Senior Intelligence Analyst – Global Threat Analysis Cell (GTAC)
Join CrowdStrike, a global leader in cybersecurity and AI-native security platform, to protect modern organizations from advanced threats. In this senior role within the Global Threat Analysis Cell (GTAC), you will track and analyze targeted intrusion activity associated with Democratic People’s Republic of Korea (DPRK)-nexus adversaries, informing CrowdStrike customers with actionable intelligence.
Responsibilities
- Track adversary campaigns, tactics, techniques, and procedures (TTPs) through analysis of CrowdStrike telemetry, open-source data, and third‑party intelligence.
- Author high‑quality short and long‑format written reports independently, applying analytic trade‑craft, estimative language, confidence levels, and structured analytic techniques.
- Generate reporting from a range of sources with minimal factual or accuracy errors and strong style, in line with CrowdStrike Intelligence standards.
- Engage in cross‑team discussions, leading groups where you serve as the subject‑matter expert.
- Identify intelligence gaps and propose research projects, proactively addressing collection shortfalls and collaborating on product development.
- Conduct peer review of reporting to maintain analytic standards for accuracy, clarity, and objectivity.
- Lead and participate in analytic discussions, incorporating input from others into investigations.
- Prioritize, categorize, and respond to requests for information from internal and external customers, serving as a responsive go‑to person on specific topics.
- Support customer engagements and crisis‑response efforts, contributing to resolutions.
- Conduct briefings independently for various customer levels via phone, video conference, webcast, in‑person, or industry conferences.
- Identify opportunities for automation and process improvements, contributing to the development of automation tools.
- Leverage cross‑team contacts and inter‑organizational partnerships to align analytical priorities.
- Track DPRK‑nexus financial operations, including cryptocurrency theft, money‑laundering trade‑craft, and blockchain‑based sanctions evasion activity.
- Develop and maintain technical infrastructure tracking for DPRK‑nexus adversaries, using tools such as Censys, VirusTotal, DomainTools, and Netflow.
- Contribute to team knowledge transfer through peer review, mentorship of junior analysts, and documentation of methodologies.
- Support production‑planning discussions and prioritize analytical workstreams and mission coverage.
Qualifications
Required
- Self‑motivated professional with 3+ years’ experience in a threat‑intelligence environment focused on DPRK cyber operations.
- Advanced knowledge of threat‑intelligence research/collection tools and analytical trade‑craft methods.
- Proven ability to identify, organize, catalog, and track adversary trade‑craft trends, often with incomplete data.
- Consistent production of high‑quality finished intelligence products on short deadlines, and maintenance of long‑term strategic assessments.
- Strong understanding of technical concepts related to cyber threat research and effective written communication.
- Ability to conduct technical analysis of tools and trade‑craft employed by threat actors and monitor adversary infrastructure.
- Proficiency with infrastructure‑tracking tools (e.g., Censys, VirusTotal, DomainTools, Netflow) and documentation of methodology and findings.
- Experience coordinating research projects and written products among subject‑matter experts and technical specialists.
- Strong understanding and application of adversary‑attribution concepts and ability to present attribution points in complex cases.
- Excellent knowledge of DPRK geopolitical issues and cyber‑operations for revenue generation and sanctions evasion.
- Self‑driven research habit, awareness of the state of the field, and knowledge of the CrowdStrike Intelligence ecosystem.
- Ability to coordinate multiple sources and maintain priorities within the mission area.
- Acts as a role model for analytical objectivity and resolves analytical disagreements independently.
- Provides a stable point of contact under high‑stress conditions.
Preferred
- Familiarity with cryptocurrency‑tracking platforms (e.g., Chainalysis, TRM Labs) or rapid proficiency in developing such skills.
- Understanding of blockchain‑based money‑laundering and sanctions‑evasion techniques relevant to state‑sponsored cyber operations.
- Experience functioning as a team lead, senior contributor, or de‑facto subject‑matter expert within an intelligence production team.
- Track record of proactive initiative in filling intelligence gaps and driving analytical work to completion with limited direction.
Education
Undergraduate degree or equivalent military training/experience in cyber intelligence, computer science, general intelligence studies, security studies, political science, international relations, or related fields.
Benefits of Working at CrowdStrike
- Market‑leader compensation and equity awards.
- Comprehensive physical and mental wellness programs.
- Competitive vacation and holidays for recharge.
- Paid parental and adoption leave.
- Professional development opportunities for all employees.
- Employee networks, neighborhood groups, and volunteer opportunities.
- Vibrant office culture with world‑class amenities.
Equal Employment Opportunity Statement
CrowdStrike is a proud equal‑opportunity employer that fosters belonging and empowers employees of all backgrounds. We support veterans and individuals with disabilities through an affirmative action program. Employment decisions are based solely on valid job requirements.
Additional Information
For assistance accessing or reviewing this job posting, or for accommodation requests, contact recruiting@crowdstrike.com. CrowdStrike participates in the E‑Verify program.
Expected Close Date of Job Posting: 07‑08‑2026