HalcyonHA

Reverse Engineer

Threats like ransomware are designed to evade modern security tools, and just one miss can have a catastrophic impact on your organization.

Halcyon

Employee count: 51-200

What we do:
Halcyon is the industry’s first dedicated, adaptive security platform that combines multiple proprietary advanced prevention engines along with AI models focused specifically on stopping ransomware.

Who we are:
Halcyon was formed in 2021 by a team of cyber industry veterans after battling the scourge of ransomware (and advanced threats) for years at some of the largest global security vendors. Comprised of leaders from Cylance (now Blackberry), Accuvant (now Optiv), Fireye and ISS X-Force (now IBM), Halcyon is focused on building products and solutions for mid-market and enterprise customers.

As a remote-native, completely distributed global team, we recognize great talent can exist anywhere. We invite you to apply to a job you’re interested in and we'll work a plan to meet your needs.

The Role:
Halcyon is redefining what modern security products can achieve, focusing on disrupting the ransomware economy through innovative, prevention-first technology. We’re seeking an experienced Reverse Engineer with a strong background in malware analysis, security research, and anti-virus technologies to help us stay ahead of emerging threats. This individual will play a key role in refining detection accuracy, expanding coverage, and contributing to the next generation of anti-ransomware defense. Responsibilities:
  • Reverse engineer malware and suspicious binaries using both static and dynamic techniques to extract indicators of compromise (IOCs), identify evasion techniques, and map behavior to the ransomware attack chain.
  • Monitor and triage security events, identifying malicious activity through data correlation, pattern analysis, and contextual threat enrichment.
  • Develop and maintain internal tools and scripts to support threat hunting, triage, and automated analysis workflows (Python, C, C++, shell scripting).
  • Analyze and assess PE file structures, obfuscation methods, and payload delivery mechanisms to detect new or evolving threats.
  • Collaborate with engineering teams to translate research into detections and product enhancements, and work closely with Customer Success during incident response.
  • Contribute to threat intelligence efforts and share actionable findings internally to improve detection and prevention strategies.
Minimum Qualifications:
  • Strong experience in reverse engineering malware using tools such as IDA Pro, Ghidra, x64dbg, WinDbg, or similar.
  • Deep understanding of Windows internals, PE file format, and ransomware attack chains.
  • Prior experience at an anti-virus (AV) or endpoint security company, or certification in reverse engineering (e.g., GREM, CREA, CRT, OSCE).
  • Proficient in one or more development/scripting languages: Python, C, C++.
  • Experience developing Yara rules and malware detection signatures.
  • Excellent communication skills and ability to clearly convey complex technical findings.
  • A passion for staying ahead of adversaries in an ever-evolving threat landscape.
Bonus Points:
  • Experience with kernel-level analysis or rootkit detection.
  • Prior research publications or community contributions in malware analysis.
  • Experience automating malware analysis pipelines or integrating sandbox results into detection infrastructure.

In accordance with applicable state and federal laws, the range provided is Halcyon’s reasonable estimate of the base compensation for this role. The actual amount may differ based on non-discriminatory factors such as experience, knowledge, skills, abilities, and location. Base pay is one part of the total package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and equity in the Company.

We understand it takes a diverse team of highly intelligent, passionate, curious, and creative people to develop the exceptional product we are building. Our dynamic team has incredible perspectives to share, just as we know you do, and we take great pride in being an equal opportunity employer.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Mid-level

Location requirements

Open to candidates from all countries.

Hiring timezones

Worldwide

About Halcyon

Learn more about Halcyon and their company culture.

View company profile

Threats like ransomware are designed to evade modern security tools, and just one miss can have a catastrophic impact on your organization. Halcyon is the first Anti-Ransomware and Cyber Resilience Platform with automated encryption key capture and autonomous decryption capabilities to keep your operations running 24/7/365.

Most security vendors are quick to update their solutions once a threat is seen in the real world. But what if you are one of the first victims? Without a dedicated anti-ransomware engine, the protection gap can range from 24 hours to several days or even weeks. Traditional rules-based EDR and other endpoint protection products rely on convolutional neural network AI models for detection that are generally too complex to quickly train on emerging threats. In contrast, Halcyon leverages Capsule Networks (CapsNets) AI micro-models that allow us to rapidly train, test and deploy new protection mechanisms to address novel and emerging threats exponentially faster than traditional endpoint tools.

After gaining initial access to a system, attackers will routinely target security tools active on an endpoint. Bypassing and unhooking these products has a lower resource cost than attempting to sneak malicious binaries or scripts past automated detection tools. With countless real-world bypasses published, it is clear that security products also need to be hardened against attacks. The Halcyon agent specifically prevents leading endpoint tools from being disabled, bypassed or unhooked.

Ransomware events can seriously disrupt business operations, that is why our resilience engine was designed to recover infected systems as quickly as possible. Once a ransomware incident occurs, the remediation clock starts ticking. While Halcyon delivers the most advanced detection and prevention capabilities in the market, we also provide the only automated resilience layer to assure a ransomware attack never slips by your defenses. Halcyon is enabled with automated encryption key capture and autonomous decryption capabilities that immediately decrypt any infected devices.

Employee benefits

Learn about the employee benefits and perks provided at Halcyon.

View benefits

Equity benefits

We offer competitive compensation packages with equity.

Life insurance

Halcyon offers life insurance as part of its benefits package.

Paid parental leave

Halcyon offers paid time off to care for and bond with a new child.

Short & long term disability insurance

Halcyon provides short and long-term disability insurance for its employees.

View Halcyon's employee benefits
Claim this profileHalcyon logoHA

Halcyon

Company size

51-200 employees

Founded in

2021

Chief executive officer

Jon Miller

Employees live in

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

33 remote jobs at Halcyon

Explore the variety of open remote roles at Halcyon, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Halcyon

Remote companies like Halcyon

Find your next opportunity by exploring profiles of companies that are similar to Halcyon. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 85,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan
Halcyon hiring Reverse Engineer • Remote (Work from Home) | Himalayas