Crowdstrike

Security Researcher - Malware Reverse Engineer (Remote)

United States

Not SpecifiedCompensation
Senior (5 to 8 years), Expert & Leadership (9+ years)Experience Level
Full TimeJob Type
UnknownVisa
Cybersecurity, Information TechnologyIndustries

Job Description

Employment Type: Full time

Position Overview

CrowdStrike, a global leader in cybersecurity, protects the people, processes, and technologies that drive modern organizations. Since 2011, our mission has been to stop breaches, and we have redefined modern security with the world's most advanced AI-native platform. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe, and their lives moving forward. We are a mission-driven company that cultivates a culture of flexibility and autonomy, empowering every CrowdStriker to own their careers. We are always looking for talented individuals with limitless passion, a relentless focus on innovation, and a fanatical commitment to our customers, community, and each other. Ready to join a mission that matters? The future of cybersecurity starts with you.

About the Role

CrowdStrike Counter Adversary Operations is seeking a motivated malware reverse engineer with excellent technical skills to research advanced cybercriminal attacks. Our Technical Analysis Cell (TAC) is at the forefront of CrowdStrike’s mission against state-sponsored adversaries and criminal actors. We combine intelligence analysis with deep-dive reverse engineering and malicious code analysis, in addition to building and using automation systems to deliver actionable indicators and operational insights. CrowdStrike is uniquely positioned to leverage data from a multitude of sources, including our proprietary telemetry, our large internal malware corpus, and our custom-built analysis pipeline. We foster an environment of respectful, passionate camaraderie and collaboration between researchers who enjoy the fast-paced nature of our work.

This highly technical position on the TAC eCrime team plays an important role in conducting research, increasing our coverage of the global threat landscape, contributing to the continuous tracking of criminal adversary groups, and ultimately developing finished intelligence products that provide a decision advantage to customers.

We are ideally looking for a seasoned specialist in the tracking of eCrime actors, their tooling, and their TTPs. That said, we are also open to applications from experienced and talented malware researchers or reverse engineers without significant knowledge in this field who are willing to rapidly expand their skills to successfully carry out the essential duties of this role.

Responsibilities

Technical Analysis

  • Discover, investigate, and track advanced cyber intrusions and document findings.
  • Enhance understanding of tools and malware through reverse engineering.
  • Develop tools to automate analysis tasks and tracking of threat actors.
  • Create host-based and network-based signatures suited for large-scale hunting, detection, and tracking of threats.

Intelligence Reporting

  • Produce high-quality, actionable intelligence reporting.
  • Collaborate with our interdisciplinary team to coordinate adversary and campaign tracking, and to provide support to teams developing mitigation strategies and responding to incidents.

Requirements

Required

  • Effective collaborator and team player.
  • Knowledge of reverse engineering tools (disassemblers, decompilers, debuggers) and processes (unpacking malware, reconstructing code logic, etc.).
  • Understanding of Windows OS internals.
  • Knowledge of programming and scripting languages, in particular Python.
  • Ability to identify and classify malicious tooling through development of signatures that can be used for tracking and hunting purposes.
  • Ability to express complex technical and non-technical concepts in written, verbal, and graphical products.
  • Proven track record of relevant experience in the cybersecurity field.

Preferred

  • Ability to interpret raw network data and to develop network signatures, as well as custom protocol decoders and decryption tools.
  • Familiarity tracking botnets and commodity malware.
  • Experience tracking adversaries engaged in...

Skills

Malware Reverse Engineering
Cybersecurity
Intelligence Analysis
Reverse Engineering
Malicious Code Analysis
Automation Systems
Telemetry
Threat Landscape
eCrime

Crowdstrike

Cloud-native endpoint security solutions provider

About Crowdstrike

CrowdStrike specializes in cybersecurity, focusing on protecting businesses from cyber threats through cloud-native endpoint security solutions. Their main product, the Falcon platform, includes services like Falcon Pro, which replaces traditional antivirus with next-generation antivirus that integrates threat intelligence, Falcon Insight for endpoint detection and response, and Falcon Device Control to manage connected devices. Unlike many competitors, CrowdStrike's services are subscription-based, allowing clients to choose different levels of protection based on their needs. The company serves a diverse clientele, including many Fortune 100 companies, and is recognized as a leader in the cybersecurity field, known for its effectiveness in threat detection and response.

Austin, TexasHeadquarters
2011Year Founded
$468MTotal Funding
IPOCompany Stage
Enterprise Software, CybersecurityIndustries
5,001-10,000Employees

Benefits

Competitive Employee Stock Purchase Plan
Remote-friendly culture
Market leader in compensation and equity awards
Competitive vacation and flexible working arrangements
Comprehensive health benefits + 401k plan
Paid Parental Leave, including adoption
Wellness programs
Professional development and mentorship opportunities
Open offices have stocked kitchens, coffee, soda and treats

Risks

Increased competition from companies like Lumos could challenge CrowdStrike's market share.
Recovery from last year's outage may still affect customer trust and future sales.
Pressure to demonstrate ROI by 2025 could challenge CrowdStrike's financial transparency.

Differentiation

CrowdStrike's Falcon platform offers cloud-native endpoint security solutions, a key differentiator.
The company serves 44 of the Fortune 100, showcasing its strong market presence.
CrowdStrike's proactive threat hunting sets it apart in cybersecurity threat detection.

Upsides

Partnership with SonicWall opens new SMB market segment for CrowdStrike.
Recognition as a leader in ransomware prevention boosts CrowdStrike's market credibility.
Gamified learning initiatives help address cybersecurity skills gap, benefiting future talent pipeline.

Land your dream remote job 3x faster with AI