Key Responsibilities
- Develop and maintain automated malware analysis workflows, tooling, and enrichment capabilities to accelerate incident investigations.
- Perform advanced static and dynamic malware analysis, reverse engineering, and behavioral analysis of malware affecting clients.
- Support global Incident Response engagements through malware triage, root cause analysis, attribution support, and threat actor investigations.
- Research emerging malware families, intrusion techniques, and threat actor tradecraft.
- Author technical research reports, threat intelligence products, blogs, and client advisories.
- Partner with CrowdStrike and BlueVoyant MDR teams to develop malware analysis processes that enhance managed detection and response services.
- Provide technical mentorship and guidance to analysts across CTI, MDR, and Incident Response teams.
- Develop detection opportunities, indicators of compromise (IOCs), and analytical methodologies based on malware findings.
- Collaborate with internal malware analysis practitioners and external industry peers to establish best practices and improve investigative capabilities.
- Evaluate and implement new technologies, sandboxes, automation platforms, and AI-enhanced analytical workflows to improve operational efficiency.
- Contribute to the development of new cyber intelligence and malware-focused service offerings.
Required Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field, or equivalent practical experience.
- 5+ years of experience in malware analysis, reverse engineering, digital forensics, incident response, threat intelligence, or a related cybersecurity discipline.
- Strong understanding of Windows internals and common malware execution techniques.
- Experience performing static and dynamic malware analysis in enterprise environments.
- Experience supporting Incident Response investigations involving malware, ransomware, or advanced persistent threats (APTs).
- Strong technical writing skills with the ability to communicate complex findings to both technical and executive audiences.
- Experience creating actionable intelligence products, technical reports, and client deliverables.
- Ability to independently conduct research and solve complex technical challenges.
- Strong collaboration and stakeholder engagement skills.
Preferred Technical Skills Malware Analysis & Reverse Engineering
- IDA Pro
- Rust
- x64dbg
- WinDbg
- Binary Ninja
Programming & Automation
- Python
- PowerShell
- C#
- Go (preferred)
Security Platforms
- CrowdStrike Falcon
- SentinelOne
- Splunk
- Microsoft Sentinel
- Elastic
- Mandiant Advantage or similar threat intelligence platforms
Preferred Certifications
- GCFA (GIAC Certified Forensic Analyst)
- GCIA (GIAC Certified Intrusion Analyst)
- CISSP
- CARTP, CRTO, or equivalent offensive security certifications
What Success Looks Like
- Established automated malware analysis capabilities that measurably improve Incident Response efficiency.
- Built repeatable processes to support malware investigations across CTI, IR, and MDR teams.
- Produced impactful malware research and thought leadership content that enhances Kroll's market reputation.
- Improved support for clients leveraging CrowdStrike and BlueVoyant MDR services.
- Developed new analytical capabilities that increase visibility into sophisticated malware threats and drive better client outcomes.
- Become the technical focal point for malware-related investigations across Kroll's cyber risk business.
Benefits (Summary)
Healthcare Coverage: Comprehensive medical, dental, and vision plans.
Time Off and Leave Policies: Generous paid time off (PTO), paid company holidays, generous parental and family leave.
Protective Insurances: Life insurance, short- and long-term disability coverage, and accident protection.
Compensation and Rewards: Competitive salary structures, performance-based incentives, and merit-based compensation reviews.
Retirement Plans: 401(k) plans with company matching.
Please note that benefits may vary by region, department and role. We encourage you to speak with your recruiter to learn more about the specific benefits available for your position.
About Kroll
Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting‑edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll.
We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability.
The current salary range for this position is $200,000 to $240,000