Incident Response Analyst
About CrowdStrike
CrowdStrike is the leader in cloud-delivered next-generation endpoint protection, threat intelligence, and pre- and post-incident response services. With the ability to collect and process over 100 billion events a day, CrowdStrike has revolutionized endpoint protection by being the first and only company to unify next-generation antivirus (AV), endpoint detection and response (EDR), and a 24/7 managed hunting service — all delivered via a single lightweight agent. We are one of the World's Most 50 Innovative Companies according to MIT, and one of Forbes Most Promising Companies. Our growth and innovation are driven by incredible employees who deliver unmatched customer success.
We have received a number of exciting awards including:
- October 2018: 100 Best Medium Workplaces Second Year in a Row by Fortune magazine.
- June 2018: Closed over $200 million, led by General Atlantic, Accel and IVP, with participation from March Capital and CapitalG (Google), achieving a valuation of more than $3 billion.
- April 2018: CrowdStrike Wins SC Award for Best Security Company Second Year in a Row.
Essential Duties and Responsibilities
- Develop detection patterns across a broad range of technologies and log sources.
- Triage detections and provide follow-up actions to mitigate risk (e.g. containment, incident.
- response, live response, etc).
- Identify coverage and efficiency gaps in security data and tooling.
- Provide information security reporting including security metrics as required.
- Participate in incident response and manage escalations as needed.
- Provide after-hours support on an on-demand basis.
- Drive efficient process development and documentation for all aspects of the detection and incident response lifecycle.
Key Qualifications
Required
- Experience responding to security events, including front-line analysis and escalation, on hacktivist, cybercrime, and APT activity
- Extensive theoretical and practical knowledge with OSX, Linux, and Windows operating systems
- Extensive theoretical and practical knowledge with TCP/IP networking and application layers
- Experience with system/application log analysis, IDS/IPS alerting and data flow, and SIEM-based workflows
- Experience with security data collection, processing, and correlatio
Preferred
- Scripting experience highly desirable (Python, Perl, Bash, Power Shell, etc.)
- Experienced user of Splunk
- Experience with host and network forensics
- Experience with malware analysis
Education
- Undergraduate degree or direct experience in information security, information systems, or computer science
- Other technical security certifications or academic background a plus
- US Citizenship required due to direct work related to GovCloud
Benefits of Working at CrowdStrike:
- Market leader in compensation and equity awards
- Competitive vacation policy
- Comprehensive health benefits + 401k plan (US only)
- Paid paternity and maternity leave, including adoption
- Flexible work hours and remote friendly environment
- Wellness programs
- Stocked fridges, coffee, soda, and lots of treats
- Peer recognition
- Inclusive culture focused on people, customers and innovation
- Regular team activities, including happy hours, community service events
CrowdStrike believes that diversity and inclusion among our organization is essential to our success as a global company, and we seek to attract, retain and empower the industry’s best and brightest from a diverse talent pool.
CrowdStrike is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex including sexual orientation and gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.