Director, Malware Analysis, Threat Intelligence

Posted 17 Days Ago
Be an Early Applicant
4 Locations
In-Office
200K-240K Annually
Senior level
Big Data • Security • Software • Analytics • Cybersecurity
The Role
Lead development of automated malware analysis workflows and tooling, perform advanced static/dynamic reverse engineering, support incident response and attribution, produce intelligence products and research, mentor analysts, partner with MDR teams, and develop detection content and new malware-focused service offerings.
Summary Generated by Built In

Kroll is seeking an experienced and innovative Malware Analysis Director to build and advance our malware analysis capabilities in support of our global Incident Response (IR), Managed Detection and Response (MDR), and Cyber Threat Intelligence (CTI) practices. This role will be responsible for developing automated malware analysis workflows and tooling that empower frontline responders, conducting deep technical investigations into sophisticated malware campaigns, and producing actionable intelligence that helps clients understand and mitigate evolving cyber threats.

 

The successful candidate will serve as a technical leader and trusted advisor, partnering closely with Incident Response consultants, Threat Intelligence analysts, CrowdStrike and BlueVoyant MDR teams, and other cyber specialists to improve Kroll's ability to identify, analyze, and respond to advanced malware threats. This individual will also contribute to Kroll's thought leadership efforts through technical blogs, research reports, threat advisories, and client-facing intelligence products.

 

This is a unique opportunity to shape the strategic direction of malware analysis within Kroll, develop new client-facing capabilities, and drive innovation across the cyber risk organization.

 

Key Responsibilities:

  • Develop and maintain automated malware analysis workflows, tooling, and enrichment capabilities to accelerate incident investigations.

  • Perform advanced static and dynamic malware analysis, reverse engineering, and behavioral analysis of malware affecting clients.

  • Support global Incident Response engagements through malware triage, root cause analysis, attribution support, and threat actor investigations.

  • Research emerging malware families, intrusion techniques, and threat actor tradecraft.

  • Author technical research reports, threat intelligence products, blogs, and client advisories.

  • Partner with CrowdStrike and BlueVoyant MDR teams to develop malware analysis processes that enhance managed detection and response services.

  • Provide technical mentorship and guidance to analysts across CTI, MDR, and Incident Response teams.

  • Develop detection opportunities, indicators of compromise (IOCs), and analytical methodologies based on malware findings.

  • Collaborate with internal malware analysis practitioners and external industry peers to establish best practices and improve investigative capabilities.

  • Evaluate and implement new technologies, sandboxes, automation platforms, and AI-enhanced analytical workflows to improve operational efficiency.

  • Contribute to the development of new cyber intelligence and malware-focused service offerings.

 

Required Qualifications:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field, or equivalent practical experience.

  • 5+ years of experience in malware analysis, reverse engineering, digital forensics, incident response, threat intelligence, or a related cybersecurity discipline.

  • Strong understanding of Windows internals and common malware execution techniques.

  • Experience performing static and dynamic malware analysis in enterprise environments.

  • Experience supporting Incident Response investigations involving malware, ransomware, or advanced persistent threats (APTs).

  • Strong technical writing skills with the ability to communicate complex findings to both technical and executive audiences.

  • Experience creating actionable intelligence products, technical reports, and client deliverables.

  • Ability to independently conduct research and solve complex technical challenges.

  • Strong collaboration and stakeholder engagement skills.

 

Preferred Technical Skills

Malware Analysis & Reverse Engineering

  • Proficiency with: 

    • IDA Pro

    • Ghidra

    • Rust

    • x64dbg

    • WinDbg

    • Binary Ninja

    • Cutter/Rizin

  • Experience analyzing: 

    • Ransomware

    • Loaders and downloaders

    • Info-stealers

    • Banking trojans

    • Linux malware

    • Web shells

    • Nation-state malware

    • Advanced persistent threat toolsets

Programming & Automation

  • Strong scripting and development skills in: 

    • Python

    • PowerShell

    • C#

    • JavaScript

    • Go (preferred)

  • Experience building automated analysis pipelines and malware triage workflows.

  • Familiarity with API integrations and workflow orchestration.

Threat Intelligence & Detection

  • Knowledge of: 

    • MITRE ATT&CK

    • YARA

    • Sigma

    • STIX/TAXII

    • IOC management

  • Experience creating: 

    • Detection content

    • YARA rules

    • Behavioral signatures

    • Threat hunting methodologies

Security Platforms

  • Experience working with: 

    • CrowdStrike Falcon

    • Microsoft Defender

    • SentinelOne

    • BlueVoyant MDR

    • Splunk

    • Microsoft Sentinel

    • Elastic

    • Mandiant Advantage or similar threat intelligence platforms

Cloud & Enterprise Technologies

  • Familiarity with: 

    • AWS

    • Azure

    • Google Cloud Platform

    • Active Directory

    • Entra ID

    • Microsoft 365

    • Enterprise network architectures

Preferred Certifications

  • GREM (GIAC Reverse Engineering Malware)

  • GCFA (GIAC Certified Forensic Analyst)

  • GCTI (GIAC Cyber Threat Intelligence)

  • GCIA (GIAC Certified Intrusion Analyst)

  • CISSP

  • CARTP, CRTO, or equivalent offensive security certifications

  • Relevant CrowdStrike certifications

What Success Looks Like

Within the first 12–18 months, the successful candidate will have:

  • Established automated malware analysis capabilities that measurably improve Incident Response efficiency.

  • Built repeatable processes to support malware investigations across CTI, IR, and MDR teams.

  • Produced impactful malware research and thought leadership content that enhances Kroll's market reputation.

  • Improved support for clients leveraging CrowdStrike and BlueVoyant MDR services.

  • Developed new analytical capabilities that increase visibility into sophisticated malware threats and drive better client outcomes.

  • Become the technical focal point for malware-related investigations across Kroll's cyber risk business.

 

Your recruiter will be happy to walk you through your U.S.-specific benefits, which include:

 

  • Healthcare Coverage: Comprehensive medical, dental, and vision plans.

  • Time Off and Leave Policies: Generous paid time off (PTO), paid company holidays, generous parental and family leave.

  • Protective Insurances: Life insurance, short- and long-term disability coverage, and accident protection.

  • Compensation and Rewards: Competitive salary structures, performance-based incentives, and merit-based compensation reviews.

  • Retirement Plans: 401(k) plans with company matching.

 

Please note that benefits may vary by region, department and role. We encourage you to speak with your recruiter to learn more about the specific benefits available for your position.

 

About Kroll 

 

Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll. 

 

In order to be considered for a position, you must formally apply via careers.kroll.com.

 

We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability.

 

The current salary range for this position is $200,000 to $240,000

 

 

#DNI

 

Skills Required

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or equivalent practical experience.
  • 5+ years of experience in malware analysis, reverse engineering, digital forensics, incident response, threat intelligence, or related cybersecurity discipline.
  • Strong understanding of Windows internals and common malware execution techniques.
  • Experience performing static and dynamic malware analysis in enterprise environments.
  • Experience supporting Incident Response investigations involving malware, ransomware, or advanced persistent threats (APTs).
  • Strong technical writing skills with the ability to communicate complex findings to both technical and executive audiences.
  • Experience creating actionable intelligence products, technical reports, and client deliverables.
  • Ability to independently conduct research and solve complex technical challenges.
  • Strong collaboration and stakeholder engagement skills.
  • Proficiency with IDA Pro, Ghidra, Rust, x64dbg, WinDbg, Binary Ninja, Cutter/Rizin.
  • Strong scripting and development skills in Python, PowerShell, C#, JavaScript, and Go.
  • Experience with MITRE ATT&CK, YARA, Sigma, STIX/TAXII, and IOC management.
  • Experience working with CrowdStrike Falcon, Microsoft Defender, SentinelOne, BlueVoyant MDR, Splunk, Microsoft Sentinel, Elastic, and Mandiant Advantage or similar platforms.
  • Familiarity with AWS, Azure, Google Cloud Platform, Active Directory, Entra ID, Microsoft 365, and enterprise network architectures.
  • Preferred certifications: GREM, GCFA, GCTI, GCIA, CISSP, CARTP, CRTO, or relevant CrowdStrike certifications.

Kroll Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Kroll and has not been reviewed or approved by Kroll.

  • Healthcare Strength Medical, dental, and vision coverage with HSA/FSA options are part of the U.S. package, alongside life and AD&D. Breadth across core health benefits is positioned as competitive for a large advisory firm.
  • Retirement Support A 401(k) plan with company match is a core element of the package. Retirement support is consistently highlighted as competitive within total rewards.
  • Leave & Time Off Breadth Paid holidays, sick leave, and PTO are included, with generous time off and parental/family leave for U.S. roles. Some roles also offer hybrid/WFH flexibility that complements time-off usability.

Kroll Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
5,001 Employees
Year Founded: 1932

What We Do

Kroll is the world’s premier provider of services and digital products related to valuation, governance, risk and transparency. We work with clients across diverse sectors in the areas of valuation, expert services, investigations, cyber security, corporate finance, restructuring, legal and business solutions, data analytics and regulatory compliance. Our firm has nearly 5,000 professionals in 30 countries and territories around the world. For more information, visit www.kroll.com.

Similar Jobs

Zscaler Logo Zscaler

Principal, Product Marketing - ZPA

Cloud • Information Technology • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
USA
8697 Employees
200K-285K Annually
Remote or Hybrid
US
15100 Employees
107K-150K Annually
Remote or Hybrid
US
15100 Employees
164K-241K Annually

Samsara Logo Samsara

Senior Software Engineer

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
155K-208K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account