Hybrid Windows Threat Detection Engineer II

CrowdStrike

Austin (TX)

Hybrid

USD 100,000 - 145,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Market leading pay
Wellness programs
Vacation & holidays
Parental leave
Professional development

Job summary

CrowdStrike seeks an experienced threat detection professional to analyze intrusions, campaigns, and malware, translating attacker behavior into robust endpoint detections on the Falcon platform.

Hybrid role requiring 2–3 days on-site at one of the posted locations with collaboration across threat intelligence, engineering, and operations teams. A degree or 4+ years of related experience is expected along with EDR tooling proficiency.

Qualifications

  • Must be eligible for CJIS clearance (U.S. citizenship or Green Card/permanent resident status).
  • Bachelor's degree in information security, computer science, or related field — or 4+ years of equivalent hands-on experience in detection engineering, threat analysis, or endpoint security.
  • Experience with endpoint detection platforms, EDR tooling, or detection-driven security workflows.
  • Proficiency in Windows OS internals and APIs (process creation, registry, file system, memory management, authentication subsystems)
  • Experience with behavioral malware analysis, sandboxing, telemetry collection, and detectable behaviors from execution logs or Windows forensics
  • Working knowledge of regular expressions and pattern-based detection authoring
  • Ability to read and understand various programming languages and PowerShell; scripting proficiency in Python for automation and analysis
  • Experience analyzing endpoint telemetry or host-based log data to identify malicious patterns
  • Solid working knowledge of common adversary TTPs and the ability to translate threat intelligence into detection logic
  • Ability to assess cyber threat intelligence, open-source intelligence, or partner reporting for actionable detection opportunities
  • Passion for detection engineering, threat analysis, or security research, with the motivation to keep learning and growing
  • Comfortable using AI-assisted tooling as a daily force multiplier, not just a novelty
  • Energetic self-starter mentality with the ability to take ownership and be accountable for deliverables
  • Clear written and verbal communication skills to drive triage, convey detection rationale, and align cross-functionally with both technical and executive-level stakeholders
  • Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.
  • Comfortable working on call rotation as needed

Responsibilities

  • Analyze emerging threats, campaigns, intrusion data, and malware execution telemetry to identify detectable behaviors and coverage gaps
  • Author and optimize behavioral detection rules (Indicators of Attack) targeting adversary techniques observed on Windows endpoints
  • Query and analyze endpoint telemetry (process execution, file system, registry, memory, authentication events) to validate detection hypotheses and assess coverage
  • Monitor detection precision metrics, investigate false positives, and tune detections to maintain high signal-to-noise ratios
  • Manage detections through a structured lifecycle: development, validation, staged deployment, and production monitoring
  • Collaborate with threat intelligence and incident response teams to prioritize detection development based on active threat campaigns

Skills

Endpoint security
Threat analysis
PowerShell
Python

Education

Bachelor's degree or equivalent 4+ years

Tools

EDR tooling

Job description

CrowdStrike seeks an experienced threat detection professional to analyze intrusions, campaigns, and malware, translating attacker behavior into robust endpoint detections on the Falcon platform.

Hybrid role requiring 2–3 days on-site at one of the posted locations with collaboration across threat intelligence, engineering, and operations teams. A degree or 4+ years of related experience is expected along with EDR tooling proficiency.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Detection Engineer II (Windows) - Hybrid
Threat Detection Engineer II (Windows) - Hybrid

CrowdStrike Holdings, Inc. • New York (NY)

Hybrid
USD 100,000 - 145,000
Equity awards
Health insurance
Paid time off
+2
Windows Threat Detection Engineer – Advanced Endpoint Security
Windows Threat Detection Engineer – Advanced Endpoint Security

CrowdStrike • Redmond (WA)

Hybrid
USD 100,000 - 145,000
Market-leading compensation
Wellness programs
Generous vacation and holidays
+2
Security Engineer: Threat Detection & Response (Hybrid)
Security Engineer: Threat Detection & Response (Hybrid)

Cricket Wireless LLC. • Los Angeles (CA)

Hybrid
USD 80,000 - 100,000
Threat Detection Engineer II - Endpoint Security
Threat Detection Engineer II - Endpoint Security

CrowdStrike Holdings, Inc. • Sunnyvale (CA)

On-site
USD 100,000 - 145,000
Market-leading compensation
Equity awards
Wellness programs
+3
Senior Windows Sensor Engineer - Security Detection (Hybrid)
Senior Windows Sensor Engineer - Security Detection (Hybrid)

CrowdStrike Holdings, Inc. • New York (NY)

Hybrid
USD 140,000 - 215,000
Competitive compensation
Equity awards
Wellness programs
+3
Senior Windows Sensor Engineer — Detection & Protection (Hybrid)
Senior Windows Sensor Engineer — Detection & Protection (Hybrid)

Socket.dev • Redmond (WA)

Hybrid
USD 140,000 - 215,000
Competitive compensation
Wellness programs
Generous vacation
+5
Security Engineer: Threat Detection & IR (Hybrid)
Security Engineer: Threat Detection & IR (Hybrid)

Manatt Health Strategies, LLC • New York (NY)

Hybrid
USD 80,000 - 100,000
Senior Windows Sensor Security Engineer - Threat Detection
Senior Windows Sensor Security Engineer - Threat Detection

CrowdStrike • Sunnyvale (CA)

On-site
USD 180,000 - 230,000
Equity awards
Health insurance
401k
+5
Senior Threat Detection Engineer — Hybrid Role
Senior Threat Detection Engineer — Hybrid Role

3M HEALTHCARE • Scottsdale (AZ)

Hybrid
USD 132,000 - 165,000
Discretionary incentive plan
Benefits
Senior Windows Sensor Engineer: Detection & Security
Senior Windows Sensor Engineer: Detection & Security

CrowdStrike Holdings, Inc. • Redmond (WA)

Hybrid
USD 140,000 - 215,000
Equity awards
Wellness programs
Vacation & holidays
+5