Sr. Security Researcher, Tac Tbna (remote)

CrowdStrike CrowdStrike · Enterprise · United Kingdom, Germany · Remote

This role focuses on researching nation-state adversary operations and targeted intrusions by performing malware reverse engineering, developing automation tools for analysis and tracking, and creating signatures for threat detection. The goal is to produce actionable intelligence reports and enhance understanding of malicious tools and malware.

What you'd actually do

  1. Discover, investigate and track advanced cyber intrusions and document findings.
  2. Enhance understanding of tools and malware through reverse engineering.
  3. Develop tools to automate analysis tasks and tracking of threat actors.
  4. Create host-based and network-based signatures suited for large-scale hunting, detection, and tracking of threats.
  5. Produce high-quality, actionable intelligence reporting.

Skills

Required

  • Knowledge of reverse engineering tools (disassemblers, decompilers, debuggers) and processes (unpacking malware, reconstructing code logic, etc).
  • Understanding of Windows OS internals.
  • Knowledge of programming and scripting languages, in particular Python.
  • Ability to identify and classify malicious tooling through development of signatures that can be used for tracking and hunting purposes.
  • Ability to express complex technical and non-technical concepts in written, verbal and graphical products.
  • Proven track record of relevant experience in the field cybersecurity
  • Be a team player

Nice to have

  • Ability to interpret raw network data and to develop network signatures, as well as custom protocol decoders and decryption tools.
  • Familiarity with targeted intrusions and tracking of state-operated adversaries.
  • A background in intelligence is a plus.

What the JD emphasized

  • seasoned specialist in targeted intrusions and tracking of nation state adversaries
  • rapidly expand their skills

Other signals

  • malware analysis
  • reverse engineering
  • automation systems
  • threat actor tracking
  • intelligence reporting