Security Researcher
McAfee
The Allowlisting Research team focuses on identifying and validating legitimate software to improve detection accuracy and minimize false positives. Researchers analyze file characteristics, software behavior, publisher reputation, digital signatures, and software provenance to determine whether file and cert can be safely allowlisted. The role combines static analysis, behavioral analysis, reputation intelligence, and technical investigation to support evidence-based trust decisions. Automated tools and threat intelligence provide supporting context, but final decisions rely on researcher expertise and technical judgment. This position is ideal for an experienced security researcher who can independently evaluate unfamiliar software and make accurate allowlisting decisions.
This is a Hybrid position located at our Bangalore, India development center. You will be required to be on-site 2 to 3 days per week. When you are not working on-site, you will be working from your home office. We are only considering candidates within a commutable distance to our Bangalore office and are not offering relocation assistance at this time.
Position Details
About The Role
- Perform hands-on file analysis and classify samples as clean, suspicious, PUP, or malicious using defensible technical evidence.
- Independently manage files from initial triage through static and behavioral analysis, debugging, unpacking, reverse engineering, and final verdict.
- Analyze Windows executables, file formats, OS interactions, and potentially malicious behavior using manual investigation supported by automation and threat intelligence.
- Clearly document technical findings, classification rationale, and complex malware behavior for relevant stakeholders.
- Collaborate with security and detection teams, contribute to detection improvements, and take ownership of complex investigations.
- 2 to 4 years of strong hands-on experience in manual malware analysis, static and dynamic analysis, Windows internals, and PE/file-format analysis.
- Working knowledge of x86/x64 architecture, debugging, disassembly, unpacking, deobfuscation, and reverse engineering.
- Ability to independently investigate unfamiliar, packed, or obfuscated samples and reach evidence-based classification decisions.
- Knowledge of digital signatures, certificate and publisher validation, software provenance, and strong technical communication skills.
- Familiarity with Python or scripting, system-monitoring tools, sandbox environments, YARA, threat intelligence, and basic network analysis is an added advantage.
McAfee is a leader in personal security for consumers. Focused on protecting people, not just devices, McAfee consumer solutions adapt to users’ needs in an always online world, empowering them to live securely through integrated, intuitive solutions that protects their families and communities with the right security at the right moment.
Company Benefits And Perks
We work hard to embrace diversity and inclusion and encourage everyone at McAfee to bring their authentic selves to work every day. We’re proud to be Great Place to Work Certified in 10 countries, a reflection of the supportive, empowering environment we’ve built where people feel seen, valued, and energized to reach their full potential and thrive.
We offer a variety of social programs, flexible work hours and family-friendly benefits to all of our employees.
- Bonus Program
- Pension and Retirement Plans
- Medical, Dental, and Vision Coverage
- Paid Time Off
- Paid Parental Leave
- Support for Community Involvement
Job Applicant Privacy Notice
Please click here to view and download the Job Applicant Privacy Notice, which applies to all McAfee job applicants who are residents of the state of California.