Cyber - CrowdStrike SecOps - Senior Consultant

Deloitte France

Portland (OR)

On-site

USD 105,000 - 208,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Deloitte Cyber Defense & Resilience is seeking a CrowdStrike SecOps Senior Consultant to design and deploy Falcon Next-Gen SIEM architectures and SOAR integrations across Windows, macOS, and Linux. You will work with SOC analysts to tune detections and automate responses, driving security maturity for enterprise clients.

Bring 5+ years in security operations, strong Python scripting, and deep CrowdStrike expertise to lead projects and coordinate with clients. Travel up to 50% may be required.

Qualifications

  • Bachelor’s degree in computer science, cybersecurity, information systems, or equivalent work experience.
  • 5+ years of experience in security operations, threat detection engineering, or enterprise information technology security.
  • 3+ years of hands-on experience with CrowdStrike Falcon platform architecture, modules, and administration, including Falcon Next-Gen SIEM; Falcon Insight EDR and XDR; Falcon Fusion SOAR; Falcon Identity Protection; Falcon Intelligence; Charlotte AI; sensor deployment; policy configuration; host grouping; exclusions; and response actions.
  • Experience conducting detection and response activities, including investigations, triage, host isolation, indicator blocking, and quarantine support; and applying the MITRE ATT&CK framework and Cyber Kill Chain.
  • Experience using Python or another scripting language for automation and integration development.
  • Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Responsibilities

  • Lead the design and implementation of Falcon Next-Gen SIEM architectures, including log source onboarding, data normalization, enrichment, and correlation rule development to support enterprise threat detection and analytics.
  • Lead the deployment of log-ingestion pipelines using data fabric technologies and API integrations, including Cribl, Tines, or similar technologies.
  • Administering and optimizing the CrowdStrike Falcon platform, including sensor deployment, policy configuration, host grouping, exclusions, and response actions across Windows, macOS, and Linux/server environments.
  • Collaborating with SOC analysts and threat detection engineers to prioritize, develop, and tune threat-detection content and use cases in CrowdStrike Falcon, including IOAs and correlation rules.
  • Building and maintaining Falcon Fusion SOAR playbooks and API-based integrations to automate alert enrichment, triage, and response, while advising clients on SOC maturity and platform capabilities.

Skills

CrowdStrike Falcon
SOAR automation
Threat detection
Python scripting
Data integration
Log analytics
SOC operations
Project leadership
MITRE ATT&CK

Education

Bachelor's degree
Cybersecurity degree

Tools

Cribl
PowerShell
Splunk
Cortex XSOAR
XSIAM
BindPlane

Job description

Our Deloitte Cyber team understands the evolving cybersecurity challenges and opportunities organizations face. Join our Cyber practice to help clients navigate a dynamic threat landscape through solutions and managed services that simplify complexity and strengthen resilience. In this role, you will support Next-Generation Security Operations Center (SOC) capabilities built on the CrowdStrike Falcon platform, including Falcon Next-Gen SIEM (NG SIEM), Falcon Insight Endpoint Detection and Response (EDR), Falcon Fusion SOAR, Falcon Identity Protection, Falcon Intelligence, and Charlotte AI. You will help clients operate with confidence and proactively manage cyber risk.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a CrowdStrike SecOps, Senior Consultant on the Cyber Defense & Resilience team, you will be responsible for:

  • Leading the design and implementation of Falcon Next-Gen SIEM architectures, including log source onboarding, data normalization, enrichment, and correlation rule development to support enterprise threat detection and analytics.

  • Leading the deployment of log-ingestion pipelines using data fabric technologies and application programming interface (API) integrations, including Cribl, Tines, or similar technologies.

  • Administering and optimizing the CrowdStrike Falcon platform, including sensor deployment, policy configuration, host grouping, exclusions, and response actions across Windows, macOS, and Linux/server environments.

  • Collaborating with SOC analysts and threat detection engineers to prioritize, develop, and tune threat-detection content and use cases in CrowdStrike Falcon, including custom indicators of attack (IOAs) and correlation rules to detect malicious behavior and adversary activity in enterprise environments.

  • Building and maintaining Falcon Fusion SOAR playbooks and API-based integrations to automate alert enrichment, triage, and response, while advising clients on SOC maturity and platform capabilities.

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team

  • Effective written and verbal communication skills

  • Meticulous attention to detail and quality of work product

  • Ability to build and sustain professional relationships

  • Ability to lead projects or workstreams

  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment

  • Strong interpersonal skills and professional demeanor

  • Ability to meet deadlines

  • Ability to provide clear guidance to others

The team

Deloitte's Cyber Defense & Resilience offering helps clients defend against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence capabilities. The team works with organizations to manage dynamic attack surfaces and strengthen readiness, response, and recovery across cyber incidents and broader business disruptions.

Qualifications

Required:

  • Bachelor's degree in computer science, cybersecurity, information systems, or equivalent work experience.

  • 5+ years of experience in security operations, threat detection engineering, or enterprise information technology security.

  • 3+ years of hands-on experience with CrowdStrike Falcon platform architecture, modules, and administration, including Falcon Next-Gen SIEM; Falcon Insight Endpoint Detection and Response (EDR) and extended detection and response (XDR); Falcon Fusion SOAR; Falcon Identity Protection; Falcon Intelligence; Charlotte AI; sensor deployment; policy configuration; host grouping; exclusions; and response actions.

  • Experience conducting detection and response activities, including investigations, triage, host isolation, indicator blocking, and quarantine support; and applying the MITRE ATT&CK framework and Cyber Kill Chain.

  • Experience using Python or another scripting language for automation and integration development.

  • Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve.

  • Limited immigration sponsorship may be available.

Preferred:

  • CrowdStrike Certified Falcon Administrator (CCFA), CrowdStrike Certified Falcon Responder (CCFR), or Certified Cloud Security Professional (CCSP) certification.

  • Experience using Python or PowerShell to develop Falcon Fusion SOAR playbooks and API integrations.

  • Experience conducting threat hunting or producing cyber threat intelligence.

  • Experience with data fabric technologies, including Bindplane or Cribl, and cloud infrastructure platforms, including Amazon Web Services (AWS) or Microsoft Azure.

  • Experience with security information and event management (SIEM) or security orchestration, automation, and response (SOAR) tools, including Splunk, Cortex XSOAR, or XSIAM.

  • Consulting experience or one or more of the following certifications: Certified Information Systems Security Professional (CISSP), Global Information Assurance Certification (GIAC) Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), or Certified Ethical Hacker (CEH).

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

#CyberCDR27

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber - CrowdStrike SecOps - Senior Consultant
Cyber - CrowdStrike SecOps - Senior Consultant

Deloitte France • San Jose (CA)

On-site
USD 105,000 - 208,000
Cyber - CrowdStrike SecOps - Senior Consultant
Cyber - CrowdStrike SecOps - Senior Consultant

Deloitte France • Richmond (VA)

On-site
USD 105,000 - 208,000
Cyber - CrowdStrike SecOps - Senior Consultant
Cyber - CrowdStrike SecOps - Senior Consultant

Deloitte France • United States

On-site
USD 105,000 - 208,000
CrowdStrike Platform Resident Consultant (Remote)
CrowdStrike Platform Resident Consultant (Remote)

CrowdStrike, Inc. • Sunnyvale (CA)

Remote
USD 85,000 - 120,000
Competitive compensation
Wellness programs
Paid time off
+3
Crowdstrike Technical Consultant
Crowdstrike Technical Consultant

Accenture • Redmond (WA)

On-site
USD 70,000 - 206,000
Medical benefits
Dental benefits
401(k) plan
CrowdStrike Platform Associate Resident Consultant (Remote)
CrowdStrike Platform Associate Resident Consultant (Remote)

Koitecc Solutions • Sunnyvale (CA)

Remote
USD 70,000 - 95,000
Market-leading compensation (base +)
Comprehensive wellness programs
Parental/maternity/paternity leaves
+2
CrowdStrike Platform Resident Consultant (Remote)
CrowdStrike Platform Resident Consultant (Remote)

Koitecc Solutions • Sunnyvale (CA)

Remote
USD 85,000 - 120,000
Market-leading compensation
Wellness programs
Paid time off & parental leave
Sr. Strategic Advisory Services Consultant (Remote)
Sr. Strategic Advisory Services Consultant (Remote)

CrowdStrike, Inc. • Sunnyvale (CA)

Remote
USD 115,000 - 160,000
Competitive compensation
Wellness programs
Vacation and holidays
+5
Cyber Operate Senior Manager- Detect and Respond
Cyber Operate Senior Manager- Detect and Respond

Deloitte France • Chicago (IL)

On-site
USD 163,000 - 322,000
Cyber Operate SOC L2 Analyst - Senior Consultant
Cyber Operate SOC L2 Analyst - Senior Consultant

Deloitte France • San Jose (CA)

On-site
USD 105,000 - 208,000