CrowdStrike logo
CrowdStrike

CrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?

Sr. Threat Researcher (Remote, IND)

Threat Intelligence SpecialistSecurity AnalystFull TimeRemoteSeniorTeam 5,001-10,000Since 2011H1B SponsorCompany SiteLinkedIn

Location

India

Posted

102 days ago

Salary

0

Seniority

Senior

Job Description

Sr. Threat Researcher (Remote, IND)

CrowdStrike

As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We’re also a mission-driven company. We cultivate a culture that gives every CrowdStriker both the flexibility and autonomy to own their careers. We’re always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you. About the Role: As a Senior Threat Researcher, you will be a technical leader and subject matter expert within the Threat Research team, driving innovation in threat detection and response capabilities. This is an individual contributor position focused on technical excellence and thought leadership, requiring deep expertise in reverse engineering, malware analysis, and automation. You will take ownership of the most complex threats facing CrowdStrike customers, architect scalable automation solutions, and serve as a technical mentor to researchers across all experience levels. Your work will directly influence the direction of threat research methodologies, tooling, and detection strategies that protect millions of endpoints worldwide. About the team: The CrowdStrike Malware Research Center is the core of Falcon's malware detection and response capabilities. The team has a focus on understanding the threat landscape and sets the target for what Falcon should be identifying and preventing. Additionally, the MRC is responsible for understanding our capabilities, and mapping how well our machine learning and behavioral protection capabilities are doing against those threats. Where there is a gap, the MRC takes action to improve our detection stance, and improve our overall protection story. MRC also performs pathfinding research to enable technology development using innovation, prototyping and bleeding edge machine learning to support our flagship Falcon product. There are many parts of CrowdStrike working towards protecting customer environments, and the MRC works across all of them to ensure we are on target and providing the best protection for our current Threat landscape. Leading the charge for understanding the activity of malware today is the Threat Research team. With a focus on malware research, the primary role of the team is to understand relevant threats and techniques used in malware that are threatening our customer's business. The challenge is the enormous scale of malware today and sheer number of samples required to be addressed. This takes a more creative approach than traditional Anti-Virus research, focusing on one sample at a time. The modern threat lab requires an economy of scale through automation and machine learning to allow people to focus on new learnings, and let systems continue to identify malware based on what the team has learned. What You'll Do: - Take ownership of critical technical initiatives and architect scalable automation solutions for malware analysis at scale - Serve as a technical mentor to researchers across all experience levels, helping to elevate team capabilities through knowledge sharing and technical guidance - Work independently on the most challenging and complex threats, performing deep reverse engineering and analysis - Collaborate cross-functionally with Engineering, Product, and Detection teams to translate research findings into production capabilities - Design proof-of-concept automation solutions and effectively hand off to engineering teams for production implementation - Directly influence the direction of threat research methodologies, tooling, and detection strategies across the organization - Drive technical excellence and thought leadership within the team, setting standards for analysis quality and automation practices - Build and optimize scalable automation pipelines, including integration with sandbox environments, YARA rule generation, and threat intelligence platforms - Produce high-quality technical documentation and reports that effectively communicate complex technical concepts to diverse audiences What You'll Need: - Bachelor's or Master's degree in Computer Science or comparable field - 12+ years of experience in the threat research field with a focus on malware analysis and reverse engineering - Strong reverse engineering skills on file-based threats, with demonstrated ability to deliver high-quality, in-depth analysis - Solid proficiency in disassembly and deep understanding of structured programming, compiler behaviors, and binary analysis techniques. Experience with reverse engineering tools such as IDA Pro, Ghidra, Binary Ninja, x64Dbg, or similar platforms - Experience in using machine learning and artificial intelligence for static and dynamic threat detection, including understanding of ML pipelines and model deployment in production environments - Strong understanding of file formats for compiled code and scripted files, with ability to analyze and contribute to parsers and feature extraction tools - Proficiency in multiple programming languages such as Python, Go, Rust, C++, or similar, with demonstrated ability to build production-quality automation tools and systems - Deep familiarity with multiple major Operating Systems (Windows, Linux, Mac), with in-depth knowledge of OS internals, kernel behaviors, and how host systems function at a technical level - Experience working with large data sets using tools like Splunk, ElasticSearch-Kibana, or similar platforms, along with knowledge of relational (MySQL, PostgreSQL) and non-relational/NoSQL databases (MongoDB, Cassandra, ElasticSearch) - Experience in building scalable automation pipelines for malware analysis, including integration with sandbox environments, YARA rule generation, and threat intelligence platforms - Deep working knowledge of malware-based automation workflows and techniques, with demonstrated ability to architect end-to-end automation solutions - Strong understanding of MITRE ATT&CK framework to describe and categorize threat behaviors - Strong technical communication and writing skills with ability to articulate complex technical concepts clearly and concisely to both technical and non-technical audiences - Track record of mentoring and providing technical guidance to researchers at all levels - Ability to influence technical direction and research strategy through deep expertise and thought leadership Bonus Points: - Experience leveraging Generative AI and Large Language Models for threat research automation workflows, including malware analysis, report generation, and threat intelligence synthesis - Proven ability to design and implement AI-powered automation solutions that enhance team productivity and scale threat research capabilities - Understanding of prompt engineering, AI model integration, and the application of GenAI tools in cybersecurity contexts - Proficiency in data visualization and statistical analysis techniques for threat intelligence and research insights - Additional reverse engineering expertise around file-less threats, exploits, rootkits, and advanced attack techniques - Experience working with certification partners like AV-Test, AV-Comparatives, SE Labs LI-VJ1 LI-Remote Benefits of Working at CrowdStrike: - Market leader in compensation and equity awards - Comprehensive physical and mental wellness programs - Competitive vacation and holidays for recharge - Paid parental and adoption leaves - Professional development opportunities for all employees regardless of level or role - Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections - Vibrant office culture with world class amenities - Great Place to Work Certified™ across the globe CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program. CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions--including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs--on valid job requirements. If you need assistance accessing or reviewing the information on this website or need help submitting an application for employment or requesting an accommodation, please contact us at recruiting@crowdstrike.com for further assistance.

Related Job Pages

More Threat Intelligence Specialist Jobs

SMI Aware logo

Open Source Intelligence Analyst

SMI Aware

We discover, collect, analyze, and preserve social media and open-source data.

Full TimeRemoteTeam 11-50Since 2011H1B No Sponsor

• Creates reports using SMI Aware's proprietary software application and other web based tools • Searching social media • Conducting advanced search engine queries • Filtering results • Writing an analytical summary of findings

Pennsylvania
$45K / year
Job Closed
RiskProfiler Inc logo

Threat Intelligence Research Intern

RiskProfiler Inc

RiskProfiler focuses on identifying and analyzing shadow risks in cybersecurity, leveraging advanced AI technology to provide comprehensive risk assessments. Our innovative approach equips clients with a deep understanding of their risks and their origins, significantly enhancing their cybersecurity defenses.

Full TimeRemoteTeam 51-200

This is a remote position. A Threat Intelligence Research Intern is a temporary position, typically designed for students or recent graduates seeking hands-on experience in the field of threat intelligence research. The intern will collaborate with a team of experienced professionals and researchers to investigate and analyze emerging cybersecurity threats, vulnerabilities, and trends. This role provides valuable exposure to cutting-edge security technologies and methodologies in a rapidly evolving field. Key Responsibilities: • Conduct research on emerging threats, vulnerabilities, and cybersecurity trends. • Analyze and interpret data and research findings related to threat intelligence. • Collaborate with team members to develop innovative threat intelligence technologies and solutions. • Support threat intelligence incident response and forensic investigations. • Stay current on new technologies and best practices in the threat intelligence field. Requirements To succeed in this role, the candidate should possess: • A strong foundation in computer science, cybersecurity, or a related field. • Excellent analytical and research skills with a detail-oriented mindset. • Good communication and problem-solving skills. • Ability to work effectively in a team environment. • Adaptability to new technologies, tools, and processes in threat intelligence. Preferred Qualifications: • Experience or coursework in cybersecurity, threat intelligence, or related fields. • Familiarity with security frameworks, tools, and methodologies. • Passion and curiosity for understanding emerging cybersecurity threats and vulnerabilities.

India
Full TimeRemoteTeam 10,001+Since 1931H1B Sponsor

At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection. Job Description We are seeking an experienced Senior Threat Hunter to perform, intelligence-driven network defense supporting the monitoring and incident response capabilities and advise governance, technical, and business leadership on results, vulnerabilities, and solutions to mitigate. The role will involve analysis of large amounts of data from vendors and internal sources, including various indicator feeds, SIEM, and several threat intelligence tools, etc. This individual will perform the functions of threat operations and hunting and serve as a liaison for Threat Services for the Cyber Operations organization, and mentor the incident handling, incident response, and forensics teams. Key Responsibilities - Design and run custom analysis models on security event information to discover active threats. - Identify (hunting) security nuances and abnormalities in the environment. - Develop use cases and actionable content to identify security issues that are currently not alerted within the environment. - Lead projects and assignments - Provide custom tool design to assist in analysis and investigations. - Perform as an Information Security resource in three or more of the following areas: - Threat Intelligence - Incident Response - Log analysis (statistical modeling, correlation, pattern recognition, etc.) - Microsoft platform (Server, workstation, applications) - Open Systems platforms (Linux, UNIX, VMWare ESX, Nutanix) - Web Application - Networking (firewalls, IDS/IPS, packet capture) - Databases (Oracle, SQL Server, DB2, IMS) - SIEM - Reverse Engineering / Malware analysis - Collaborate and support teammates and outside teams with regard to threat hunting techniques/issues. - Communication/build rapport with other divisions and various peers - Identify needs, drive solutions, and provide guidance in an autonomous manner. - Automate repetitive tasks via scripting in languages such as Python, PowerShell, Bash as business needs require. Job Qualifications - 5+ years overall technical experience in threat hunting, threat intelligence, incident response, security operations, or related information security field - Demonstrable work experience automating repetitive tasks via scripting in languages such as Python, PowerShell, Bash. - 2+ years’ experience in penetration testing, ethical hacking, exploit writing, and/or vulnerability management - Bachelor's and/or Master’s Degree in IT Security, Engineering, Computers Science, or related field/experience - Deep understanding of common network and application stack protocols, including but not limited to TCP/IP, SMTP, DNS, TLS, XML, HTTP, etc. - Advanced experience with security operations tools, including but not limited to: - SIEM (e.g., Splunk, ArcSight) - Network analysis (e.g., Net Witness, Palo Alto) - Signature development/management (e.g., Spunk rules, Snort rules, Yara rules) - EDR solutions (e.g., CrowdStrike, Tanium, Defender) - Broad experience with various common security infrastructure tools (NIDS, HIPS, EDR, etc. - Excellent analytical and problem-solving skills, a passion for research and puzzle-solving - Strong communication (oral, written, presentation), interpersonal and consultative skills - Leadership and mentorship skills Additional Desirable Criteria - Experience hunting in AWS and/or Azure environments - Deep understanding of large, complex corporate network environments - Strong knowledge or experience in penetration testing, ethical hacking, exploit writing, and/or vulnerability management - Knowledge or experience in application design/engineering, including but not limited to Windows/Linux system administration, RDBMS/NoSQL database administration, etc. - Recent experience with malware analysis and reverse engineering - Obtained certifications in several of the following: SANS GIAC courses, CEH, CISSP, OSCP, or tool-specific certifications Skills Cyber Incident Response, Cybersecurity Operations, Cyber Threat Hunting, Cyber Threat Intelligence, Cyber Threat Modeling, Endpoint Detection and Response (EDR), IT Problem Solving, IT Security Operations, Penetration Testing, Scripting, Security Incident Response, Security Information and Event Management (SIEM), Stakeholder Management Compensation Compensation offered for this role is 100,000.00 - 170,500.00 annually and is based on experience and qualifications. The candidate(s) offered this position will be required to submit to a background investigation. Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact. Allstate generally does not sponsor individuals for employment-based visas for this position. Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component. For jobs in San Francisco, please click “here” for information regarding the San Francisco Fair Chance Ordinance. For jobs in Los Angeles, please click “here” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance. To view the “EEO Know Your Rights” poster click “here”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs. To view the FMLA poster, click “here”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint. It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.

United States
$100K - $170K / year
Full TimeRemoteTeam 51-200H1B No Sponsor

About Our Internship Program Our summer internship program offers emerging cybersecurity professionals a unique opportunity to gain hands-on experience in threat hunting. As a Threat Hunting intern, you’ll be fully embedded within a team for 12 weeks, working alongside experienced hunters on actual investigations, learning the craft from the inside, and building skills that directly reflect what the industry demands. What We Offer • Customized Experience: We match qualified interns with projects and teams based on their interests and skill sets • Real-World Hunts: Contribute meaningfully to live threat hunting operations, not simulated exercises • Dedicated Mentorship: Receive one-on-one guidance from experienced senior threat hunters • Full Team Integration: Experience what it is truly like to work in a mature security team by becoming a valued contributor from day one The Role You will be joining a threat hunting team focused on hypothesis-driven detection of adversary activity across client environments. The team’s mission is to surface what automated tools miss: the subtle, low-and-slow behaviors that signal a determined attacker. As an intern, you will support senior hunters across every phase of the hunt lifecycle, learning by doing and contributing real work to ongoing investigations. As a Threat Hunting Intern, you’ll: • Support senior threat hunters in executing structured hunt missions from initial hypothesis through to final reporting, participating in every phase of the process • Conduct searches and queries across SIEM and EDR platforms to surface anomalous behaviors and gather evidence to validate or refute active hunt hypotheses • Assist in organizing and maintaining hunt hypothesis logs, tracking the reasoning behind each hypothesis, the data sources queried, and the outcomes as hunts progress • Validate hunt results by cross-referencing detections against environmental baselines, threat intelligence, and known-good behavior, distinguishing true positives from noise and documenting your reasoning clearly • Contribute to the drafting of final hunt reports, helping to summarize methodology, findings, and recommendations in a format suitable for both technical team members and non-technical readers • Communicate the results of completed hunts internally, presenting findings in written summaries, team updates, or channel posts with appropriate technical clarity • Assist senior hunters in refining and testing detection queries, helping to identify edge cases, validate logic against real data, and suggest improvements based on observed patterns • Support triage and contextualization of security findings that surface during hunt operations, helping to prioritize and document what matters • Contribute to team knowledge resources by helping document search patterns, field references, hunt playbooks, and lessons learned from completed hunts • Stay current on emerging threats and adversary techniques, bringing relevant threat intelligence into hypothesis discussions and helping connect external context to active hunt priorities Qualifications • Currently pursuing a degree in Cybersecurity, Computer Science, Information Systems, or a related field; or equivalent demonstrated experience through self-study, competitions, or independent work • Demonstrated interest in cybersecurity evidenced through personal projects, CTF participation, home labs, coursework, or active engagement with the security community • Foundational understanding of networking concepts including TCP/IP, DNS, and common protocols, with an ability to recognize when traffic or behavior looks out of place • Basic familiarity with Windows and/or Linux operating systems: understanding of processes, file systems, and logs at a level that supports security investigation • Some exposure to query languages such as KQL, SPL, SQL, or similar; comfort writing structured searches to filter and investigate data is a strong advantage • Awareness of attacker tactics, techniques, and procedures (TTPs) and familiarity with frameworks such as MITRE ATT&CK at a conceptual level • Strong written communication skills, as you will be contributing to internal findings summaries and hunt reports read by experienced practitioners • Detail-oriented and curious working style: the ability to follow evidence methodically, ask the next question, and challenge initial assumptions is central to this work • Comfortable working under the direction of senior team members, asking questions, communicating findings proactively, and flagging blockers early • Any prior exposure to security tooling such as a SIEM, EDR, or log analysis platform is a plus, but not required; we will teach you what you need Program Details Duration: 12 weeks Location: Remote Reports to: Senior Threat Hunter

United States