Incident Response Principal Consultant (Remote)

CrowdStrike Holdings, Inc.

Northern (KY)

Hybrid

USD 115,000 - 160,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Market-leading compensation
Comprehensive wellness programs
Generous vacation & holidays
Parental & adoption leaves
Professional development opportunities
Employee networks & volunteering
Vibrant office culture
Great Place to Work Certified

Job summary

CrowdStrike, Inc. is seeking highly motivated, self-driven incident response consultants who can lead engagements against the world’s most advanced attackers. You’ll develop new hunting methods, conduct intrusion investigations, and deliver high-impact findings to executives and clients.

Ideal candidates bring IR experience, strong leadership, and excellent communication. The role supports remote work and involves travel as needed.

Qualifications

  • Experience leading incident response investigations in a consulting environment.
  • Ability to conduct intrusion investigations and produce written/verbal findings.

Responsibilities

  • Lead incident response engagements for client organizations.
  • Develop and use new methods to hunt for bad actors across large datasets.
  • Work with counsel to conduct intrusion investigations.
  • Perform host and/or network-based forensics on Windows, Mac, and Linux.
  • Perform basic malware analysis.
  • Produce high-quality reports and presentations for stakeholders.
  • Share thought leadership through public content and talks.

Skills

Incident Response
Team leadership
Forensic Analysis
Network Forensics
Reverse Engineering
Threat hunting
Communication
AI-enabled decision making

Education

Bachelor's or Master’s in CS/IS/related

Tools

Bro/Zeek
Suricata

Job description

As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn't changed - we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. We work on large scale distributed systems, processing almost 3 trillion events per day and this traffic is growing daily. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We're proud to work for a mission-driven company leveraging AI to transform the way we work. CrowdStrikers drive their careers through flexibility and autonomy while also being expected to contribute to a culture of responsible AI adoption, experimentation, and innovation. We use an AI-first mindset as a force multiplier to proactively and continuously accelerate execution, build expertise, uncover insights, and solve complex problems. We’re always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you.

About the Role

CrowdStrike is looking for highly motivated, self-driven, technical consultants dedicated to making a difference in global security by protecting organizations against the most advanced attackers in the world. Our CrowdStrike Services team offers opportunities to expand your skill set through a wide variety of engagements including front page incident response investigations for organizations you’ll find on the annual Fortune 100 list.

Am I a Principal Consultant Candidate? Do you find yourself interested in and keeping up with the latest vulnerabilities and breaches? Are you self-motivated and looking for an opportunity to rapidly accelerate your skills? Do you crave new and innovative work that actually matters to your customer? Do you have an Incident Response or Information Security background that you’re not fully utilizing? Are you capable of leading teams and interacting with customers? Do you love working around like-minded, smart people who you can learn from and mentor on a daily basis?

What You'll Do
  • Lead incident response engagements
  • Develop and use new methods to hunt for bad actors across large sets of data
  • Work under the direction of outside counsel to conduct intrusion investigations
  • Perform host and/or network-based forensics across Windows, Mac, and Linux platforms
  • Perform basic malware analysis
  • Produce high-quality written and verbal reports, presentations, recommendations, and findings to key stakeholders including customer management, regulators, and legal counsel
  • Demonstrate industry thought leadership through blog posts, CrowdCasts, and other public speaking events
What You'll Need
  • Successful candidates will have experience in one or more of the following areas: Team leadership experience in a matrixed consulting environment
  • Incident Response: experience conducting or managing incident response investigations for organizations, investigating targeted threats such as the Advanced Persistent Threat, Organized Crime, and Hacktivists
  • Computer Forensic Analysis: a background using a variety of forensic analysis tools in incident response investigations to determine the extent and scope of compromise
  • Network Forensic Analysis: strong knowledge of network protocols, network analysis tools like Bro/Zeek or Suricata, and ability to perform analysis of associated network logs
  • Reverse Engineering: ability to understand the capabilities of static and dynamic malware analysis
  • Incident Remediation: strong understanding of targeted attacks and able to create customized tactical and strategic remediation plans for compromised organizations
  • Network Operations and Architecture/Engineering: strong understanding of secure network architecture and strong background in performing network operations
  • Cloud Incident Response: knowledge in any of the following areas: AWS, Azure, GCP incident response methodologies
  • Communications: strong ability to communicate executive and/or detailed level findings to clients; ability to effectively communicate tasks, guidance, and methodology with internal teams
  • Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes
Additionally, all candidates must possess the following qualifications
  • Capable of completing technical tasks without supervision
  • Desire to grow and expand both technical and soft skills
  • Strong project management skills
  • Contributing thought leader within the incident response industry
  • Ability to foster a positive work environment and attitude
  • Ability to travel on short notice, up to 30% of the time
Education

BA or BS / MA or MS degree in Computer Science, Computer Engineering, Math, Information Security, Information Assurance, Information Security Management, Intelligence Studies, Cybersecurity, Cybersecurity Policy, or a related field. Applicants without a degree but with relevant work experience and/or training will be considered.

#LI-Remote #LI-AC1

This role may require the candidate to periodically undergo and pass alcohol and/or drug test(s) during the course of employment.

Benefits of Working at CrowdStrike
  • Market leader in compensation and equity awards
  • Comprehensive physical and mental wellness programs
  • Competitive vacation and holidays for recharge
  • Paid parental and adoption leaves
  • Professional development opportunities for all employees regardless of level or role
  • Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections
  • Vibrant office culture with world class amenities
  • Great Place to Work Certified across the globe

CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program. CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions--including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs--on valid job requirements.

If you need assistance accessing or reviewing the information on this website or need help submitting an application for employment or requesting an accommodation, please contact us at recruiting@crowdstrike.com for further assistance.

Find out more about your rights as an applicant.

CrowdStrike participates in the E-Verify program.

Notice of E-Verify Participation Right to Work

CrowdStrike, Inc. is committed to fair and equitable compensation practices. Placement within the pay range is dependent on a variety of factors including, but not limited to, relevant work experience, skills, certifications, job level, supervisory status, and location.

The base salary range for this position for all U.S. candidates is $115,000 - $160,000 per year, with eligibility for bonuses, equity grants and a comprehensive benefits package that includes health insurance, 401k and paid time off.

Expected Close Date of Job Posting is: 10-21-2026

CrowdStrike was founded in 2011 to fix a fundamental problem: The sophisticated attacks that were forcing the world’s leading businesses into the headlines could not be solved with existing malware-based defenses. Founder George Kurtz realized that a brand new approach was needed - one that combines the most advanced endpoint protection with expert intelligence to pinpoint the adversaries perpetrating the attacks, not just the malware. There’s much more to the story of how Falcon has redefined endpoint protection but there’s only one thing to remember about CrowdStrike: We stop breaches.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Principal Consultant (Remote)
Incident Response Principal Consultant (Remote)

CrowdStrike Holdings, Inc. • Washington

Hybrid
USD 115,000 - 160,000
Market leader compensation and equity
Comprehensive wellness programs
Generous vacation and holidays
+2
Incident Response Senior Consultant (Remote)
Incident Response Senior Consultant (Remote)

CrowdStrike Holdings, Inc. • Northern (KY)

Hybrid
USD 95,000 - 140,000
Health insurance
401k
Paid time off
+1
Incident Response Senior Consultant (Remote)
Incident Response Senior Consultant (Remote)

CrowdStrike Holdings, Inc. • California (MO)

Hybrid
USD 95,000 - 140,000
Wellness programs
Vacation & holidays
Parental leave
+3
Strategic Advisory Services Consultant (Remote)
Strategic Advisory Services Consultant (Remote)

CrowdStrike Holdings, Inc. • Town of Texas (WI), Northern (KY)

Hybrid
USD 95,000 - 140,000
Professional development
Paid parental leave
Vacation & holidays
+1
Sr. Strategic Advisory Services Consultant (Remote)
Sr. Strategic Advisory Services Consultant (Remote)

CrowdStrike Holdings, Inc. • Northern (KY)

Hybrid
USD 115,000 - 160,000
Market leading compensation
Wellness programs
Paid parental leaves
+1
Analyst I, Falcon Complete (Hybrid, San Antonio)
Analyst I, Falcon Complete (Hybrid, San Antonio)

CrowdStrike Holdings, Inc. • San Antonio (TX)

Hybrid
USD 85,000 - 120,000
Competitive compensation
Wellness programs
Paid time off
+1
Incident Response Senior Consultant (Remote)
Incident Response Senior Consultant (Remote)

Socket.dev • California (MO)

Hybrid
USD 95,000 - 140,000
Market leading compensation and equity
Sr. Engineer, Cloud Native - AI Detection and Response (AIDR) (Hybrid, Sunnyvale)
Sr. Engineer, Cloud Native - AI Detection and Response (AIDR) (Hybrid, Sunnyvale)

CrowdStrike Holdings, Inc. • Sunnyvale (CA)

On-site
USD 140,000 - 215,000
Market compensation
Wellness programs
Paid time off
+3
Incident Response Principal Consultant (Remote)
Incident Response Principal Consultant (Remote)

CrowdStrike • United States

On-site
USD 115,000 - 160,000
Market-leading compensation
Wellness programs
Vacation & holidays
+5
Manager, Corporate Sales Engineering (Remote)
Manager, Corporate Sales Engineering (Remote)

CrowdStrike Holdings, Inc. • Town of Texas (WI), Northern (KY)

Hybrid
USD 135,000 - 205,000
Compensation & equity
Wellness programs
Vacation & holidays
+5