Threat Analyst Ii, Ai/ml Operations (remote, Esp)

CrowdStrike CrowdStrike · Enterprise · Spain · Remote

This role focuses on analyzing adversary intrusions and creating/modifying security detections, with a secondary responsibility of addressing customer requests regarding the efficacy of machine learning detection models. It involves reviewing ML-based product detections, handling false positive/negative reports, and analyzing binary files. Experience with machine learning concepts is a plus.

What you'd actually do

  1. Review current ML-based product detections to ensure they are performing to the company standard
  2. Review customer-based reports of false positives and false negatives
  3. Review adversary intrusions and create ML-based security detections as needed
  4. Analyze binary files to determine their legitimacy

Skills

Required

  • Exposure and understanding of different types and functionality of malware
  • Experience with reverse engineering malware, detection engineering, or threat hunting
  • Knowledge of programming and scripting languages, in particular Python
  • Fundamental understanding of attributes of binary files such as imports/exports and packers
  • Ability to demonstrate practical knowledge of research/collection skills and analytical methods
  • A creative approach to problem solving and closing detection gaps
  • An excellent understanding of at least one major operating system type,or a public cloud provider
  • Ability to break down complex problems into workable components

Nice to have

  • Experience in a security operations center, incident response, blue teaming, or similar
  • A thorough understanding of Windows OS internals and the Windows API
  • Familiarity with tools used in targeted and criminal cyber-intrusions
  • A background in exploit and vulnerability analysis, or read teaming
  • Knowledge of a variety of programming languages including C, C++, Java, and assembly
  • Intimate knowledge of public cloud infrastructure
  • Experience with machine learning, data science, or data science concepts
  • Familiarity with CrowdStrike product and services

What the JD emphasized

  • ML-based product detections
  • customer-based reports of false positives and false negatives
  • create ML-based security detections