Threat Analyst

ThreatLocker Inc.

Orlando (FL)

On-site

USD 90,000 - 130,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The analyst will authors blogs and finished intelligence reports, leverage telemetry to address detection gaps, and collaborate with Detection Engineering to enhance ThreatLocker Detect coverage. This is an in‑office position in Orlando.

Qualifications

  • Minimum of 3 years of experience in Information Security.
  • Minimum of 2 years of experience in malware analysis, reverse engineering, or related discipline.
  • Familiarity with malware analysis and reverse engineering tools (IDA Pro, Binary Ninja, Detect It Easy, x64dbg, Malcat, HxD).
  • Experience with Windows operating systems and forensic artifacts.
  • Knowledge of MITRE ATT&CK framework and its enterprise application.
  • Excellent written and verbal communication skills; ability to explain complex concepts to non-technical stakeholders.
  • Content development or technical writing experience preferred.

Responsibilities

  • Identify and investigate new and emerging cybersecurity threats.
  • Track APT adversaries and characterize TTPs.
  • Conduct malware analysis, reverse engineering, infrastructure investigations, and campaign research.
  • Analyze artifacts and telemetry to identify malicious activity.
  • Author high-impact technical blog posts and finished intelligence reports.
  • Collaborate with Detection Engineering team to improve threat detection coverage.
  • Communicate complex threat intelligence to technical and non-technical stakeholders.
  • Provide insights regarding product functionality and roadmap considerations.
  • Manage multiple research priorities and meet deadlines.

Skills

Malware analysis
Reverse engineering
Threat hunting
Windows forensics
MITRE ATT&CK
Technical writing
Communication

Tools

IDA Pro
Binary Ninja
Detect It Easy
x64dbg
Malcat
HxD

Job description

ThreatLocker is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker platform with Application Allowlisting, Ringfencing, Storage Control, Elevation Control, Endpoint Network Control, Configuration Management, and Operational Alert solutions are leading the cybersecurity market toward a more secure approach of blocking the exploits of application vulnerabilities.

POSITION OVERVIEW

The Threat Analyst plays a key role within the ThreatLocker Threat Intelligence team, driving research and intelligence efforts focused on identifying and investigating new and emerging cybersecurity threats. This position is responsible for tracking advanced persistent threat (APT) adversaries, analyzing tactics, techniques, and procedures (TTPs), conducting malware and infrastructure investigations, and producing high-impact technical intelligence.

The Threat Analyst will author technical blog posts on malicious software, finished intelligence reports on malicious campaigns, threat actor profiles, and analyses of the evolving threat landscape. Artifacts and telemetry collected through malware analysis, infrastructure investigation, and campaign research will be leveraged to identify and address ThreatLocker Detect coverage deficiencies in partnership with Detection Engineering team members.

This role will be based in Orlando, FL and is an in-office position.

JOB SCOPE
  • Identify and investigate new and emerging cybersecurity threats.
  • Track APT adversaries and characterize their tactics, techniques, and procedures (TTPs).
  • Conduct malware analysis, reverse engineering, infrastructure investigations, and campaign research.
  • Analyze artifacts and telemetry to identify malicious activity and emerging threat patterns.
  • Author high-impact technical blog posts covering malicious software, campaigns, and threat research.
  • Produce finished intelligence reports on malicious campaigns, threat actor profiles, and threat landscape trends.
  • Leverage research findings and collected telemetry to identify potential ThreatLocker Detect coverage deficiencies.
  • Collaborate with Detection Engineering team members to improve and expand threat detection coverage.
  • Analyze Windows operating system artifacts, including mechanisms associated with persistence, privilege escalation, and defense evasion.
  • Apply the MITRE ATT&CK framework to threat research and analysis within enterprise environments.
  • Communicate complex technical findings and threat intelligence to both technical and non-technical stakeholders.
  • Provide professional insight and recommendations regarding product functionality and roadmap considerations.
  • Collaborate effectively with team members across Threat Intelligence, Detection Engineering, and other relevant functions.
  • Manage multiple research priorities and meet time-sensitive deadlines.
  • Perform other duties as assigned.
REQUIRED QUALIFICATIONS
  • Minimum of 3 years of experience in Information Security.
  • Minimum of 2 years of experience in malware analysis, reverse engineering, digital forensics, or a related discipline.
  • Familiarity with malware analysis and reverse engineering tools such as IDA Pro, Binary Ninja, Detect It Easy, x64dbg, Malcat, HxD, or similar platforms.
  • Experience with Windows operating systems and associated forensic artifacts.
  • Knowledge of common mechanisms used for persistence, privilege escalation, and defense evasion.
  • Familiarity with common parent-child process structures within Windows environments.
  • In-depth knowledge of the MITRE ATT&CK framework and its application within enterprise environments.
  • Strong understanding of security technologies and their relevant applications within enterprise environments.
  • Excellent analytical, critical-thinking, and problem-solving skills.
  • Ability to communicate abstract and complex technical concepts to non-technical stakeholders.
  • Strong written and verbal communication skills.
  • Content development or technical writing experience strongly preferred.
  • Self-starting mentality with the ability to work independently and take ownership of research initiatives.
  • Ability to perform effectively in a high-pressure environment.
  • Ability to collaborate and work effectively in a team setting.
  • Strong time management skills with the ability to meet time-sensitive deadlines.
  • Confidence in conveying professional opinions regarding product functionality and roadmap considerations.
RELEVANT CERTIFICATIONS

The following certifications are relevant to this position:

  • GIAC Certified Forensic Analyst (GCFA).
  • GIAC Certified Incident Handler (GCIH).
  • GIAC Certified Intrusion Analyst (GCIA).
  • GIAC Reverse Engineering Malware (GREM).
  • GIAC Information Security Professional Certification (GISP).
WORKING CONDITIONS

The duties described below are representative of those encountered while performing the essential functions of this position. If necessary, reasonable accommodation may be requested and will be evaluated for its relationship to the essential functions that must be performed.

  • The job will generally be performed in an office environment but may require travel to visit company offices, customers, prospects, partners, trade shows, conferences, or other business locations.
  • While performing the duties of this job, the employee may occasionally be required to stand, walk, sit, reach with hands and arms, climb or balance, stoop or kneel, talk and hear, and use fingers and hands to feel objects and tools.
  • Must occasionally lift and/or move up to 25 pounds.
  • Specific vision abilities required include close vision, distance vision, depth perception, and the ability to adjust focus.

A background check and drug/substance screening are required after a conditional offer. Employment will proceed only upon receiving clear results from both.

ThreatLocker also conducts randomized drug and substance testing approximately every 60 days, in line with the same screening standards.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.

As set forth in ThreatLocker’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Voluntary Self-Identification of Disability

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp .

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Engineer, Tooling
Software Engineer, Tooling

Anduril-1 • Fort Collins (CO)

On-site
USD 165,000 - 218,000
Senior Consultant, Restoration and Remediation (Remote)
Senior Consultant, Restoration and Remediation (Remote)

Surefire Cyber Inc. • Northern (KY)

Hybrid
USD 120,000 - 160,000
Competitive compensation
Generous paid time off
Employer-paid premiums for medical, d 
+3
Senior Informatics Engineer
Senior Informatics Engineer

Eikon Therapeutics • Millbrae (CA)

On-site
USD 134,000 - 162,000
401k plan with company matching
Medical, dental, and vision insurance
IT Systems Engineer III/IV Fort Worth, Texas
IT Systems Engineer III/IV Fort Worth, Texas

Zone 5 Tech • Fort Worth (TX)

On-site
USD 115,000 - 176,000
Comprehensive benefit package
401k with company-match
4 weeks of paid time off
+1
Test Engineer 3
Test Engineer 3

Captivation-Software • Maryland

On-site
USD 130,000 - 270,000
401k plan
HSA contribution
Insurance coverage
+1
Applied Machine Learning Engineer
Applied Machine Learning Engineer

Vulcan-Elements • Durham (NC)

On-site
USD 120,000 - 180,000
Software Engineer, Autonomous Driving Platforms
Software Engineer, Autonomous Driving Platforms

Bot Auto • San Francisco (CA), Houston (TX)

On-site
USD 100,000 - 150,000
Software Engineer, AI Platforms
Software Engineer, AI Platforms

Figma • San Francisco (CA)

Remote
USD 149,000 - 350,000
Health, dental & vision benefits
Retirement with company contribution
Generous PTO
+1
Senior Mechanical Engineer, Intelligence Systems
Senior Mechanical Engineer, Intelligence Systems

Anduril-1 • Costa Mesa (CA)

On-site
USD 146,000 - 194,000
Patient Services Representative - Front Desk - Henderson, NV
Patient Services Representative - Front Desk - Henderson, NV

PhyNet Dermatology LLC (External) • Henderson (NV)

On-site
USD 32,000 - 42,000