368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$94k – $213k per year (Estimated)
Location
In office (Sunnyvale, New York, Austin, Redmond)
Seniority
Middle · 4+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
CrowdStrike is a global cybersecurity leader specializing in cloud-delivered endpoint protection, threat intelligence, and cyberattack response services. Headquartered in Austin, Texas, and publicly traded on the Nasdaq (CRWD), the company provides real-time security solutions to enterprises worldwide.

As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed - we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. We work on large scale distributed systems, processing almost 3 trillion events per day and this traffic is growing daily. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We're proud to work for a mission-driven company leveraging AI to transform the way we work. CrowdStrikers drive their careers through flexibility and autonomy while also being expected to contribute to a culture of responsible AI adoption, experimentation, and innovation. We use an AI-first mindset as a force multiplier to proactively and continuously accelerate execution, build expertise, uncover insights, and solve complex problems. We’re always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you.

About the Role:

The CrowdStrike Endpoint Protection (EPP) Content Response team is seeking an experienced and passionate professional to analyze intrusions, threat campaigns, and malware - and to drive efforts to mitigate them by implementing robust behavioral detection coverage on the Falcon sensor platform. The Content Response Team improves detection capability and efficiency through tactical analysis of ongoing attacks by criminal and nation-state actors impacting our customers, translating observed attacker behavior into high-fidelity endpoint detections deployed at global scale.

The role requires independent work as well as the ability to collaborate across threat intelligence, engineering, and operational teams. You will be expected to take initiative identifying and solving detection gaps that directly protect our customers. You will be part of a cutting-edge threat detection team regularly facing off against sophisticated techniques and well-resourced adversaries.

This role is hybrid, requiring 2-3 days per week on-site at one of the posted locations.

What You'll Do:

  • Analyze emerging threats, campaigns, intrusion data, and malware execution telemetry to identify detectable behaviors and coverage gaps

  • Author and optimize behavioral detection rules (Indicators of Attack) targeting adversary techniques observed on Windows endpoints

  • Query and analyze endpoint telemetry (process execution, file system, registry, memory, authentication events) to validate detection hypotheses and assess coverage

  • Monitor detection precision metrics, investigate false positives, and tune detections to maintain high signal-to-noise ratios

  • Manage detections through a structured lifecycle: development, validation, staged deployment, and production monitoring

  • Collaborate with threat intelligence and incident response teams to prioritize detection development based on active threat campaigns

What You’ll Need:

  • Must be eligible for CJIS clearance (requires U.S. citizenship or Green Card/permanent resident status).

  • Bachelor's degree in information security, computer science, or related field - or 4+ years of equivalent hands-on experience in detection engineering, threat analysis, or endpoint security

  • Experience with endpoint detection platforms, EDR tooling, or detection-driven security workflows

  • Proficiency in Windows OS internals and APIs (process creation, registry, file system, memory management, authentication subsystems)

  • Experience with behavioral malware analysis, sandboxing, telemetry collection, and detectable behaviors from execution logs or Windows forensics

  • Working knowledge of regular expressions and pattern-based detection authoring

  • Ability to read and understand various programming languages and PowerShell; scripting proficiency in Python for automation and analysis

  • Experience analyzing endpoint telemetry or host-based log data to identify malicious patterns

  • Solid working knowledge of common adversary TTPs and the ability to translate threat intelligence into detection logic

  • Ability to assess cyber threat intelligence, open-source intelligence, or partner reporting for actionable detection opportunities

  • Passion for detection engineering, threat analysis, or security research, with the motivation to keep learning and growing

  • Comfortable using AI-assisted tooling as a daily force multiplier, not just a novelty

  • Energetic self-starter mentality with the ability to take ownership and be accountable for deliverables

  • Clear written and verbal communication skills to drive triage, convey detection rationale, and align cross-functionally with both technical and executive-level stakeholders

  • Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.

  • Comfortable working on call rotation as needed

Bonus Points:

  • Experience writing behavioral detection rules or signatures for an endpoint security product (IOA/IOC logic, behavioral engines, or equivalent)

  • Experience with regex optimization or pattern matching in performance-sensitive contexts

  • Familiarity with detection precision concepts: true/false positive analysis, disposition workflows, and tuning at scale

  • Experience with detection content lifecycle management (development → testing → staged deployment → monitoring)

  • Understanding of behavioral detection paradigms: process tree analysis, parent-child relationships, API call sequences, and living-off-the-land technique identification

  • Familiarity with MITRE ATT&CK adversary tactics and techniques

  • Experience in a security operations center or similar environment tracking threat actors and responding to incidents

  • Experience building test environments, lab infrastructure, or automation to improve detection development workflows

  • Working knowledge of agentic AI CLIs and skills for detection engineering workflows

  • Contributions to the open-source community (GitHub, Stack Overflow, blogging) or published research (conferences, blogs, articles)

This role will require the candidate to periodically undergo and pass additional background and fingerprint check(s) consistent with government customer requirements.

Benefits of Working at CrowdStrike:

  • Market leader in compensation and equity awards

  • Comprehensive physical and mental wellness programs

  • Competitive vacation and holidays for recharge

  • Paid parental and adoption leaves

  • Professional development opportunities for all employees regardless of level or role

  • Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections

  • Vibrant office culture with world class amenities

  • Great Place to Work Certified™ across the globe

CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program.

CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions--including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs--on valid job requirements.

If you need assistance accessing or reviewing the information on this website or need help submitting an application for employment or requesting an accommodation, please contact us at [email protected] for further assistance.

Find out more about your rights as an applicant.

CrowdStrike participates in the E-Verify program.

Notice of E-Verify Participation

Right to Work

CrowdStrike, Inc. is committed to fair and equitable compensation practices. Placement within the pay range is dependent on a variety of factors including, but not limited to, relevant work experience, skills, certifications, job level, supervisory status, and location. The base salary range for this position for all U.S. candidates is $100,000 - $145,000 per year, with eligibility for bonuses, equity grants and a comprehensive benefits package that includes health insurance, 401k and paid time off.

For detailed information about the U.S. benefits package, please click here.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Sunnyvale
$100k – $500k per year • In office • Full-Time • 1+ year exp • Fort Collins
C++
Python
SystemVerilog
Cython
C++
CMake
Cython
PyBind11
AI/ML
ChatGPT
Claude
Copilot
Edge AI
Chips/EDA
Synopsys ZeBu
Apply
Remote/Hybrid • 7+ years exp • Bachelor's Degree
C#
JavaScript
Python
SQL
TypeScript
C#
ASP.NET Core
Blazor
Dapper
Databases
Oracle
Frontend
Angular
Bootstrap
JQuery
Vue.js
DevOps
AWS
Azure
Azure DevOps
CI/CD
Git
Apply
$26k – $90k per year (Estimated) • Remote/Hybrid • 2+ years exp • Madrid
Python
Python
Celery
Django
Databases
Apache Kafka
MySQL
PostgreSQL
RabbitMQ
Redis
Apply
$54k – $124k per year (Estimated) • Remote/Hybrid • 5+ years exp • Madrid
Python
Python
Celery
Django
Databases
Apache Kafka
MySQL
PostgreSQL
RabbitMQ
Redis
Apply
$26k – $66k per year (Estimated) • In office • Full-Time • 7+ years exp • Master's Degree • Hyderabad
Python
SQL
TypeScript
Databases
OpenSearch
Snowflake
AI/ML
AI Agents
AWS Bedrock
Claude
Claude Code
Fine-tuning
Hallucination
LangChain
LLM
Model Context Protocol
Multimodal AI
Prompt Engineering
RAG
Synthetic Data
A2A
Amazon SageMaker
DevOps
AWS
CI/CD
Docker
Vector
Analytics
A/B Testing
Apply
$17k – $50k per year (Estimated) • Equity • In office • Full-Time • 8+ years exp • Pune • Bengaluru
Go
DevOps
Argo Workflows
ArgoCD
CI/CD
Crossplane
GitHub Actions
GitOps
Grafana
Istio
Jaeger
Jenkins
Kubernetes
Linkerd
OpenTelemetry
Platform Engineering
Prometheus
Pulumi
Service Mesh
Tekton
Terraform
GitHub
Cybersecurity
Crowdstrike
Apply
$90k – $181k per year (Estimated) • Equity • Remote • Full-Time • 5+ years exp • Bachelor's Degree • United States
Python
SQL
AI/ML
Airflow
DevOps
AWS
Azure
CI/CD
Docker
GCP
Kubernetes
Terraform
IAM
Cybersecurity
Crowdstrike
Apply
$18k – $52k per year (Estimated) • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Bengaluru
C++
Java
Python
AI/ML
AI Agents
Anomaly Detection
AutoGen
CrewAI
Function Calling
LangChain
LangSmith
LlamaIndex
LLM
Prompt Engineering
RAG
Weights & Biases
Arize Phoenix
DevOps
Ansible
Chef
CI/CD
Configuration Management
Docker
Grafana
Kubernetes
Platform Engineering
Prometheus
Puppet
Self-Healing
VMWare
Cybersecurity
Crowdstrike
Apply
$97k – $209k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 5+ years exp • United States
AI/ML
LLM
DevOps
ArgoCD
AWS
CI/CD
Datadog
GitLab CI
GitOps
Helm
Kubernetes
Octopus Deploy
Platform Engineering
Terraform
GitLab
IAM
Cybersecurity
Crowdstrike
SOC 2
Apply
$20k – $50k per year (Estimated) • Equity • Remote • Full-Time • 7+ years exp • India
Apex
Apex
Copado
Lightning Web Components
Visualforce
AI/ML
Agentforce
AI Agents
DevOps
CI/CD
Cybersecurity
Crowdstrike
Management
Slack
Marketing
Salesforce
Apply
Sr. SDET 1 hour ago
$109k – $163k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Sunnyvale
Java
Python
SQL
Java
Spring Framework
Mobile
JUnit
DevOps
CI/CD
Kubernetes
QA
Cypress
JMeter
Postman
Apply
$168k – $356k per year • In office • Full-Time • 8+ years exp • Master's Degree • Sunnyvale
Python
AI/ML
AI Agents
ChatGPT
Gemini
LLM
NLP
RAG
Recommender Systems
Semantic Search
Semantic Search
Vertex AI
Apply
$81k – $155k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Sunnyvale
Apply
$148k – $267k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 5+ years exp • Sunnyvale • Boston • Austin • Toronto • New York
AI/ML
AI Agents
Claude
Claude Code
Lovable
Replit
Cybersecurity
BeyondTrust
Crowdstrike
CyberArk
Delinea
Microsoft Entra ID
Okta
PCI DSS
SOC 2
Threat Modeling
Apply
$162k – $180k per year • Equity • In office • 5+ years exp • Bachelor's Degree • Sunnyvale
AI/ML
AI Agents
Chain-of-Thought
Fine-tuning
LLM
Prompt Engineering
RAG
Robotics
Digital Twin
Analytics
A/B Testing
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.