CrowdStrike logo
CrowdStrike

CrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?

Senior Intelligence Analyst, GTAC Vulnerability Mission

Threat Intelligence SpecialistSecurity AnalystFull TimeRemoteSeniorTeam 5,001-10,000Since 2011H1B SponsorCompany SiteLinkedIn

Location

Germany

Posted

15 days ago

Salary

0

Seniority

Senior

Bachelor Degree2 yrs expEnglishLinuxMacOS

Job Description

Senior Intelligence Analyst, GTAC Vulnerability Mission

CrowdStrike

• Identify threats, trends, and new developments in vulnerabilities and exploit behavior by adversaries while synthesizing raw intelligence and data from numerous data sources • Identify and monitor the Tactics, Techniques, and Procedures (TTPs) employed by cyber threat actors that use exploits • Digest, analyze, model and structure data relationships to support the identification and description of malicious activities. • Apply understood analytic tradecraft to gathered intelligence in a consistent manner • Produce finished intelligence analysis to internal and external customers through written reporting of varied depth on short deadlines, with minimal supervision • Collaborate across teams to inform various functions within CrowdStrike about activity of interest and to coordinate adversary/campaign tracking • Develop tools, processes, and technology to support predictive analysis of adversaries and tactics based on vulnerabilities/exploits. • Identify intelligence gaps and submit requests for information to fill gaps • Conduct briefings as needed for a variety of levels of customers as requested (via either phone, video conference, webcast, in-person briefing, or industry conference)

Job Requirements

  • Minimum of 2-3 years’ experience in a threat intelligence environment
  • Motivated self-starter with experience in the cyber threat intelligence field, preferably with experience in researching and reporting on exploits and exploit behavior by adversaries
  • Ability to produce quality finished intelligence products on short deadlines, as well as continuing to maintain analysis for and report on long term strategic assessments
  • Knowledge of analytic tradecraft including the production of intelligence assessments
  • Basic knowledge of how vulnerabilities are discovered and exploits are developed, (e.g. understanding of common remote network exploitation and/or local privilege escalation techniques)
  • Ability to identify and track adversary tradecraft and trends for actors of all types
  • Experience with technical indicators from malware, logs, and/or PCAP through leveraging resources for analysis of infrastructure, samples, and link analysis.
  • Familiarity or aptitude to learn basic signature writing (e.g .YARA, Snort, Zeek etc.)
  • Knowledge of operating system fundamentals (e.g. Windows, Linux, macOS) and networking concepts
  • Desire to extend knowledge on intelligence tradecraft and technical terminology relevant to vulnerability intelligence, as well as provide assistance to other members of the intelligence team.
  • Previous experience as an All-Source intelligence analyst at a national level intelligence organization (bonus)
  • General understanding of network and host log analysis with a foundational knowledge of Incident Response (IR) processes and procedures (bonus)
  • Familiarity with EDR and SIEM solutions (bonus)
  • Experience using, developing, deploying and honeypots (bonus)

Benefits

  • Market leader in compensation and equity awards
  • Comprehensive physical and mental wellness programs
  • Competitive vacation and holidays for recharge
  • Paid parental and adoption leaves
  • Professional development opportunities for all employees regardless of level or role
  • Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections
  • Vibrant office culture with world class amenities
  • Great Place to Work Certified™ across the globe

Related Job Pages

More Threat Intelligence Specialist Jobs

Senior All Source Investigator

TRM Labs

TRM Labs specializes in blockchain investigations and risk management, empowering organizations to detect, investigate, and prevent crypto-related fraud and fin

Role Description The Scam Disruption team is TRM's tip of the spear against pig butchering syndicates, romance fraud networks, and investment scam operations that steal billions from victims each year. As an All-Source Investigator, you’ll lead targeting-driven investigative work: taking legal process to the ground, following the data wherever it leads, and delivering actionable intelligence to law enforcement partners. You will operate the "intelligence flywheel" daily — fusing on-chain and off-chain data to build operational pictures that help dismantle scam operations. The Impact You Will Have - Run legal process end-to-end against scam infrastructure and convert returns into targeting-ready intelligence for TRM’s teams and law enforcement partners. - Trace scam compounds geographically and operationally — combining on-chain attribution with off-chain telemetry, OSINT, and commercially available data to identify operators, controllers, and movement patterns. - Work the intelligence flywheel operationally — processing returns at high volume and feeding victim and operator data into TRM's intelligence and product pipelines. - Find the seams — pivot from a single victim into uncovering the operation and multiplying leads. - Partner with the Threat Intelligence Analyst (Scams Expert) and the All-Source Lead to translate disruption strategy into targeting packages that influence federal investigations. Qualifications - 5-8+ years of all-source investigative or targeting experience — federal law enforcement (former 1811s — e.g., FBI, HSI, IRS-CI, Secret Service), Intelligence Community all-source analysis, or mission-aligned private sector equivalent. - Legal process expertise — you have personally drafted and worked returns from US legal process and know how to operationalize the data. - Creative tactical thinking — demonstrated ability to pivot from a single point to a network view, identifying operators behind operations. - Link and pattern analysis fluency — ability to correlate disparate data sources to generate defensible target packages. - Strong written communication — skilled at writing memos, attribution write-ups, and federal-style leads that are actionable. - AI fluency (required) — you use AI tools in your workflow, synthesizing returns, drafting outputs, and accelerating analysis, with examples of how AI has impacted your work. - Crypto experience is a plus, not a requirement — we teach on-chain tradecraft; we cannot teach the targeter's instinct. - US Citizenship required. - Must be located in the US. Benefits - High autonomy, high standards, low bureaucracy — work directly with analysts, engineers, and customers who depend on your output. - Weekly team syncs to align targeting priorities and review disruption opportunities. - Daily async standups via Slack on active work, returns, and target packages in flight. - Surge availability expected during time-sensitive disruption windows. Company Description TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.

United States

Lead All Source Investigator

TRM Labs

TRM Labs specializes in blockchain investigations and risk management, empowering organizations to detect, investigate, and prevent crypto-related fraud and fin

Role Description The Scam Disruption team is TRM's tip of the spear against pig butchering syndicates, romance fraud networks, and investment scam operations that steal billions from victims every year. The Lead All Source Investigator owns the all-source targeting function inside the team — setting the tradecraft bar, building the operating model, mentoring a team of investigators, and personally working the highest-value targets. You are the senior operator who has run this work before, knows what "good" looks like, and is ready to build the foundation that makes the next several investigators effective from day one. The Impact You Will Have - Own the all-source targeting function for the Scam Disruption team — define the tradecraft, set the standards, and ensure every target package leaving the team is defensible, prioritized, and actionable. - Build and scale the team's operating model — design how legal process, data exploitation, and targeting flow end-to-end, and close the loop with engineering on tooling integration. - Mentor and direct a team of All-Source Investigators — set collection priorities, review work product, raise the bar on output quality, and create the player-coach culture that lets the team scale without losing rigor. - Personally work the most complex investigations — multi-jurisdiction compound targeting, controller-level attribution, and the cases no one else on the team can close. - Serve as the senior law-enforcement-facing interface — coordinate with federal partners on perishable leads, prosecutorial referrals, and joint disruption operations. - Partner with the Threat Intelligence Analyst (Scams Expert) as the operational counterpart — turn their strategic disruption frameworks into executed targeting campaigns the team runs at scale. Qualifications - 8+ years of all-source investigative or targeting experience — including time as a senior 1811 (e.g., FBI, HSI, IRS-CI, Secret Service), an Intelligence Community targeting officer, or a private-sector senior investigative lead working complex transnational targeting. - Demonstrated player-coach experience — you have led a team of investigators or targeters before, built workflows others followed, and can point to people you have grown. - Deep legal process expertise — you have built or run a legal-process program at scale and have the operational tradecraft to convert returns into targets. - Federal law-enforcement network — you have working relationships with cyber/crypto units across federal agencies and know how to package intelligence so it actually gets used. - Senior tactical thinking — you have designed the methodology, not just executed it; you can describe an operation where you reframed the problem (e.g., "stop targeting victims, target controllers") and changed team-level outcomes. - Strong written communication and executive presence — comfortable briefing federal partners, TRM leadership, and customer executives on disruption strategy and case outcomes. - AI fluency (required) — you have used AI to scale your team's work, not just your own; you can speak to specific workflows where AI has unlocked headcount-level productivity. - Crypto experience is preferred but not required — fluency in on-chain tradecraft is welcome; you must be willing and able to ramp on the crypto side quickly, working alongside our Threat Intel Scams Expert. Requirements - U.S. Citizenship. - Must be located in the United States. Benefits - High velocity, high ownership team that expects clarity, follow-through, and impact. - Work that often requires operating with a high degree of ambiguity. - A high level of personal ownership and accountability. - Close collaboration across teams and functions. - Frequent, high-touch communication. - Creative problem solving and out-of-the-box thinking. - A pace that rewards urgency, adaptability, and outcomes.

United States
Job Closed

All Source Investigator

TRM Labs

TRM Labs specializes in blockchain investigations and risk management, empowering organizations to detect, investigate, and prevent crypto-related fraud and fin

Role Description The Scam Disruption team is TRM's tip of the spear against pig butchering syndicates, romance fraud networks, and investment scam operations that steal billions from victims each year. As an All-Source Investigator, you’ll lead targeting-driven investigative work: - Run legal process end-to-end against scam infrastructure and convert returns into targeting-ready intelligence for TRM’s teams and law enforcement partners. - Trace scam compounds geographically and operationally — combining on-chain attribution with off-chain telemetry, OSINT, and commercially available data to identify operators, controllers, and movement patterns. - Work the intelligence flywheel operationally — processing returns at high volume and feeding victim and operator data into TRM's intelligence and product pipelines. - Find the seams — pivot from a single victim into uncovering the operation and multiplying leads. - Partner with the Threat Intelligence Analyst (Scams Expert) and the All-Source Lead to translate disruption strategy into targeting packages that influence federal investigations. Qualifications - 3 to 5 years of all-source investigative or targeting experience — federal law enforcement (former 1811s — e.g., FBI, HSI, IRS-CI, Secret Service), Intelligence Community all-source analysis, or mission-aligned private sector equivalent. - Legal process expertise — you have personally drafted and worked returns from US legal process and know how to operationalize the data. - Creative tactical thinking — demonstrated ability to pivot from a single point to a network view, identifying operators behind operations. - Link and pattern analysis fluency — ability to correlate disparate data sources to generate defensible target packages. - Strong written communication — skilled at writing memos, attribution write-ups, and federal-style leads that are actionable. - AI fluency (required) — you use AI tools in your workflow, synthesizing returns, drafting outputs, and accelerating analysis, with examples of how AI has impacted your work. - Crypto experience is a plus, not a requirement — we teach on-chain tradecraft; we cannot teach the targeter's instinct. - US Citizenship required. - Must be located in the US. Benefits - High autonomy, high standards, low bureaucracy — work directly with analysts, engineers, and customers who depend on your output. - Weekly team syncs to align targeting priorities and review disruption opportunities. - Daily async standups via Slack on active work, returns, and target packages in flight. - Surge availability expected during time-sensitive disruption windows. Company Description TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.

United States

Malware Analyst

Accenture

Accenture Federal Services, a division of Accenture, provides technology and consulting services to U.S. federal agencies, delivering solutions that enhance performance and efficie

Role Description Buscamos un profesional motivado para unirse a nuestro equipo de Inteligencia de Amenazas Cibernéticas (CTI) en el área de Malware, apoyando el análisis e investigación de amenazas. Las responsabilidades principales serán: - Identificar, analizar y documentar aplicaciones maliciosas, principalmente en entornos Android. - Asistir en la detección y seguimiento de amenazas móviles. Qualifications - Conocimiento de sistemas Windows, Android y Linux. - Experiencia básica en análisis de malware para Android. - Uso de VirusTotal y otras herramientas como CAPE, Any.Run o Joe Sandbox. - Experiencia con herramientas como CyberChef, JADx, JD-GUI, JEB Decompiler, Android Studio y ADB. - Habilidades de programación en Python. - Conocimiento de ingeniería inversa y ensamblaje para diferentes arquitecturas. - Análisis avanzado de malware (empaquetadores, encriptadores, antidepuración, rootkits, bootkits...). - Experiencia con PeStudio, PEiD, LordPE, Depends, Exeinfo PE, PEframe, PE-Bear, bintext, DIE, Resource Hacker. - Experiencia con Frida, Sysinternals Suite, Process Hacker, Regshot, APIMonitor, Wireshark o Inetsim. - Experiencia con IDA Pro, Ghidra, x64dbg y Radare2. Company Description Accenture es una compañía líder mundial en servicios profesionales que ayuda a las principales empresas, administraciones públicas y otras organizaciones del mundo a desarrollar su core digital, optimizar sus operaciones, acelerar el crecimiento de sus ingresos y mejorar los servicios para los ciudadanos, creando valor tangible a velocidad y escala.

Spain