Sr. Security Researcher (remote)

CrowdStrike CrowdStrike · Enterprise · United States · Remote

CrowdStrike is seeking a Sr. Security Researcher to analyze in-the-wild exploits for vulnerabilities. This role involves implementing tracking systems, improving detection capabilities, identifying new data sources, reverse engineering exploits, developing automation tools for analysis, creating classification frameworks for attribution, and contributing to mitigation efforts. The role also includes producing threat intelligence reports, collaborating across teams, and briefing customers. The position requires proficiency in exploitation techniques, understanding of operating systems and network services, strong reverse engineering skills, and Python programming. Experience leveraging LLMs and AI-assisted tools for research and analysis is mandatory, as is the ability to validate technical findings independently. The role is focused on defensive security research within an AI-driven cybersecurity platform.

What you'd actually do

  1. Implement tracking systems that inform cross-team adversary tracking efforts based on observed exploitation behavior.
  2. Improve and maintain capabilities for detecting exploits, malicious payloads and other potential attack vectors using existing data sources.
  3. Identify opportunities for increasing the visibility of threats, specifically exploits, using new data sources.
  4. Maintain a detailed understanding of the inner functioning of relevant exploits through reverse engineering.
  5. Develop tools to assist with the automation of exploit analysis tasks by extending static and dynamic analysis frameworks.

Skills

Required

  • Proficiency in exploitation techniques that are commonly seen in exploits for userspace and kernel-level vulnerabilities.
  • Knowledge of common network service exploitation techniques.
  • Solid understanding of at least two operating system platforms, including Microsoft Windows.
  • Familiarity with standard web-based exploitation vectors.
  • Collaborative mindset, strong team player who enables others.
  • Profound knowledge of reverse engineering tools (disassemblers, decompilers, debuggers) and processes (unpacking malware, reconstructing code logic, etc).
  • Knowledge of programming and scripting languages, in particular Python.
  • Ability to effectively leverage Large Language Models (LLMs) and AI-assisted tools to accelerate vulnerability research, and exploit analysis while independently validating technical findings.
  • Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.
  • Ability to express complex technical and non-technical concepts in verbal and graphical products.
  • Excellent writing skills are mandatory.

Nice to have

  • Experience in attribution and intelligence analysis is a plus.
  • A background in intelligence writing is a plus.
  • Experience in writing Snort and YARA signatures is a plus.

What the JD emphasized

  • independent validation of technical findings
  • Ability to effectively leverage Large Language Models (LLMs) and AI-assisted tools to accelerate vulnerability research, and exploit analysis while independently validating technical findings.
  • Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.

Other signals

  • AI-native platform
  • AI-first mindset
  • responsible AI adoption
  • experimentation
  • innovation
  • AI-assisted tools
  • LLMs