Sr. Intelligence Analyst - Dprk Mission (remote)

CrowdStrike CrowdStrike · Enterprise · United States · Remote

CrowdStrike is seeking a Senior Intelligence Analyst to track and analyze cyber operations associated with DPRK-nexus adversaries. The role involves monitoring cyber operations, identifying trends, investigating adversary activity, and producing intelligence assessments. Responsibilities include analyzing telemetry and open-source data, authoring reports, engaging in team discussions, identifying intelligence gaps, conducting peer reviews, and responding to customer requests. The analyst will also track DPRK financial operations, develop technical infrastructure tracking, and contribute to team knowledge transfer. A strong understanding of geopolitical issues specific to the DPRK and proficiency with threat intelligence research tools are required.

What you'd actually do

  1. Track adversary campaigns, tactics, techniques, and procedures (TTPs) through analysis of CrowdStrike's unique telemetry, open-source data sets, and third-party intelligence
  2. Author high-quality short and long format written reports independently that apply analytic tradecraft, including appropriate use of estimative language, confidence levels, and structured analytic techniques
  3. Generate reporting from a range of sources with minimal factual or accuracy errors and strong style, in line with CrowdStrike Intelligence standards
  4. Actively engage with inter-team discussions, including participation and leadership of groups in which you are the subject matter expert
  5. Identify intelligence gaps and propose research projects to address collection shortfalls, proactively seeking opportunities to collaborate on products with other teams

Skills

Required

  • 3+ years' experience in a threat intelligence environment
  • Expertise in DPRK cyber operations
  • Advanced knowledge of threat intelligence research/collection tools
  • Analytical tradecraft methods
  • Ability to identify, organize, catalog, and track adversary tradecraft trends
  • Ability to produce high-quality finished intelligence products
  • Strong understanding of technical concepts related to cyber threat research
  • Ability to conduct technical analysis of threat actor tools and infrastructure
  • Proficiency with infrastructure tracking tools (e.g., Censys, VirusTotal, DomainTools, Netflow)
  • Experience coordinating research projects and written products
  • Strong understanding and application of adversary attribution concepts
  • Excellent knowledge of geopolitical issues specific to the DPRK
  • Self-driven research and awareness of the state of the field

Nice to have

  • Leadership of groups
  • Mentorship of junior analysts
  • Contribution to automation tools within existing frameworks
  • Customer engagements and requests
  • Briefings for various customer levels
  • Peer review of reporting
  • Collaboration on products with other teams

What the JD emphasized

  • demonstrated expertise in DPRK cyber operations
  • Advanced knowledge of threat intelligence research/collection tools and analytical tradecraft methods
  • Demonstrated ability to identify, organize, catalog, and track adversary tradecraft trends — often with incomplete data
  • Proven ability to produce a consistent stream of high-quality finished intelligence products on short deadlines independently, as well as maintaining analysis for long-term strategic assessments
  • Ability to conduct technical analysis of the tools and tradecraft employed by threat actors, as well as to enumerate and monitor threat actors' infrastructure
  • Demonstrated proficiency with infrastructure tracking tools (e.g., Censys, VirusTotal, DomainTools, Netflow, or equivalent) and ability to document methodology, pivot logic, and findings in a format that enables team-level knowledge transfer
  • Strong understanding and application of adversary attribution concepts and ability to present attribution points in complex cases and work with other SMEs to gain consensus
  • Excellent knowledge of geopolitical issues specific to the DPRK (including North Korean strategic objectives, Korean Peninsula security dynamics, regional politics, and the DPRK's use of cyber operations for revenue generation and sanctions evasion) and ability to use that information to support understanding of current and future impacts on the cyber threat landscape