ForgeApply
Try it free

ForgeApply · Job listing

Analyst I, Falcon Complete (Remote, PST/MST)

CrowdStrike

Remote · Remote, United States, US$85k – $120k

Tailor your resume to this posting in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for CrowdStrike's site. Free trial, no card required.

About this role

As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. We work on large scale distributed systems, processing almost 3 trillion events per day and this traffic is growing daily. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We're proud to work for a mission-driven company leveraging AI to transform the way we work. CrowdStrikers drive their careers through flexibility and autonomy while also being expected to contribute to a culture of responsible AI adoption, experimentation, and innovation. We use an AI-first mindset as a force multiplier to proactively and continuously accelerate execution, build expertise, uncover insights, and solve complex problems. We’re always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you.

About the Role: CrowdStrike is looking for highly motivated, self-driven, technical analysts dedicated to making a difference in global security by protecting organizations against the most advanced attackers in the world. Our CrowdStrike virtual security operations center offers opportunities to expand your skill set through a wide variety of experiences, detecting and responding to incidents as they occur in real-time for our customers.

This position is open to candidates in PST and MST time zones.

Am I an Analyst, Endpoint Protection Team Candidate? • Do you find yourself interested in putting your hands-on technical skills to the test in detecting, containing, and remediating incidents? • Are you self-motivated and looking for an opportunity to rapidly accelerate your skills? • Do you crave new and innovative work that actually matters to your customer? • Do you have an Incident Response or Information Security background that you're not fully utilizing? • Do you excel at communicating clearly and professionally with customers and colleagues? • Do you love working around like-minded, smart people who you can learn from and mentor on a daily basis? • Are you excited about the evolving role of AI in security operations, including AI models, prompt engineering, and agentic SOC workflows?

What You'll Do: • Triage, investigate, and respond to security detections across endpoint, identity, email, network, and cloud environments. • Conduct tactical analysis of EDR telemetry, log sources, and forensic artifacts to determine the root cause and scope of compromise, and develop targeted remediation recommendations. • Investigate suspicious Microsoft 365 activity, including business email compromise (BEC) and adversary-in-the-middle (AITM) attacks, contain the threat, and deliver actionable guidance to customers. • Perform basic malware analysis to support investigation and triage of security incidents. • Develop and improve processes for incident detection and the execution of countermeasures. • Deliver clear, concise, and professional customer communications as the primary point of contact during incident response activities. • Produce high-quality written and verbal communications, recommendations, and findings to customers and internally.

What You'll Need : Successful candidates will have experience in one or more of the following areas: • Incident Handling : hands-on experience conducting and coordinating incident response across a broad range of security events, including the ability to manage multiple simultaneous incidents across hosts and customer environments. Experience investigating threats including host/user compromises, network breaches, organized crime, and advanced persistent threats. • Threat Landscape Awareness : strong working knowledge of attack vectors, threat actor tactics, techniques, and procedures (TTPs), with demonstrated experience applying frameworks such as MITRE ATT&CK to active investigations. • Computer Forensic Analysis : hands-on experience using forensic analysis tools in incident response investigations to determine the extent and scope of compromise. • Malware Analysis : demonstrated ability to perform basic static and dynamic malware analysis to understand the nature and behavior of malicious code. • Operating System Fundamentals : strong understanding of Windows, Mac, and/or Linux operating systems with emphasis on Windows internals such as the file system, registry, scheduled tasks, and running processes. • Systems Administration : hands-on experience administering networks and resolving connectivity, authentication, and configuration issues across small to large enterprise environments. • Network Analysis Fundamentals : strong working knowledge of network protocols and analysis tools, with experience analyzing network traffic to support incident investigations. • Identity Platform Awareness : experience working with identity and access management platforms such as Okta, Microsoft Entra ID, Active Directory, and similar enterprise technologies. • Email Security Awareness : experience investigating Microsoft 365 security incidents, including business email compromise (BEC) and adversary-in-the-middle (AITM) attacks. • Third-Party Log Analysis : working knowledge of log sources across cloud platforms, network devices, identity providers, email platforms, and other enterprise technologies, with experience conducting investigation and triage within a SIEM platform. • Incident Remediation : basic understanding of surgical remediation actions needed to contain threats across compromised hosts, including third-party platform containment measures. • Network Operations and Architecture/Engineering

Ready to apply to CrowdStrike?

Tailor my resume for this role

Similar jobs

More like this: More jobs at CrowdStrike · Browse all jobs