About the Role
The CrowdStrike Endpoint Protection (EPP) Content Response team is seeking an experienced professional to analyze intrusions, threat campaigns, and malware, and to drive efforts to mitigate them by implementing robust behavioral detection coverage on the Falcon sensor platform. This role improves detection capability and efficiency through tactical analysis of ongoing attacks, translating observed attacker behavior into high-fidelity endpoint detections deployed at global scale. The role requires independent work and collaboration across threat intelligence, engineering, and operational teams, with an expectation to identify and solve detection gaps that directly protect customers. This is a cutting-edge threat detection team regularly facing sophisticated techniques and well-resourced adversaries.
Responsibilities
- Analyze emerging threats, campaigns, intrusion data, and malware execution telemetry to identify detectable behaviors and coverage gaps.
- Author and optimize behavioral detection rules (Indicators of Attack) targeting adversary techniques observed on Windows endpoints.
- Query and analyze endpoint telemetry (process execution, file system, registry, memory, authentication events) to validate detection hypotheses and assess coverage.
- Monitor detection precision metrics, investigate false positives, and tune detections to maintain high signal-to-noise ratios.
- Manage detections through a structured lifecycle: development, validation, staged deployment, and production monitoring.
- Collaborate with threat intelligence and incident response teams to prioritize detection development based on active threat campaigns.
Requirements
- Must be eligible for CJIS clearance (requires U.S. citizenship or Green Card/permanent resident status).
- Bachelor's degree in information security, computer science, or related field — or 4+ years of equivalent hands-on experience in detection engineering, threat analysis, or endpoint security.
- Experience with endpoint detection platforms, EDR tooling, or detection-driven security workflows.
- Proficiency in Windows OS internals and APIs (process creation, registry, file system, memory management, authentication subsystems).
- Experience with behavioral malware analysis, sandboxing, telemetry collection, and detectable behaviors from execution logs or Windows forensics.
- Working knowledge of regular expressions and pattern-based detection authoring.
- Ability to read and understand various programming languages and PowerShell; scripting proficiency in Python for automation and analysis.
- Experience analyzing endpoint telemetry or host-based log data to identify malicious patterns.
- Solid working knowledge of common adversary TTPs and the ability to translate threat intelligence into detection logic.
- Ability to assess cyber threat intelligence, open-source intelligence, or partner reporting for actionable detection opportunities.
- Passion for detection engineering, threat analysis, or security research, with the motivation to keep learning and growing.
- Comfortable using AI-assisted tooling as a daily force multiplier.
- Energetic self-starter mentality with the ability to take ownership and be accountable for deliverables.
- Clear written and verbal communication skills to drive triage, convey detection rationale, and align cross-functionally with both technical and executive-level stakeholders.
- Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.
- Experience writing behavioral detection rules or signatures for an endpoint security product (IOA/IOC logic, behavioral engines, or equivalent).
- Experience with regex optimization or pattern matching in performance-sensitive contexts.
- Familiarity with detection precision concepts: true/false positive analysis, disposition workflows, and tuning at scale.
- Experience with detection content lifecycle management (development → testing → staged deployment → monitoring).
- Understanding of behavioral detection paradigms: process tree analysis, parent-child relationships, API call sequences, and living-off-the-land technique identification.
- Familiarity with MITRE ATT&CK adversary tactics and techniques.
- Experience in a security operations center or similar environment tracking threat actors and responding to incidents.
- Experience building test environments, lab infrastructure, or automation to improve detection development workflows.
- Working knowledge of agentic AI CLIs and skills for detection engineering workflows.
- Contributions to the open-source community (GitHub, Stack Overflow, blogging) or published research (conferences, blogs, articles).
- This role will require the candidate to periodically undergo and pass additional background and fingerprint check(s) consistent with government customer requirements.
Skills
- Endpoint protection
- Behavioral detection
- Windows OS internals
- Windows APIs
- Behavioral malware analysis
- Sandboxing
- Telemetry collection
- Regular expressions
- Pattern-based detection
- Programming languages
- PowerShell
- Python scripting
- Endpoint telemetry analysis
- Host-based log data analysis
- Adversary TTPs
- Threat intelligence translation
- Cyber threat intelligence assessment
- Open-source intelligence assessment
- AI-assisted tooling
- AI technologies
- Detection engineering
- Threat analysis
- Security research
- Regex optimization
- Pattern matching
- Detection precision
- True/false positive analysis
- Disposition workflows
- Detection content lifecycle management
- Behavioral detection paradigms
- Process tree analysis
- Parent-child relationships
- API call sequences
- Living-off-the-land techniques
- MITRE ATT&CK
- Security operations center (SOC)
- Incident response
- Test environment building
- Lab infrastructure building
- Automation
- Agentic AI CLIs
- Open-source contributions
- Published research
Location
- Hybrid
Work Type
- Hybrid
Experience Level
- Experienced professional
Education Level
- Bachelor's degree in information security, computer science, or related field
Salary/Compensations
- $100,000 - $145,000 per year
Benefits
- Market leader in compensation and equity awards
- Comprehensive physical and mental wellness programs
- Competitive vacation and holidays
- Paid parental and adoption leaves
- Professional development opportunities
- Employee Networks, geographic neighborhood groups, and volunteer opportunities
- Vibrant office culture with world class amenities
- Great Place to Work Certified™
- Eligibility for bonuses
- Equity grants
- Health insurance
- 401k
- Paid time off
About the Company
- Global leader in cybersecurity, protecting people, processes, and technologies that drive modern organizations.
- Mission: To stop breaches, redefining modern security with the world’s most advanced AI-native platform.
- Processes almost 3 trillion events per day on large scale distributed systems, with daily traffic growth.
- Customers span all industries, relying on CrowdStrike to keep businesses running, communities safe, and lives moving forward.
- Mission-driven company leveraging AI to transform work.
- CrowdStrikers drive careers through flexibility and autonomy, contributing to a culture of responsible AI adoption, experimentation, and innovation.
- Uses an AI-first mindset as a force multiplier to accelerate execution, build expertise, uncover insights, and solve complex problems.
- Seeking talented individuals with passion, a focus on innovation, and commitment to customers, community, and each other.
- Founded in 2011 to address the inadequacy of existing malware-based defenses against sophisticated attacks.
- Developed the Falcon platform, combining advanced endpoint protection with expert intelligence to pinpoint adversaries.
Equal Opportunity
- CrowdStrike is proud to be an equal opportunity employer.
- Committed to fostering a culture of belonging where everyone is valued and empowered to succeed.
- Supports veterans and individuals with disabilities through affirmative action.
- Provides equal employment opportunity for all employees and applicants.
- Does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law.
- Bases all employment decisions on valid job requirements.
- Participates in the E-Verify program.
- CrowdStrike, Inc. is committed to fair and equitable compensation practices.
