CrowdStrike Analyst

ComTec Information Systems (IT)

The Woodlands (TX)

On-site

USD 85,000 - 125,000

Full time

18 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

CrowdStrike Analyst in The Woodlands, TX or Little Rock, AR is sought to monitor and investigate endpoint threats using the CrowdStrike Falcon platform. The role focuses on threat detection, incident response, and proactive threat hunting to strengthen endpoint security.

You will analyze telemetry, correlate data with SIEMs like Splunk, develop detection queries with CQL, and coordinate containment and remediation.

Qualifications

  • 3+ years hands-on with CrowdStrike Falcon or equivalent EDR/XDR.
  • Strong threat detection, threat hunting, incident response, and endpoint investigation.
  • Experience with Windows/Linux security, malware/ransomware, attacker techniques.
  • Knowledge of MITRE ATT&CK, IOC/IOA analysis, threat intelligence, and SIEM correlations.

Responsibilities

  • Monitor and investigate alerts using CrowdStrike Falcon.
  • Perform threat detection, hunting, incident investigation, and response.
  • Analyze endpoint telemetry, processes, network activity, and file behavior.
  • Investigate malware, ransomware, phishing, credential attacks, and PowerShell activity.
  • Use CrowdStrike Falcon Insight/EDR for investigation and response.
  • Develop and tune detection queries and workflows with CQL.
  • Proactive threat hunting using MITRE ATT&CK and threat intel.
  • Correlate CrowdStrike data with Splunk, Cribl, and other sources.
  • Coordinate containment, remediation, and recovery activities.
  • Use CrowdStrike APIs and scripting to improve operations.
  • Support AI-assisted workflows where applicable.
  • Document incidents, findings, root cause, and remediation actions.

Skills

CrowdStrike Falcon
Threat detection
Incident response
Endpoint investigation
MITRE ATT&CK
Splunk SIEM
Scripting
SOAR automation
Communication skills

Tools

CrowdStrike EDR
CQL
Python
PowerShell
Splunk
Cribl
SOAR platforms

Job description

CrowdStrike Analyst
The Woodlands, TX or Little Rock, AR
Job Overview

We are seeking a CrowdStrike Analyst with strong hands-on experience in the CrowdStrike Falcon platform, endpoint detection and response, threat hunting, security investigation, and incident response. The candidate will monitor and investigate endpoint threats, analyze security telemetry, identify malicious activity, and support automated detection and response.

Responsibilities
  • Monitor and investigate security alerts and incidents using CrowdStrike Falcon.
  • Perform threat detection, threat hunting, incident investigation, and response.
  • Analyze endpoint telemetry, processes, command lines, network activity, users, and file behavior.
  • Investigate malware, ransomware, phishing, credential attacks, and suspicious PowerShell activity.
  • Use CrowdStrike Falcon Insight/EDR capabilities for endpoint investigation and response.
  • Develop and tune detection queries and investigation workflows using CrowdStrike Query Language (CQL).
  • Perform proactive threat hunting based on MITRE ATT&CK techniques and threat intelligence.
  • Correlate CrowdStrike data with Splunk/SIEM, Cribl, and other security data sources.
  • Execute or coordinate endpoint containment, remediation, and recovery activities.
  • Use CrowdStrike APIs, scripting, and automation to improve security operations.
  • Support AI-assisted / AI-driven detection and response (AIDR) workflows where applicable.
  • Document incidents, investigation findings, root cause, and remediation actions.
Required Skills
  • 3+ years of hands-on experience with CrowdStrike Falcon or equivalent EDR/XDR platforms.
  • Strong experience in threat detection, threat hunting, incident response, and endpoint investigation.
  • Hands-on experience with CrowdStrike Falcon EDR/Insight and CQL.
  • Strong understanding of Windows and Linux security, malware, ransomware, and attacker techniques.
  • Knowledge of MITRE ATT&CK, IOC/IOA analysis, threat intelligence, and security operations.
  • Experience with Splunk or another SIEM for event correlation and investigation.
  • Scripting/automation experience with Python, PowerShell, or similar tools.
  • Experience working with security APIs and SOAR/automation workflows.
  • Strong analytical, troubleshooting, and communication skills.
Preferred Skills
  • CrowdStrike certifications.
  • Experience with Falcon Fusion or similar automated response capabilities.
  • Experience integrating CrowdStrike with Splunk, Cribl, SOAR, or security data platforms.
  • Experience with AI/GenAI, AI agents, or AI-driven security operations.
  • Experience developing automated threat detection and response workflows.
  • Knowledge of cloud security and AWS security services.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CrowdStrike Falcon Threat Hunter & IR Analyst
CrowdStrike Falcon Threat Hunter & IR Analyst

ComTec Information Systems (IT) • The Woodlands (TX)

On-site
USD 85,000 - 125,000
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)

CrowdStrike, Inc. • Sunnyvale (CA)

On-site
USD 85,000 - 120,000
Equity awards
Wellness programs
Vacation and holidays
+3
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)

Socket.dev • St. Louis (MO)

On-site
USD 85,000 - 120,000
Compensation & equity
Wellness programs
Vacation & holidays
+5
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)

CrowdStrike • United States

On-site
USD 85,000 - 120,000
Equity awards
Wellness programs
Vacation & holidays
+5
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)

CrowdStrike • St. Louis (MO)

On-site
USD 85,000 - 120,000
Equity awards
Wellness programs
Vacation and holidays
+4
Associate Analyst, Falcon Complete
Associate Analyst, Falcon Complete

CrowdStrike, Inc. • St. Louis (MO)

Hybrid
USD 70,000 - 95,000
Health insurance
Equity grants
Paid time off
+1
Senior Information Security Engineer – SIEM, Detection
Senior Information Security Engineer – SIEM, Detection

Jobtailor • Washington

On-site
USD 170,000 - 250,000
Associate Security Engineer (Remote)
Associate Security Engineer (Remote)

CrowdStrike • Town of Texas (WI)

On-site
USD 70,000 - 95,000
Market-leading compensation
Comprehensive wellness programs
Paid time off and holidays
Sr. Windows Sensor Engineer (Hybrid)
Sr. Windows Sensor Engineer (Hybrid)

CrowdStrike • Sunnyvale (CA)

On-site
USD 140,000 - 215,000
Competitive compensation
Wellness programs
Paid time off
+5
Incident Response Senior Consultant (Remote)
Incident Response Senior Consultant (Remote)

CrowdStrike Holdings, Inc. • Northern (KY)

Hybrid
USD 95,000 - 140,000
Health insurance
401k
Paid time off
+1