Windows Threat Detection Engineer – Advanced Endpoint Security

CrowdStrike

Redmond (WA)

Hybrid

USD 100,000 - 145,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Market-leading compensation
Wellness programs
Generous vacation and holidays
Parental and adoption leaves
Professional development

Job summary

CrowdStrike is seeking an experienced professional for the Endpoint Protection Content Response team in the USA. You will analyze intrusions, threat campaigns, and malware, driving robust behavioral detection coverage on the Falcon sensor platform.

Role requires independent work and collaboration with threat intel, engineering, and operations. You will identify detection gaps, take initiative, and work with cross-functional teams to protect customers in a hybrid role requiring 2–3 days on-site.

Qualifications

  • Must be eligible for CJIS clearance (U.S. citizenship or Green Card).
  • Bachelor's degree in information security, computer science, or related field — or 4+ years of equivalent hands-on experience in detection engineering, threat analysis, or endpoint security
  • Experience with endpoint detection platforms, EDR tooling, or detection-driven security workflows
  • Proficiency in Windows OS internals and APIs
  • Experience with behavioral malware analysis, sandboxing, telemetry collection, and detectable behaviors from execution logs or Windows forensics
  • Regular expressions and pattern-based detection authoring
  • Ability to read and understand various programming languages and PowerShell; Python scripting for automation
  • Experience analyzing endpoint telemetry or host-based log data to identify malicious patterns
  • Knowledge of common adversary TTPs and translating threat intel into detection logic
  • Ability to assess cyber threat intel for actionable detection opportunities
  • Passion for detection engineering and learning
  • Comfortable using AI-assisted tooling
  • Self-starter with accountability
  • Clear written and verbal communication for cross-functional alignment
  • Experience utilizing AI technologies to enhance decision-making and workflows
  • Comfortable working on-call rotation

Responsibilities

  • Analyze emerging threats, campaigns, intrusion data, and malware telemetry to identify detectable behaviors and coverage gaps
  • Author and optimize behavioral detection rules (IOA) targeting Windows techniques
  • Query and analyze endpoint telemetry to validate detection hypotheses
  • Monitor detection precision metrics and tune detections to maintain high signal-to-noise
  • Manage detections through development, validation, staged deployment, and production monitoring
  • Collaborate with threat intel and incident response to prioritize detections based on active campaigns

Skills

Windows OS internals
PowerShell
Python
Threat analysis
Endpoint security

Education

Bachelor's degree in information security or computer science

Tools

EDR tooling
Endpoint detection platforms

Job description

CrowdStrike is seeking an experienced professional for the Endpoint Protection Content Response team in the USA. You will analyze intrusions, threat campaigns, and malware, driving robust behavioral detection coverage on the Falcon sensor platform.

Role requires independent work and collaboration with threat intel, engineering, and operations. You will identify detection gaps, take initiative, and work with cross-functional teams to protect customers in a hybrid role requiring 2–3 days on-site.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid Windows Threat Detection Engineer II
Hybrid Windows Threat Detection Engineer II

CrowdStrike • Austin (TX)

Hybrid
USD 100,000 - 145,000
Market leading pay
Wellness programs
Vacation & holidays
+2
Threat Detection Engineer II - Endpoint Security
Threat Detection Engineer II - Endpoint Security

CrowdStrike Holdings, Inc. • Sunnyvale (CA)

On-site
USD 100,000 - 145,000
Market-leading compensation
Equity awards
Wellness programs
+3
Security Engineer: Threat Detection & Response (Hybrid)
Security Engineer: Threat Detection & Response (Hybrid)

Cricket Wireless LLC. • Los Angeles (CA)

Hybrid
USD 80,000 - 100,000
Threat Detection Engineer II (Windows) - Hybrid
Threat Detection Engineer II (Windows) - Hybrid

CrowdStrike Holdings, Inc. • New York (NY)

Hybrid
USD 100,000 - 145,000
Equity awards
Health insurance
Paid time off
+2
Senior Windows Sensor Security Engineer - Threat Detection
Senior Windows Sensor Security Engineer - Threat Detection

CrowdStrike • Sunnyvale (CA)

On-site
USD 180,000 - 230,000
Equity awards
Health insurance
401k
+5
Senior Windows Sensor Engineer — Detection & Protection (Hybrid)
Senior Windows Sensor Engineer — Detection & Protection (Hybrid)

Socket.dev • Redmond (WA)

Hybrid
USD 140,000 - 215,000
Competitive compensation
Wellness programs
Generous vacation
+5
Engineer II, Threat Detection - Windows (Hybrid)
Engineer II, Threat Detection - Windows (Hybrid)

CrowdStrike • Redmond (WA)

Hybrid
USD 100,000 - 145,000
Market-leading compensation
Wellness programs
Generous vacation and holidays
+2
Engineer II, Threat Detection - Windows (Hybrid)
Engineer II, Threat Detection - Windows (Hybrid)

CrowdStrike • Austin (TX)

Hybrid
USD 100,000 - 145,000
Market leading pay
Wellness programs
Vacation & holidays
+2
Senior Windows Sensor Engineer: Detection & Security
Senior Windows Sensor Engineer: Detection & Security

CrowdStrike Holdings, Inc. • Redmond (WA)

Hybrid
USD 140,000 - 215,000
Equity awards
Wellness programs
Vacation & holidays
+5
Senior Windows Sensor Engineer - Security Detection (Hybrid)
Senior Windows Sensor Engineer - Security Detection (Hybrid)

CrowdStrike Holdings, Inc. • New York (NY)

Hybrid
USD 140,000 - 215,000
Competitive compensation
Equity awards
Wellness programs
+3