Full-Time

Sr. Threat Researcher II

Confirmed live in the last 24 hours

Crowdstrike

Crowdstrike

10,001+ employees

Cloud-native endpoint security solutions provider

Compensation Overview

$155k - $255k/yr

+ Variable Compensation + Incentive Compensation + Equity

Expert

Company Historically Provides H1B Sponsorship

Remote in USA

US Top Secret Clearance Required

Category
Cybersecurity
IT & Security
Required Skills
AWS
Requirements
  • 10+ years’ experience in the threat research field with a focus on malware analysis with experience in cloud threat actor tradecraft
  • A proven background in reverse engineering and disassembly on file-based threats, exploits, and other attack techniques
  • Strong experience with AWS tradecraft, adversary use of Infrastructure as a Service (IaaS), Infrastructure as Code (IaC), or threat actor use of cloud Identity and Access Management (IAM)
  • Proficiency in disassembly and operating system internals
  • Expert level familiarity with at least one major Operating System is required as a behavior based system requires in-depth knowledge of how the host OS appears, as opposed to how the end user sees it
  • Knowledge of using MITRE ATT&CK to describe threat behaviors
  • Proficiency in at least one programming or scripting language
  • Demonstrated experience creating and handing off proof-of-concept research to engineering teams
  • Strong interpersonal communications skills, with the ability to demonstrate leadership and team building expertise.
Responsibilities
  • The Threat Analyst will take input from many sources and validate if those threats are something Falcon can mount an effective defense against.
  • The analysis can range from simple execution and review of the behaviors to reverse engineering.
  • The Threat Analyst will be expected to use the appropriate technique to efficiently understand the threat to identify how to best mitigate it.
  • This role will be looked on as the go to person when new threats are reported for understanding those threats and formulating an opinion on how we should be thinking about the threat.
  • Good cross team collaboration skills are important.
  • Clear, effective communication of technical details in a means which is actionable is the key to success.
  • Working with the engineering team to define automation improvements and process automation to reduce time and manual effort in the analysis of threats.
  • Prioritizing automation tasks and features will help define success of the role.
  • Being able to understand the bigger picture of threat analysis and convey that to the engineering team which may not be familiar with the process will be required.

CrowdStrike focuses on cybersecurity by providing cloud-native endpoint security solutions to protect businesses from cyber threats. Their main product, the Falcon platform, includes services like next-generation antivirus, endpoint detection and response, and device control to manage network access. The company serves a wide range of clients, including many Fortune 100 companies, and operates on a subscription-based model, offering various service levels and premium threat hunting services. CrowdStrike is recognized as a leader in the cybersecurity field for its effectiveness in threat detection and response.

Company Size

10,001+

Company Stage

IPO

Headquarters

Austin, Texas

Founded

2011

Simplify Jobs

Simplify's Take

What believers are saying

  • Partnership with NVIDIA enhances Falcon platform's AI capabilities, boosting threat detection.
  • Recognition as 2025 Google Cloud Workload Security Partner of the Year strengthens market credibility.
  • Integration with NTT DATA expands market reach and service offerings for CrowdStrike.

What critics are saying

  • Competitors like Microsoft advancing AI-powered security could challenge CrowdStrike's market position.
  • Google's acquisition poses direct competition to CrowdStrike's endpoint security solutions.
  • AI-driven attacks' increasing sophistication challenges CrowdStrike's ability to protect clients effectively.

What makes Crowdstrike unique

  • CrowdStrike's Falcon platform offers cloud-native endpoint security, setting it apart from competitors.
  • The company serves 44 of the Fortune 100, showcasing its strong market presence.
  • CrowdStrike's proactive threat hunting service adds a unique layer of cybersecurity protection.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Competitive Employee Stock Purchase Plan

Remote-friendly culture

Market leader in compensation and equity awards

Competitive vacation and flexible working arrangements

Comprehensive health benefits + 401k plan

Paid Parental Leave, including adoption

Wellness programs

Professional development and mentorship opportunities

Open offices have stocked kitchens, coffee, soda and treats

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

2%

2 year growth

0%
VentureBeat
Apr 14th, 2025
Amex Gbt Puts Ai At The Center Of Soc Automation, Threat Modeling, Incident Response

Join our daily and weekly newsletters for the latest updates and exclusive content on industry-leading AI coverage. Learn More. Balancing the paradox of protecting one of the world’s leading travel, software and services businesses against the accelerating threats of AI illustrates why CISOs need to be steps ahead of the latest adversarial AI tradecraft and attack strategies.    As a leading global B2B travel platform, American Express Global Business Travel (Amex GBT) and its security team are doing just that, proactively confronting this challenge with a dual focus on cybersecurity innovation and governance. With deep roots in a bank holding company, Amex GBT upholds the highest data privacy standards, security compliance and risk management. This makes secure, scalable AI adoption a mission-critical priority.Amex GBT Chief Information Security Officer David Levin is leading this effort. He is building a cross-functional AI governance framework, embedding security into every phase of AI deployment and managing the rise of shadow AI without stifling innovation

Digital IT News
Apr 9th, 2025
CrowdStrike Wins 2025 Google Cloud Workload Security Partner of the Year

CrowdStrike wins 2025 Google Cloud Workload Security Partner of the Year.

The Finance Headline
Apr 3rd, 2025
CrowdStrike Appoints Alex Ionescu as Chief Technology Innovation Officer

CrowdStrike appoints Alex Ionescu as chief technology innovation officer.

The Motley Fool
Mar 27th, 2025
Did Google Just Say "Checkmate" to CrowdStrike?

Google's latest acquisition could be seen as a more direct way to compete with endpoint security and artificial intelligence (AI) specialist CrowdStrike.

VentureBeat
Mar 25th, 2025
From Alerts To Autonomy: How Leading Socs Use Ai Copilots To Fight Signal Overload And Staffing Shortfalls

Join our daily and weekly newsletters for the latest updates and exclusive content on industry-leading AI coverage. Learn More. Thanks to the rapid advances in AI-powered security copilots, security operations centers (SOCs) are seeing false positive rates drop by up to 70% while saving over 40 hours a week of manual triage.The latest generation of copilots has moved far beyond chat interfaces. These agentic AI systems are capable of real-time remediation, automated policy enforcement and integrated triage across cloud, endpoint and network domains. Purpose-built to integrate within SIEM, SOAR and XDR pipelines, they’re making solid contributions to improving SOC accuracy, efficiency and speed of response.Microsoft launched six new Security Copilot agents today—including ones for phishing triage, insider risk, conditional access, vulnerability remediation, and threat intelligence—alongside five partner-built agents, as detailed in Vasu Jakkal’s blog post.Quantifiable gains in SOC performance are growing. Mean-time-to-restore is improving by 20% or more, and threat detection times have dropped by at least 30% in SOCs deploying these technologies