Threat Detection Engineer II - Endpoint Security

CrowdStrike Holdings, Inc.

Sunnyvale (CA)

On-site

USD 100,000 - 145,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Market-leading compensation
Equity awards
Wellness programs
Generous vacation and holidays
Parental and adoption leaves
Professional development opportunities

Job summary

CrowdStrike Holdings, Inc. in Sunnyvale is seeking a seasoned detection engineer to analyze intrusions, threat campaigns, and malware, translating attacker behavior into high‑fidelity endpoint detections deployed at global scale.

You will author and optimize behavioral detection rules, query telemetry, and collaborate with threat intel and incident response teams to prioritize development while maintaining high signal‑to‑noise ratios.

Qualifications

  • Bachelor's degree or 4+ years in detection engineering or endpoint security
  • Experience with endpoint detection platforms or EDR tooling
  • Proficiency in Windows OS internals and APIs
  • PowerShell and Python for automation and analysis
  • Read and understand programming languages and scripting
  • Familiar with MITRE ATT&CK adversary tactics and techniques

Responsibilities

  • Analyze emerging threats, campaigns, intrusion data and malware telemetry to identify detectable behaviors
  • Author and optimize behavioral detection rules (IOA) for Windows endpoints
  • Query and analyze endpoint telemetry to validate detection hypotheses
  • Monitor detection precision and tune detections to reduce false positives
  • Manage detections through development, validation, staged deployment and production monitoring
  • Collaborate with threat intel and IR teams to prioritize detection development

Skills

Windows OS internals
PowerShell scripting
Python for automation
Threat analysis
EDR tooling
Telemetry analysis

Education

Bachelor's degree in information security or computer science

Tools

EDR platforms
Sandboxing
Regex tooling
Telemetry collection tooling

Job description

CrowdStrike Holdings, Inc. in Sunnyvale is seeking a seasoned detection engineer to analyze intrusions, threat campaigns, and malware, translating attacker behavior into high‑fidelity endpoint detections deployed at global scale.

You will author and optimize behavioral detection rules, query telemetry, and collaborate with threat intel and incident response teams to prioritize development while maintaining high signal‑to‑noise ratios.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Detection Engineer II (Windows) - Hybrid
Threat Detection Engineer II (Windows) - Hybrid

CrowdStrike Holdings, Inc. • New York (NY)

Hybrid
USD 100,000 - 145,000
Equity awards
Health insurance
Paid time off
+2
GovCloud Security Analyst I — Incident Response & AI
GovCloud Security Analyst I — Incident Response & AI

CrowdStrike, Inc. • Sunnyvale (CA)

On-site
USD 85,000 - 120,000
Equity awards
Wellness programs
Vacation and holidays
+3
Remote Security Engineer: Threat Detection & Automation
Remote Security Engineer: Threat Detection & Automation

CrowdStrike • Town of Texas (WI)

On-site
USD 70,000 - 95,000
Market-leading compensation
Comprehensive wellness programs
Paid time off and holidays
Advanced Cloud Security Research Engineer II
Advanced Cloud Security Research Engineer II

CrowdStrike Holdings, Inc. • Northern (KY)

Hybrid
USD 100,000 - 145,000
Health insurance
401k plan
Paid time off
+1
Remote Associate Security Engineer — Threat Detection
Remote Associate Security Engineer — Threat Detection

Socket.dev • Town of Texas (WI)

Hybrid
USD 70,000 - 95,000
Health insurance
401k
Paid time off
+2
Staff Detection Engineer: SIEM, Cloud & Threat Hunting
Staff Detection Engineer: SIEM, Cloud & Threat Hunting

LinkedIn • Mountain View (CA)

Hybrid
USD 156,000 - 255,000
Health and wellness programs
Annual performance bonus
Stock options
+1
Vulnerability Detection Engineer AI-Driven Security Hybrid
Vulnerability Detection Engineer AI-Driven Security Hybrid

CrowdStrike Holdings, Inc. • Sunnyvale (CA)

Hybrid
USD 100,000 - 145,000
Competitive compensation & equity
Comprehensive wellness programs
Generous vacation & holidays
+1
Sensor Security Engineer - Endpoint Detection & Platform
Sensor Security Engineer - Endpoint Detection & Platform

CrowdStrike Holdings, Inc. • Sunnyvale (CA), Northern (KY)

Hybrid
USD 120,000 - 180,000
Competitive compensation
Health and wellness programs
Paid time off
+2
Senior Threat Detection Engineer – Cloud & Forensics
Senior Threat Detection Engineer – Cloud & Forensics

EngineersOfAI • Northern (KY)

Hybrid
USD 140,000 - 190,000
Engineer II, Threat Detection - Windows (Hybrid)
Engineer II, Threat Detection - Windows (Hybrid)

CrowdStrike Holdings, Inc. • Sunnyvale (CA)

On-site
USD 100,000 - 145,000
Market-leading compensation
Equity awards
Wellness programs
+3