Security Operations Analyst I – GovCloud Incident Response

CrowdStrike

United States

On-site

USD 85,000 - 120,000

Full time

15 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity awards
Wellness programs
Vacation & holidays
Parental leave
Professional development
Employee networks
Office culture & amenities
Great Place to Work

Job summary

CrowdStrike, a global leader in cybersecurity, seeks a technical analyst to join its security operations center. You will triage, investigate, and respond to detections across endpoints, identity, email, network, and cloud environments, and perform malware analysis to support incident triage.

Ideal candidates bring hands-on incident handling, forensic skills, and experience with SIEM and EDR tools, plus strong communication with customers during incidents.

Qualifications

  • Experience in incident handling across security events and response coordination.
  • Familiarity with MITRE ATT&CK frameworks in active investigations.
  • Hands-on use of forensic analysis tools in investigations.
  • Basic static/dynamic malware analysis abilities.

Responsibilities

  • Triage, investigate, and respond to detections across endpoints, identity, email, network, and cloud.
  • Analyze EDR telemetry, logs, and artifacts to determine root cause and remediation scope.
  • Investigate Microsoft 365 activity including BEC and AITM attacks; contain threats.
  • Perform basic malware analysis to support incident triage.
  • Develop and improve incident detection and countermeasure processes.
  • Deliver clear customer communications as primary incident contact.
  • Produce high-quality written and verbal reports to customers and internal teams.

Skills

Incident Handling
Threat Landscape Awareness
Forensic Analysis
Malware Analysis
OS Fundamentals
Network Analysis
Identity Platform Awareness
Email Security Awareness
Scripting
SIEM

Education

BA/BS or MA/MS in CS/Engineering/InfoSec or related

Tools

Okta
Microsoft Entra ID
Active Directory
SIEM platforms
Forensic tools
EDR tools

Job description

CrowdStrike, a global leader in cybersecurity, seeks a technical analyst to join its security operations center. You will triage, investigate, and respond to detections across endpoints, identity, email, network, and cloud environments, and perform malware analysis to support incident triage.

Ideal candidates bring hands-on incident handling, forensic skills, and experience with SIEM and EDR tools, plus strong communication with customers during incidents.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GovCloud Security Analyst I - Incident Response
GovCloud Security Analyst I - Incident Response

Socket.dev • St. Louis (MO)

On-site
USD 85,000 - 120,000
Compensation & equity
Wellness programs
Vacation & holidays
+5
GovCloud Security Analyst I — Incident Response & AI
GovCloud Security Analyst I — Incident Response & AI

CrowdStrike, Inc. • Sunnyvale (CA)

On-site
USD 85,000 - 120,000
Equity awards
Wellness programs
Vacation and holidays
+3
Junior Incident Response Analyst – Remote
Junior Incident Response Analyst – Remote

CrowdStrike Holdings, Inc. • United States

Remote
USD 60,000 - 90,000
GovCloud Tech Support Engineer — Cyber Defense
GovCloud Tech Support Engineer — Cyber Defense

Socket.dev • North Carolina

Hybrid
USD 70,000 - 110,000
Competitive compensation
Equity opportunities
Health insurance
Incident Response Analyst
Incident Response Analyst

Breeze End Technology, LLC • Alexandria (VA)

On-site
USD 70,000 - 110,000
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)

CrowdStrike, Inc. • Sunnyvale (CA)

On-site
USD 85,000 - 120,000
Equity awards
Wellness programs
Vacation and holidays
+3
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)

CrowdStrike • United States

On-site
USD 85,000 - 120,000
Equity awards
Wellness programs
Vacation & holidays
+5
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)

Socket.dev • St. Louis (MO)

On-site
USD 85,000 - 120,000
Compensation & equity
Wellness programs
Vacation & holidays
+5
GovCloud Technical Support Engineer—AI-Driven Security
GovCloud Technical Support Engineer—AI-Driven Security

CrowdStrike Holdings, Inc. • Northern (KY)

Hybrid
USD 70,000 - 110,000
Health insurance
401k
Paid time off
GovCloud Technical Support Engineer — Cybersecurity Advocate
GovCloud Technical Support Engineer — Cybersecurity Advocate

Relha LLC • Northern (KY)

Hybrid
USD 70,000 - 110,000
Equity awards
Wellness programs
Vacation & holidays
+2