Position Title: Sr. Information Security Engineer (Incident Response) Crowdstrike Falcon
Location: Remote (Work@Home)
Schedule: 6am – 6pm CST (it might be within this range).
Duration: Part-Time (To start)
Company Background:
Our Client is a global leader providing online education, assessment, remediation, certification, and e-learning solutions for the post-secondary academic market, specifically serving the nursing, allied health, sports medicine, public safety, and financial services industries. The Company employs more than 900 employees in 35 states. Our client’s portfolio companies consist of Jones and Bartlett Learning, ATI Nursing Education, the National Healthcare Association, ExamFX, the National Academy of Sports Medicine, Boston Reed, Advanced Informatics, and ClickSafety.
We are looking for a confident person who should not get nervous easily. This is a very critical and technical role; we expect this person to walk in the door and be able to own the management of the CrowdStrike tool and investigate attacks.
Required skills:
- CrowdStrike Falcon EDR tool expert, not just admin. 2 years+ experience performing advanced searches & queries, in-depth understanding of CrowdStrike events and the event data dictionary, IOA customization, playbook creation, AI agent use, and threat hunting in CrowdStrike Falcon.
- Strong experience & skills performing incident triage and investigating attacks, malware, and suspicious activity at a process, command, and code-level
- Strong regex experience
- Strong Windows OS server infrastructure knowledge
- Technology experience 10+ years, 6+ years of information security
- Excellent English communication skills (written, verbal, and comprehension)
- Confident, energetic, driver, leader mentality
- Extremely detail-oriented
- Passionate about information security
- Good Judgement
- Proactivity
- Advanced problem solver
Experience
- Working in a SOC or providing incident support for a security team
- Leading multi-team incident investigations
- Log/protocol analysis, writing RegEx, working with snort rules, YAML, and JSON
- Experience with searches in an EDR like Carbon Black, CrowdStrike Falcon
- Threat hunting in core security tools
Tool Experience
- CrowdStrike Falcon
- Splunk query language
- Regex