Skip to main content

Threat Research Engineer

Amsterdam, Hybrid
Full-time
Temporary
70,000 - 90,000 € per year

Who are we?

Want to reverse engineer mobile malware, build threat intelligence extraction pipelines, and help protect millions of banking customers from cybercrime?

We help the world's leading banks stay ahead of fraudsters, scammers, and cybercriminals. Our technology protects millions of users every day by detecting fraud, malware, and emerging attack techniques before damage is done. We do this by combining 15 years of extensive research with our own smart software.

At ThreatFabric, we're not just shaping the future of cybersecurity, we're defining it. With our headquarters in the vibrant city of Amsterdam, ThreatFabric stands at the forefront of combating online fraud, mobile malware, and threat intelligence.

Your mission

Position: Full-time | 40 hours per week
Location: Amsterdam, Netherlands | Hybrid (2–3 days office)
Salary Range: between 70.000,- and 90.000,- annually

About the job

As a Threat Research Engineer at ThreatFabric, you combine reverse engineering and software development skills to research threats identified by our Threat Analysts and automate threat intelligence extraction. Your mission is to transform raw malware samples into structured and actionable threat intelligence by creating, maintaining, and improving the tooling and analysis pipelines that power ThreatFabric's threat intelligence capabilities.

You will play a key role in developing deobfuscation tooling, config extractors, unpackers, and scalable analysis pipelines. Working closely with Threat Analysts within the MTI team, you will help automate intelligence extraction processes, improve analysis workflows, and ensure ThreatFabric continues to scale its threat intelligence operations.

You will work on a combination of reverse engineering, malware analysis, research, automation, monitoring, and software development, helping ThreatFabric stay ahead of emerging threats and provide high-quality threat intelligence to customers around the world.

Your key responsibilities will include:

  1. Performing reverse engineering of various threats, with a focus on mobile malware.
  2. Identifying reliable ways to automate threat intelligence extraction from malware samples.
  3. Supporting Threat Analysts in their research and investigation of threats.
  4. Creating deobfuscation modules, configuration extractors, and unpackers based on your own reverse engineering efforts or requests from Threat Analysts.
  5. Designing, building, and maintaining reliable and scalable analysis pipelines.
  6. Combining static analysis, dynamic analysis, and AI-powered assessments within analysis workflows.
  7. Developing and maintaining threat intelligence sharing tools to support ThreatFabric customers.
  8. Documenting and standardising existing and newly developed tooling to ensure maintainability by the wider team.
  9. Monitoring the performance and reliability of analysis pipelines.
  10. Identifying and communicating opportunities to improve analysis tooling and infrastructure.
  11. Performing traffic analysis as part of malware investigations.
  12. Using scripting techniques to perform decryption during malware analysis.
  13. Analysing simple native code when required.
  14. Contributing to the continuous improvement and scaling of ThreatFabric's threat intelligence extraction capabilities.
What We Offer
  1. A 12-month employment contract with the intention to extend. Subject to mutual satisfaction, this may lead to a permanent position.
  2. A competitive salary that reflects your skills and experience with a salary range between 70.000,- to 90.000,- annually.
  3. 25 holidays per year.
  4. 8% holiday allowance (included in annual salary).
  5. A Pension Scheme.
  6. A stimulating and supportive work environment that encourages growth and development.
  7. An annual personal Growth and Development budget.
  8. The opportunity to make a meaningful impact in a rapidly growing tech company.
  9. Flexible Remote / Hybrid work-from-home options to promote work-life balance.
  10. Flexible working hours.
  11. Active ThreatFabric events and FitFabric bootcamps.
  12. Active knowledge-sharing huddles.

Who are we looking for?

Skills & Competencies

Technical Skills

- 5-8 years of relevant experience in a similar role.

- Strong software engineering skills and the ability to write clean, tested, and maintainable code.

- Ability to create, maintain, and improve services and analysis pipelines.

-Practical reverse engineering experience with real malware

-Ability to identify and defeat obfuscation and encryption schemes

- Experience analysing communication protocols

- Experience establishing and maintaining scalable analysis services.

- Ability to reverse engineer most malware analysis cases independently.

- Experience performing traffic analysis.

- Experience using scripting to support malware analysis and decryption activities.

- Ability to analyse simple native code.

- Fluency in English, both written and spoken.

Analytical Skills

-Ability to translate ad-hoc analyst workflows into robust and generalised automation.
-Ability to identify patterns in malicious code and automate data extraction.
-Strong analytical and problem-solving capabilities.
-Ability to identify opportunities for automation and process improvement.
-Ability to connect technical findings to actionable threat intelligence.

Learning Ability & Eagerness to Learn

-Continuously develops expertise in reverse engineering, malware analysis, and threat intelligence extraction.
-Actively contributes to improving and scaling threat intelligence extraction pipelines.
-Keeps up to date with developments in malware analysis, reverse engineering, and cyber threats.
-Demonstrates curiosity and a strong desire to continuously expand technical knowledge and expertise.

Communication & Documentation

-Good writing skills and ability to create clear and understandable documentation.
-Able to document existing and newly developed tooling in a structured and maintainable manner.
-Able to communicate technical findings clearly and effectively.
-Shares knowledge and collaborates effectively with colleagues.

Continuous Improvement

- Continuously seeks opportunities to improve tooling, services, and analysis workflows.
- Thinks before acting and takes ownership of deliverables and outcomes.
- Strives for cutting-edge solutions and continuous technical excellence
- Actively contributes to improving ThreatFabric's threat intelligence extraction capabilities.

Information Security, Business Continuity & Privacy

- Adheres to company security, continuity, and privacy standards.
- Acts as a role model in secure research practices and data compliance.
- Proactively reports and supports resolution of security incidents.

Why us?

Protecting people, not just systems

At ThreatFabric, your work has a direct impact on the lives of millions of people. Every day, fraudsters, scammers, and cybercriminals target individuals and financial institutions around the world. The technology we build helps stop these attacks before they cause harm, protecting not only money, but also trust, confidence, and peace of mind.

Unlike many technology companies, the problems we solve are real, complex, and constantly evolving. You'll work on challenges that make a measurable difference and see your contributions translated into solutions used by some of the world's leading financial institutions.

Work alongside experts who love what they do

ThreatFabric brings together security researchers, engineers, data scientists, threat intelligence specialists, and fraud experts from around the globe. We're passionate about our craft and continuously challenge each other to think differently, improve our solutions, and stay ahead of emerging threats.

Learning is part of our DNA. Whether through knowledge-sharing sessions, technical discussions, mentoring, or simply collaborating with highly experienced colleagues, you'll be surrounded by people who are eager to learn and equally eager to share their expertise.

Why people stay

People join ThreatFabric because they're excited by the technology and the mission. They stay because of the people. We celebrate successes together, learn from challenges together, and create an environment where talented individuals can do the best work of their careers while enjoying the journey along the way.

Get in touch!

Interested?

Looking for your next challenge? We'd love to hear your story. Apply through the Personio link below and we'll be in touch shortly. Whether you're ready to make a move or simply want to explore the opportunity further, we're happy to answer your questions and help you determine if ThreatFabric is the right fit for you.

What's next?

So, you've hit send - what happens now? First, we'll do a screening to ensure we're a good match. If all goes well, you'll be invited for an initial chat with us. Then, there's a second interview, and we may include an assessment to better understand your skills and approach to threat research. Ready to take the plunge?

Please note: Pre-employment screening is part of our selection process. We do not accept unsolicited resumes from recruiters or employment agencies.