Kroll Logo

Kroll

Director, Malware Analysis, Threat Intelligence

Posted 13 Days Ago
Be an Early Applicant
In-Office
New York, NY, USA
200K-240K Annually
Senior level
In-Office
New York, NY, USA
200K-240K Annually
Senior level
Lead development of automated malware analysis workflows and tooling, perform advanced static/dynamic reverse engineering, support incident response and attribution, produce intelligence products and research, mentor analysts, partner with MDR teams, and develop detection content and new malware-focused service offerings.
The summary above was generated by AI

Kroll is seeking an experienced and innovative Malware Analysis Director to build and advance our malware analysis capabilities in support of our global Incident Response (IR), Managed Detection and Response (MDR), and Cyber Threat Intelligence (CTI) practices. This role will be responsible for developing automated malware analysis workflows and tooling that empower frontline responders, conducting deep technical investigations into sophisticated malware campaigns, and producing actionable intelligence that helps clients understand and mitigate evolving cyber threats.

 

The successful candidate will serve as a technical leader and trusted advisor, partnering closely with Incident Response consultants, Threat Intelligence analysts, CrowdStrike and BlueVoyant MDR teams, and other cyber specialists to improve Kroll's ability to identify, analyze, and respond to advanced malware threats. This individual will also contribute to Kroll's thought leadership efforts through technical blogs, research reports, threat advisories, and client-facing intelligence products.

 

This is a unique opportunity to shape the strategic direction of malware analysis within Kroll, develop new client-facing capabilities, and drive innovation across the cyber risk organization.

 

Key Responsibilities:

  • Develop and maintain automated malware analysis workflows, tooling, and enrichment capabilities to accelerate incident investigations.

  • Perform advanced static and dynamic malware analysis, reverse engineering, and behavioral analysis of malware affecting clients.

  • Support global Incident Response engagements through malware triage, root cause analysis, attribution support, and threat actor investigations.

  • Research emerging malware families, intrusion techniques, and threat actor tradecraft.

  • Author technical research reports, threat intelligence products, blogs, and client advisories.

  • Partner with CrowdStrike and BlueVoyant MDR teams to develop malware analysis processes that enhance managed detection and response services.

  • Provide technical mentorship and guidance to analysts across CTI, MDR, and Incident Response teams.

  • Develop detection opportunities, indicators of compromise (IOCs), and analytical methodologies based on malware findings.

  • Collaborate with internal malware analysis practitioners and external industry peers to establish best practices and improve investigative capabilities.

  • Evaluate and implement new technologies, sandboxes, automation platforms, and AI-enhanced analytical workflows to improve operational efficiency.

  • Contribute to the development of new cyber intelligence and malware-focused service offerings.

 

Required Qualifications:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field, or equivalent practical experience.

  • 5+ years of experience in malware analysis, reverse engineering, digital forensics, incident response, threat intelligence, or a related cybersecurity discipline.

  • Strong understanding of Windows internals and common malware execution techniques.

  • Experience performing static and dynamic malware analysis in enterprise environments.

  • Experience supporting Incident Response investigations involving malware, ransomware, or advanced persistent threats (APTs).

  • Strong technical writing skills with the ability to communicate complex findings to both technical and executive audiences.

  • Experience creating actionable intelligence products, technical reports, and client deliverables.

  • Ability to independently conduct research and solve complex technical challenges.

  • Strong collaboration and stakeholder engagement skills.

 

Preferred Technical Skills

Malware Analysis & Reverse Engineering

  • Proficiency with: 

    • IDA Pro

    • Ghidra

    • Rust

    • x64dbg

    • WinDbg

    • Binary Ninja

    • Cutter/Rizin

  • Experience analyzing: 

    • Ransomware

    • Loaders and downloaders

    • Info-stealers

    • Banking trojans

    • Linux malware

    • Web shells

    • Nation-state malware

    • Advanced persistent threat toolsets

Programming & Automation

  • Strong scripting and development skills in: 

    • Python

    • PowerShell

    • C#

    • JavaScript

    • Go (preferred)

  • Experience building automated analysis pipelines and malware triage workflows.

  • Familiarity with API integrations and workflow orchestration.

Threat Intelligence & Detection

  • Knowledge of: 

    • MITRE ATT&CK

    • YARA

    • Sigma

    • STIX/TAXII

    • IOC management

  • Experience creating: 

    • Detection content

    • YARA rules

    • Behavioral signatures

    • Threat hunting methodologies

Security Platforms

  • Experience working with: 

    • CrowdStrike Falcon

    • Microsoft Defender

    • SentinelOne

    • BlueVoyant MDR

    • Splunk

    • Microsoft Sentinel

    • Elastic

    • Mandiant Advantage or similar threat intelligence platforms

Cloud & Enterprise Technologies

  • Familiarity with: 

    • AWS

    • Azure

    • Google Cloud Platform

    • Active Directory

    • Entra ID

    • Microsoft 365

    • Enterprise network architectures

Preferred Certifications

  • GREM (GIAC Reverse Engineering Malware)

  • GCFA (GIAC Certified Forensic Analyst)

  • GCTI (GIAC Cyber Threat Intelligence)

  • GCIA (GIAC Certified Intrusion Analyst)

  • CISSP

  • CARTP, CRTO, or equivalent offensive security certifications

  • Relevant CrowdStrike certifications

What Success Looks Like

Within the first 12–18 months, the successful candidate will have:

  • Established automated malware analysis capabilities that measurably improve Incident Response efficiency.

  • Built repeatable processes to support malware investigations across CTI, IR, and MDR teams.

  • Produced impactful malware research and thought leadership content that enhances Kroll's market reputation.

  • Improved support for clients leveraging CrowdStrike and BlueVoyant MDR services.

  • Developed new analytical capabilities that increase visibility into sophisticated malware threats and drive better client outcomes.

  • Become the technical focal point for malware-related investigations across Kroll's cyber risk business.

 

Your recruiter will be happy to walk you through your U.S.-specific benefits, which include:

 

  • Healthcare Coverage: Comprehensive medical, dental, and vision plans.

  • Time Off and Leave Policies: Generous paid time off (PTO), paid company holidays, generous parental and family leave.

  • Protective Insurances: Life insurance, short- and long-term disability coverage, and accident protection.

  • Compensation and Rewards: Competitive salary structures, performance-based incentives, and merit-based compensation reviews.

  • Retirement Plans: 401(k) plans with company matching.

 

Please note that benefits may vary by region, department and role. We encourage you to speak with your recruiter to learn more about the specific benefits available for your position.

 

About Kroll 

 

Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll. 

 

In order to be considered for a position, you must formally apply via careers.kroll.com.

 

We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability.

 

The current salary range for this position is $200,000 to $240,000

 

 

#DNI

 

HQ

Kroll New York, New York, USA Office

600 3rd Ave, New York, NY, United States, 10016

Kroll Newark, New Jersey, USA Office

Newark, United States

Similar Jobs

37 Minutes Ago
In-Office
Mid level
Mid level
Artificial Intelligence • Hardware • Information Technology • Machine Learning
Design and implement high-performance Verilog/SystemVerilog RTL for HBM digital blocks. Define micro-architecture, optimize area/power/performance, address CDC/RDC and timing, apply low-power methodologies (CPF/UPF, clock gating), support synthesis/STA/SDC, collaborate with verification/DFT/physical design, and assist post-silicon debug and verification closure.
Top Skills: CdcClock GatingCpfLevel ShiftersLinuxMulti-Domain PartitioningPerlPythonRdcSdc ConstraintsStatic Timing Analysis (Sta)SynthesisSystemverilogUpfVerilog
Entry level
Artificial Intelligence • Hardware • Information Technology • Machine Learning
Develop, enhance, and support CAD/EDA tools and flows for NAND, DRAM, and HBM designs; provide production support, documentation, training, and collaborate across design, process, and vendor teams. Apply CAD software engineering and AI/ML techniques to improve automation, productivity, and design quality.
Top Skills: AICC++Cad ToolsCmosEda ToolsIc Design Cad ToolsJavaLayoutLinuxLispMachine LearningPerlPythonSchematic CaptureShell ScriptingSimulationSkillUnixVerificationVisual Basic
46 Minutes Ago
Remote or Hybrid
45K-100K Annually
Junior
45K-100K Annually
Junior
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Handle inbound and warm sales leads remotely, consult customers on insurance needs, match products and coverages, close sales, complete paid training and obtain Property & Casualty license, work scheduled shifts including one weekend day, and meet remote workspace and connectivity requirements.

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account