Get more replies from employers
Send a job-specific resume in minutes.
CrowdStrike is seeking a Senior Analyst to lead complex investigations across endpoint, identity, email, network and cloud environments. You will guide high-severity incidents, determine root cause, and coordinate remediation with customers and partners.
Ideal candidates have extensive incident response and threat-hunting background, plus strong scripting and automation skills to accelerate detection and response. Join a mission-driven AI-powered security leader.
As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. We work on large scale distributed systems, processing almost 3 trillion events per day and this traffic is growing daily. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We're proud to work for a mission-driven company leveraging AI to transform the way we work. CrowdStrikers drive their careers through flexibility and autonomy while also being expected to contribute to a culture of responsible AI adoption, experimentation, and innovation. We use an AI-first mindset as a force multiplier to proactively and continuously accelerate execution, build expertise, uncover insights, and solve complex problems. We’re always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you.
CrowdStrike is looking for highly motivated, self-driven, technical analysts dedicated to making a difference in global security by protecting organizations against the most advanced attackers in the world. Our CrowdStrike virtual security operations center offers opportunities to expand your skill set through a wide variety of experiences, detecting and responding to incidents as they occur in real time for our customers. Am I a Senior Analyst, Endpoint Protection Team Candidate? Do you have a passion for hunting down advanced threats and leading complex incident response investigations from start to finish? Are you self-motivated and ready to take ownership of the most challenging cases your team faces? Do you crave new and innovative work that actually matters to your customer? Do you have an extensive Incident Response or Information Security background and the desire to put it to work at scale? Do you excel at communicating clearly and professionally with customers, including in high-pressure escalation scenarios? Do you love developing others and leaving your team measurably stronger than you found it? Do you have a desire to contribute to the security community through thought leadership, mentoring, and industry engagement? Are you excited about the evolving role of AI in security operations, including AI models, prompt engineering, and agentic SOC workflows?
Successful candidates will have extensive experience in one or more of the following areas: Incident Handling: expert‑level experience leading and managing complex incident response investigations, including the ability to take ownership of high‑severity, multi‑host, and multi‑customer incidents from triage through remediation. Proven experience investigating host/user compromises, organized crime groups, and sophisticated nation‑state adversaries. Threat Landscape Awareness: deep expertise in attack vectors, threat actor tactics, techniques, and procedures (TTPs), with advanced proficiency applying and extending MITRE ATT&CK to drive detection improvements and investigation strategies. Computer Forensic Analysis: advanced experience conducting forensic analysis across host, memory, and network artifacts using a broad toolkit to determine full scope and root cause of compromise. Malware Analysis: advanced ability to perform static and dynamic malware analysis, including reverse engineering concepts and behavioral analysis. Operating System Fundamentals: expert‑level knowledge of Windows, Mac, and/or Linux operating systems, with particular depth in at least one of these areas. Systems Administration: advanced experience administering and securing enterprise network environments, with strong knowledge of IT architecture, authentication systems, and common attack paths across infrastructure. Network Analysis Fundamentals: expert‑level knowledge of network protocols and traffic analysis, with the ability to identify attack patterns, lateral movement, and exfiltration in network data. Identity Platform Awareness: deep expertise with identity and access management platforms such as Okta, Microsoft Entra ID, and Active Directory, including advanced knowledge of identity‑based attack techniques and credential abuse patterns. Email Security Awareness: advanced experience investigating and remediating Microsoft 365 security incidents, including sophisticated business email compromise (BEC) and adversary‑in‑the‑middle (AITM) attack chains. Third‑Party Log Analysis: advanced proficiency querying and correlating log sources across cloud platforms, network devices, identity providers, and email platforms within a SIEM environment to build detection logic and drive complex investigations. Incident Remediation: proven expertise developing and executing strategic and surgical remediation plans for compromised environments, including complex multi‑host and multi‑platform scenarios with third‑party containment coordination. Network Operations and Architecture/Engineering: expert‑level understanding of secure network architecture with advanced hands‑on experience navigating and troubleshooting enterprise network environments to support complex incident investigations. Programming/Scripting: experience developing scripts and automation using Python, PowerShell, or Bash to build investigative tooling, automate remediation workflows, and expand detection and response capabilities. AI Platforms: Experience working across various AI models, platforms, and tooling including MCP servers and agentic frameworks. Applies AI broadly across security operations — from investigation acceleration and workflow automation to internal capability development, prompt engineering, and driving AI adoption and maturity across the team. Proven experience utilizing AI technologies to enhance decision‑making, streamline workflows and processes, improve efficiency and drive business outcomes.
Must be willing to work 4x10 schedule, including a day on the weekend. This role is only open to US citizens and Green Card holders. Education: BA or BS / MA or MS degree in Computer Science, Computer Engineering, Math, Information Security, Information Assurance, Information Security Management, Intelligence Studies, Cybersecurity, Cybersecurity Policy, or a related field. Applicants without a degree but with relevant work experience and/or training will be considered. The base salary range for this position for all U.S. candidates is $125,000 - $180,000 per year, with eligibility for bonuses, equity grants and a comprehensive benefits package that includes health insurance, 401k and paid time off. For detailed information about the U.S. benefits package, please click here. This role may require the candidate to periodically undergo and pass alcohol and/or drug test(s) during the course of employment.
CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program. CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions--including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs--on valid job requirements.
Notice of E-Verify Participation
CrowdStrike participates in the E-Verify program.