Salary
💰 $100,000 - $155,000 per year
Tech Stack
AWSAzureCloudCyber SecurityGoogle Cloud Platform
About the role
- CrowdStrike Intelligence seeking Intelligence Analyst for GTAC to identify, research and track cloud threat trends
Focus on tracking and documenting cloud-related techniques observed in the wild and their use by intrusion and eCrime adversaries
Coordinate with subject matter experts and integrate data from other sources
Increase understanding of global cloud threat landscape and contribute to tracking of criminal and state-sponsored adversary groups
Develop finished intelligence products
Query Logscale and analyze raw cloud logs including CloudTrail and Azure related logs
Research new techniques for clustering and tracking cloud-conscious threat actors
Identify and monitor TTPs employed by cyber threat actors that compromise cloud environments
Provide finished intelligence analysis through written reporting on short deadlines
Collaborate across teams and identify intelligence gaps and requests for information
Conduct briefings for various customers as needed
Requirements
- Minimum of 2-3 years’ experience in a threat intelligence environment or cloud-focused incident response
Motivated self-starter with experience in the cyber threat intelligence field, preferably with experience in researching and reporting on cloud incidents in AWS, Azure, or GCP as well as adversary behavior
Experience analyzing API logs (e.g. CloudTrail) from at least one of the three major cloud service providers: AWS, Azure, or GCP
Basic understanding of identity and access management (IAM) concepts in the cloud
Understanding of identity initial access and BEC techniques including AitM and password spraying
Ability to identify and track adversary tradecraft trends
Ability to produce quality finished intelligence products on short deadlines, as well as continuing to maintain analysis for and report on long term strategic assessments
Basic knowledge of how malware is developed, functions, and is employed
Desire to extend knowledge on intelligence tradecraft and technical terminology relevant to cloud intelligence, and provide assistance to other members of the intelligence team
Undergraduate degree, military training or relevant experience in cyber intelligence, computer science, general intelligence studies, security studies, political science, international relations, etc.