practical automation or tooling improvements   WHAT WE ARE LOOKING FOR The candidate should have strong hands-on experience in: Malware reverse engineering on Windows and Linux. Static and dynamic analysis. x86/x64 assembly and common compiler patterns. Debugging, unpacking, deobfuscation, and anti-analysis bypass. Malware families such as loaders, stealers, RATs, r
HOUSE AD986,449 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →