Detection Engineer, Falcon Complete (Remote)
As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We’re also a mission-driven company. We cultivate a culture that gives every CrowdStriker both the flexibility and autonomy to own their careers. We’re always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you.
About the Role:
The CrowdStrike Managed Services team offers opportunities to expand your skill set through a wide variety of experiences building detection rules, tools, and infrastructure supporting Falcon Complete Next-Gen SIEM. As a Detection Engineer on the Falcon Complete team, you will be responsible for collaborating with internal CrowdStrike teams to create high fidelity detections based on both CrowdStrike and 3rd-party telemetry to enable the Falcon Complete Next-Gen MDR team. The ideal candidate will demonstrate high competency in technical skills aimed at delivering value for customers and providing a successful experience with Falcon Complete.
What You’ll Do:
- Perform threat research and threat hunting to identify emerging tactics, techniques, and procedures (TTPs) to build detection requirements using an intelligence driven approach
- Develop, test, and deploy actionable high fidelity CrowdStrike Next-Gen SIEM detection rules to enable a world class Managed Detection and Response team
- Perform code reviews and testing to ensure high quality and high fidelity detection rules
- Leverage CI/CD best practices and principles to deploy detection rule logic at scale
- Collaborate with Security Analysts to create playbooks for triage and response for actionable high fidelity detections
- Collaborate with SIEM architects to develop and define best practices for parsing data and normalizing data to a common event schema
- Build and maintain utilities and tools to enable the managed services team to operate quickly and at a large scale
- Develop and maintain processes and documentation
- 3+ years of experience as a detection engineer, security engineer, security analyst, threat intelligence analyst, or related field
- Knowledge of current cyber threats and how to detect them using SIEM and relevant technologies
- Relevant industry certifications (i.e. GCFA, GCDA, GCIH, etc.)
- Experience with analyzing large datasets across variety of vendors
- Experience working with SIEM solutions (LogScale, Splunk, SumoLogic, Sentinel, QRadar, LogRhythm, etc)
- Proven ability to write code and leverage regular expressions
- Participate in a Detection Engineer handler rotation
- Attention to detail and effective communication skills
- Remote-friendly and flexible work culture
- Market leader in compensation and equity awards
- Comprehensive physical and mental wellness programs
- Competitive vacation and holidays for recharge
- Paid parental and adoption leaves
- Professional development opportunities for all employees regardless of level or role
- Employee Resource Groups, geographic neighbourhood groups and volunteer opportunities to build connections
- Vibrant office culture with world class amenities
- Great Place to Work Certified across the globe