
Senior Analyst, Falcon Complete
Posted 19 hours ago

Posted 19 hours ago
This is a fully remote position, open to applicants in United States.
• Oversee intricate investigations spanning endpoint, identity, email, network, and cloud environments.
• Act as the technical lead for high-severity incidents affecting multiple customers.
• Evaluate EDR telemetry, forensic artifacts, and network data to identify the root cause, attacker TTPs, and the extent of the compromise.
• Examine complex Microsoft 365 attacks, such as BEC and AITM.
• Conduct both static and dynamic malware analyses.
• Create and implement remediation plans for compromised environments.
• Coordinate containment actions on third-party platforms across customer infrastructures.
• Mentor and develop members of the Analyst team.
• Contribute to the creation of training materials, knowledge base content, and team capability enhancement.
• Propel process enhancements, SOP development, and automation efforts.
• Represent CrowdStrike through blog articles, CrowdCasts, and external speaking opportunities.
• Provide expert-level communications to customers and manage technical escalations.
• Serve as a trusted advisor during critical incidents.
• Extensive experience in incident response, information security, or related fields.
• Expert-level proficiency in managing complex incident response investigations from initial triage to remediation.
• Experience in investigating host/user compromises, organized crime groups, and nation-state adversaries.
• In-depth knowledge of threat actor tactics, techniques, and procedures, including MITRE ATT&CK.
• Advanced skills in computer forensic analysis, covering host, memory, and network artifacts.
• Advanced abilities in static and dynamic malware analysis, including reverse engineering principles.
• Expert-level understanding of Windows, Mac, and/or Linux operating systems, with in-depth knowledge in at least one.
• Advanced experience in administering and securing enterprise network environments.
• Expert-level comprehension of network protocols and traffic analysis.
• Profound expertise with Okta, Microsoft Entra ID, and Active Directory.
• Advanced capabilities in investigating and addressing Microsoft 365 security incidents, including BEC and AITM.
• High proficiency in querying and correlating logs within SIEM environments.
• Proven expertise in developing and executing incident remediation plans.
• Expert-level grasp of secure network architecture and troubleshooting within enterprise networks.
• Experience in creating scripts and automation using Python, PowerShell, or Bash.
• Familiarity with AI models, platforms, MCP servers, agentic frameworks, prompt engineering, and AI adoption.
• Ability to independently lead complex technical investigations as a subject matter expert.
• Proven record of mentoring and team development.
• Demonstrated thought leadership within the incident response sector.
• Project management skills with the capacity to complete process improvement initiatives.
• Willingness to work a 4x10 schedule, including one weekend day.
• Must be a US citizen or Green Card holder.
• A BA or BS / MA or MS degree in a relevant technical field is required; however, candidates without a degree but with relevant work experience and/or training will be considered.
• May be required to undergo and pass alcohol and/or drug tests periodically.
• Leading compensation and equity awards in the market.
• Comprehensive programs for physical and mental wellness.
• Competitive vacation and holiday allowances for rejuvenation.
• Paid parental and adoption leave.
• Professional development opportunities available for all employees, regardless of level or role.
• Employee Networks, neighborhood groups, and volunteer opportunities to foster connections.
• Dynamic office culture featuring world-class amenities.
• Health insurance coverage.
• 401k plan.
• Paid time off.
• Eligibility for bonuses.
• Equity grants.
Allied Benefit Systems
Allied Benefit Systems
Municipal Credit Union
Ânima Educação
Get handpicked remote jobs straight to your inbox weekly.