Use your browser's print dialog to save this as a PDF.
Krasimir Konov
Security Engineer · Malware Analyst · Threat Research
Sofia, Bulgaria · loading… · linkedin.com/in/krasimir-konov
Summary
Security engineer with 16 years in web security, including 9+ years at GoDaddy/Sucuri specializing in malware analysis and threat research. I reverse-engineer obfuscated PHP and JavaScript, build automated detection signatures (YARA, regex) deployed at scale across millions of websites, and publish original threat research — including work referenced in a peer-reviewed 2025 ACM SIGSAC (CCS) conference paper.
Fluent in English and Bulgarian. EU citizen, eligible to work anywhere in the EU without sponsorship.
Core Skills
Malware Analysis & Reverse Engineering · PHP / JavaScript Deobfuscation · YARA & Regex Signature Development · Threat Detection & Incident Response · Python · Amazon Web Services (AWS) & Lambda · CI/CD Automation (GitHub Actions) · AI-Assisted Detection Tooling · Linux Administration · Vulnerability Management · WordPress & Magento (CMS) Security · Technical Writing & Threat Reporting · MySQL / Apache · Mentoring & Team Leadership
Professional Experience
Security Engineer III
Sep 2024 – Present
GoDaddy / Sucuri — Remote
- · Lead advanced threat detection, vulnerability management, and incident response for websites and infrastructure across GoDaddy's hosting portfolio.
- · Personally resolve a high volume of malware-classification cases — the large majority requiring one or more original detection signatures.
- · Reverse-engineer newly discovered malware samples and develop technical detection signatures (PHP, JavaScript, regex); among the most active contributors org-wide to the team's core detection codebase.
- · Design and build CI/CD-style automation — GitHub workflows that trigger AWS Lambda functions to QA-test every new signature before it deploys across the scanner network.
- · Train AI agents to draft signatures for straightforward malware, publish original threat research to the GoDaddy and Sucuri blogs, and mentor junior analysts on triage and signature development.
Security Engineer II
Jun 2024 – Sep 2024
GoDaddy / Sucuri — Remote
- · Handled forensic investigation of escalated security incidents, tracing attack vectors through log data and building the mitigation steps to close them.
- · Authored detection signatures in regex, PHP, and JavaScript; worked closely with engineering and incident-response counterparts to tighten classification processes ahead of moving into Engineer III three months later.
Technical Security II
Dec 2018 – Jun 2024
GoDaddy / Sucuri — Remote
- · Decoded and analyzed malware samples submitted by the wider analyst team, correlating indicators and behavior to produce regex/PHP/JS signatures used to detect and remediate infections at scale.
- · Investigated complex, novel infection chains — including fake plugins, PHP web shells, and JavaScript skimmers (Magecart-style) — and documented findings in published Labs Notes and blog posts.
- · Built detection coverage that scaled cleanup across large volumes of compromised WordPress and Magento websites over five and a half years in the role.
Supervisor / Team Lead
Dec 2017 – Dec 2018
GoDaddy / Sucuri — Remote
- · Led a team of security analysts handling malware investigation and remediation for client websites, reviewing case quality and clearing escalations to keep resolution times inside SLA.
- · Ran team meetings and training, coordinated schedules, and served as the escalation point for the most complex or high-profile infections.
Security Analyst
Apr 2017 – Dec 2018
GoDaddy / Sucuri — Remote
- · Investigated and remediated malware infections on compromised client websites, repairing the functional damage left behind and advising clients directly on hardening steps to prevent reinfection.
Security Analyst
Sep 2014 – Dec 2018
Sucuri Inc. (prior to GoDaddy acquisition)
- · Cleaned malware from compromised websites, resolved the downstream damage, and flagged previously unseen threats to the wider team for deeper investigation and signature development.
Security Administrator
Sep 2011 – Aug 2014
HostGator — Houston, Texas
- · Investigated malware and phishing attacks reported by hosting clients, tracing attack vectors through server and access logs.
- · Monitored servers for spam abuse and worked directly with clients to guide remediation and blacklist removal.
Jr. Administrator
Sep 2010 – Sep 2011
HostGator — Houston, Texas
- · Supported a global hosting customer base on DNS, domain, and CMS issues across concurrent phone and chat channels — the troubleshooting foundation for the security work that followed.
Selected Publications & Research
- Massive WordPress JavaScript Injection Campaign Redirects to Ads (2022) — Sucuri Blog · Cited as a reference in a peer-reviewed paper at the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS).
- Malware Targeting WordPress Abuses Steam Community Profiles for Command & Control Operations (2026) — GoDaddy Resources
- Detecting & Mitigating a Phishing Threat: Greatness (2024) — Sucuri Blog
- Magento Credit Card Stealing Malware: gstaticapi (2020) — Sucuri Blog · Skimmer found on roughly 22% of infected Magento checkout pages at the time.
- From Privacy to Exfiltration: Telegram's Role in Website Malware (2024) — Sucuri Blog
- Shifting Malware Tactics & Stealthy Use of Non-Executable .txt & .log Files (2023) — Sucuri Blog
- Infected WordPress Site Reveals Malicious C&C Script (2022) — Sucuri Blog
- String Concatenation: Obfuscation Techniques (2020) — Sucuri Blog
25 publications total, 2015–present — full list at konov.dev/research, or the archives at blog.sucuri.net/author/krasimir · labs.sucuri.net/author/krasimir-konov
Media & Speaking
Guest, Sucuri Sit-Down podcast, Episode 2 (2020) — discussed malware taxonomy and detection methodology.
Languages
Bulgarian (Native/Bilingual) · English (Native/Bilingual)