Use your browser's print dialog to save this as a PDF.

Krasimir Konov

Security Engineer · Malware Analyst · Threat Research

Sofia, Bulgaria · loading… · linkedin.com/in/krasimir-konov

Summary

Security engineer with 16 years in web security, including 9+ years at GoDaddy/Sucuri specializing in malware analysis and threat research. I reverse-engineer obfuscated PHP and JavaScript, build automated detection signatures (YARA, regex) deployed at scale across millions of websites, and publish original threat research — including work referenced in a peer-reviewed 2025 ACM SIGSAC (CCS) conference paper.

Fluent in English and Bulgarian. EU citizen, eligible to work anywhere in the EU without sponsorship.

Core Skills

Malware Analysis & Reverse Engineering · PHP / JavaScript Deobfuscation · YARA & Regex Signature Development · Threat Detection & Incident Response · Python · Amazon Web Services (AWS) & Lambda · CI/CD Automation (GitHub Actions) · AI-Assisted Detection Tooling · Linux Administration · Vulnerability Management · WordPress & Magento (CMS) Security · Technical Writing & Threat Reporting · MySQL / Apache · Mentoring & Team Leadership

Professional Experience

Security Engineer III

Sep 2024Present

GoDaddy / Sucuri — Remote

  • · Lead advanced threat detection, vulnerability management, and incident response for websites and infrastructure across GoDaddy's hosting portfolio.
  • · Personally resolve a high volume of malware-classification cases — the large majority requiring one or more original detection signatures.
  • · Reverse-engineer newly discovered malware samples and develop technical detection signatures (PHP, JavaScript, regex); among the most active contributors org-wide to the team's core detection codebase.
  • · Design and build CI/CD-style automation — GitHub workflows that trigger AWS Lambda functions to QA-test every new signature before it deploys across the scanner network.
  • · Train AI agents to draft signatures for straightforward malware, publish original threat research to the GoDaddy and Sucuri blogs, and mentor junior analysts on triage and signature development.

Security Engineer II

Jun 2024Sep 2024

GoDaddy / Sucuri — Remote

  • · Handled forensic investigation of escalated security incidents, tracing attack vectors through log data and building the mitigation steps to close them.
  • · Authored detection signatures in regex, PHP, and JavaScript; worked closely with engineering and incident-response counterparts to tighten classification processes ahead of moving into Engineer III three months later.

Technical Security II

Dec 2018Jun 2024

GoDaddy / Sucuri — Remote

  • · Decoded and analyzed malware samples submitted by the wider analyst team, correlating indicators and behavior to produce regex/PHP/JS signatures used to detect and remediate infections at scale.
  • · Investigated complex, novel infection chains — including fake plugins, PHP web shells, and JavaScript skimmers (Magecart-style) — and documented findings in published Labs Notes and blog posts.
  • · Built detection coverage that scaled cleanup across large volumes of compromised WordPress and Magento websites over five and a half years in the role.

Supervisor / Team Lead

Dec 2017Dec 2018

GoDaddy / Sucuri — Remote

  • · Led a team of security analysts handling malware investigation and remediation for client websites, reviewing case quality and clearing escalations to keep resolution times inside SLA.
  • · Ran team meetings and training, coordinated schedules, and served as the escalation point for the most complex or high-profile infections.

Security Analyst

Apr 2017Dec 2018

GoDaddy / Sucuri — Remote

  • · Investigated and remediated malware infections on compromised client websites, repairing the functional damage left behind and advising clients directly on hardening steps to prevent reinfection.

Security Analyst

Sep 2014Dec 2018

Sucuri Inc. (prior to GoDaddy acquisition)

  • · Cleaned malware from compromised websites, resolved the downstream damage, and flagged previously unseen threats to the wider team for deeper investigation and signature development.

Security Administrator

Sep 2011Aug 2014

HostGator — Houston, Texas

  • · Investigated malware and phishing attacks reported by hosting clients, tracing attack vectors through server and access logs.
  • · Monitored servers for spam abuse and worked directly with clients to guide remediation and blacklist removal.

Jr. Administrator

Sep 2010Sep 2011

HostGator — Houston, Texas

  • · Supported a global hosting customer base on DNS, domain, and CMS issues across concurrent phone and chat channels — the troubleshooting foundation for the security work that followed.

Selected Publications & Research

25 publications total, 2015–present — full list at konov.dev/research, or the archives at blog.sucuri.net/author/krasimir · labs.sucuri.net/author/krasimir-konov

Media & Speaking

Guest, Sucuri Sit-Down podcast, Episode 2 (2020) — discussed malware taxonomy and detection methodology.

Languages

Bulgarian (Native/Bilingual) · English (Native/Bilingual)