Senior Threat Intelligence Analyst (China Focus)
Recorded FutureFull Time
Senior (5 to 8 years), Expert & Leadership (9+ years)
The ideal candidate possesses deep technical expertise in Linux or Mac operating systems, including internals and threat behaviors, and demonstrated subject matter expertise in public Cloud environments, preferably AWS or Azure. A strong background in reverse engineering malware and malware operations is required, along with solid proficiency in Python and additional experience in other scripting/programming languages. In-depth understanding of binary analysis, including file attributes, imports/exports, and common packing techniques, is essential. Advanced analytical skills, including practical experience with threat research, intelligence collection, and structured analysis methodologies, are necessary, as is a strong grasp of threat/risk assessment and threat management frameworks. Experience with security detections by machine learning models is a plus.
The Senior Threat Analyst will lead efforts to review and refine product detections to ensure they meet and exceed company standards. This role involves identifying and driving improvements in false positive detection management through deep technical analysis and process enhancements. Responsibilities include analyzing files and killchains across different platforms (Linux, public Clouds, Mac, and Windows) to assess legitimacy and identify malicious behaviors. The analyst will also act as a senior escalation point for internal teams regarding complex customer threat detections and collaborate cross-functionally with threat research, engineering, and incident response teams to drive detection efficacy.
Cloud-native endpoint security solutions provider
CrowdStrike specializes in cybersecurity, focusing on protecting businesses from cyber threats through cloud-native endpoint security solutions. Their main product, the Falcon platform, includes services like Falcon Pro, which replaces traditional antivirus with next-generation antivirus that integrates threat intelligence, Falcon Insight for endpoint detection and response, and Falcon Device Control to manage connected devices. Unlike many competitors, CrowdStrike's services are subscription-based, allowing clients to choose different levels of protection based on their needs. The company serves a diverse clientele, including many Fortune 100 companies, and is recognized as a leader in the cybersecurity field, known for its effectiveness in threat detection and response.