Senior Security Researcher, TAC Cloud
Location
Germany
Posted
38 days ago
Salary
0
Seniority
Senior
Job Description
Senior Security Researcher, TAC Cloud
CrowdStrike
• Technical Analysis: Reconstruct, investigate, and track cloud intrusions leveraging cloud service provider activity logs (AWS CloudTrail, Azure Activity Logs) and document findings • Enhance understanding of observed cloud activity by reproducing the activity in a test cloud environment • Create tools to automate analysis tasks and tracking of threat actors • Write cloud-activity-based (KQL, Amazon Athena), host-based (Yara) and network-based (Snort/Suricata) signatures suited for large-scale hunting, detection, and tracking of threats • Perform a technical analysis and reverse engineering of tools related to threat activity within the cloud environment or as part of cloud-conscious intrusions • Intelligence Reporting: Produce high-quality, actionable intelligence reporting • Collaborate with our interdisciplinary team to coordinate adversary and campaign tracking, and to provide support to teams developing mitigation strategies and responding to incidents
Job Requirements
- Understanding of cloud security concepts in particular identity and access management (IAM)
- Ability to reconstruct incidents based on cloud activity logs from at least one major cloud service provider (AWS, Azure, or GCP)
- Ability to express complex technical and non-technical concepts in written, verbal and graphical products for all levels of readership, including actionable mitigation and detection guidance
- Knowledge of programming and scripting languages, in particular Python
- Knowledge of reverse engineering tools (disassemblers, decompilers, debuggers) and processes (unpacking malware, reconstructing code logic, etc)
- Ability to identify and classify malicious tooling through development of signatures that can be used for tracking and hunting purposes
- Ability to interpret raw network data and to develop network signatures, as well as custom protocol decoders and decryption tools
- Be a team player
- Bonus Points: Experience developing detections with KQL and Amazon Athena
- Proven track record of relevant experience in the cloud security field
- A background in intelligence is a plus
- Relevant cloud certifications are a plus
Benefits
- Market leader in compensation and equity awards
- Comprehensive physical and mental wellness programs
- Competitive vacation and holidays for recharge
- Paid parental and adoption leaves
- Professional development opportunities for all employees regardless of level or role
- Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections
- Vibrant office culture with world class amenities
- Great Place to Work Certified™ across the globe
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Develop, update, and test cloud security policies (Azure) • Create and maintain CI/CD pipelines for deploying policies to cloud environments • Translate Information Security policies into technical controls in Azure • Implement preventive and detective controls to mitigate cyber risks • Work with Infrastructure as Code (IaC) to standardize environments • Ensure security integration in pipelines (DevSecOps) • Manage secrets, tokens, and certificates using secure mechanisms (e.g., Key Vault) • Work with access control (RBAC) and identity governance • Perform troubleshooting of critical and high-visibility issues • Collaborate with global, cross-functional teams • Participate in change management processes and CMDB
• Provide personalized support by addressing learner questions related to course content and projects. • Prior to the call mentors are expected to review the students' previous project submission(s) - provided by the Mentor Success Team when available - and/or any specific areas of the Nanodegree content or project that the student has expressed confusion or difficulty with. • For concept deep-dives, mentors will come prepared with a slide presentation that reviews a Nanodegree concept in more detail, share different use-cases for the concept to broaden student perspectives and understanding, and hold a Q&A session with the learners. • For project walkthroughs, a mentor will come prepared with a slide presentation that outlines each element of the rubric to help learners understand expectations and typical problem areas they may encounter. This can include a mentor “grading” a sample submission to demonstrate what mentors are looking for when reviewing projects. • Host regular sessions (via Slack or video) to address learner queries related to projects and coursework. No prior preparation required.
Cybersecurity Researcher, Threat Analysis and Detection Engineering
AcronisNatively integrated, highly efficient cyber protection.
• Research adversary tactics, techniques, and procedures (TTPs) and translate them into detection and prevention capabilities for Acronis Security and EDR products • Analyze malicious and benign content — executables, scripts, documents, memory dumps, network traffic, exploit chains — to identify indicators and behavioral patterns • Develop, tune, and maintain detection logic, signatures, and behavioral rules across multiple expression languages and rule formats • Monitor and improve automated detection pipelines to maintain high efficacy and low false-positive rates • Track emerging threats through open-source intelligence, telemetry analysis, and threat feeds to ensure coverage keeps pace with the landscape • Collaborate with scan engine and product engineering teams on joint research projects and new security features • Publish original research through blog posts, whitepapers, and conference presentations
• Implement, maintain, and improve security controls across AWS environments. • Support secure configuration of IAM, logging, monitoring, networking, and cloud services. • Operate and improve vulnerability management processes across infrastructure, applications, containers, and dependencies. • Triage security findings, assign ownership, track remediation, and drive closure with engineering teams. • Support SAST, SCA, DAST, SBOM, and container security workflows using tools such as Snyk and AWS-native services. • Help integrate security checks into CI/CD pipelines and development workflows. • Track remediation of penetration testing findings and validate closure of high-priority issues. • Support NIST 800-171 control implementation, evidence collection, and audit readiness activities. • Maintain accurate documentation of security controls, risks, exceptions, and remediation progress. • Support enterprise-grade security monitoring and incident response by leveraging centralized logging, alerting, and detection capabilities to identify, investigate, and respond to security events across the environment. • Assist with security monitoring, alert triage, investigation, and incident response activities. • Partner with Engineering, Platform, and IT teams to improve security processes without creating unnecessary friction. • Contribute to repeatable DevSecOps practices across teams.




