Endpoint Threat Hunting Consultant (Remote) at Crowdstrike

United States

Crowdstrike Logo
Not SpecifiedCompensation
Mid-level (3 to 4 years), Senior (5 to 8 years)Experience Level
Full TimeJob Type
UnknownVisa
CybersecurityIndustries

Requirements

  • Experience in Threat Hunting: Understanding of Windows and Linux forensic artifacts and analysis methodologies, including program execution, persistence, file system, event logging, process analysis, and anomaly detection
  • Strong threat analysis skills, including hypothesis-driven analysis, IOC searching, long-tail analysis, correlation, pivoting on findings, and timelining threat activity
  • Understanding of targeted attacks, including tradecraft associated with eCrime and nation-state adversaries, and ability to use intelligence for targeted IOC searching
  • Ability to create search queries and write simple scripts in Python or another scripting language
  • Practical understanding of Windows and Linux operating systems, including file systems, registry, memory management, kernel and user-mode functions, identity, and process handling
  • Practical understanding of network protocols and how data is handled at the various layers of the OSI model
  • Familiarity with fundamental identity concepts, including Active Directory and associated protocols like Kerberos
  • Strong ability to communicate analysis findings to clients, including technical and executive audiences, and legal counsel
  • BA or BS / MA or MS degree in Computer Science, Computer Engineering, Math, Information Security, Information Assurance, Information Security Management, Intelligence Studies, Cybersecurity, Cybersecurity Policy, or a related field (applicants without a degree but with relevant work experience and/or training will be considered)
  • Beneficial (not essential): Incident Response experience, especially with large-scale investigations involving e-Crime and nation-state actors; familiarity with cloud platforms (AWS, Azure, GCP); strong understanding of targeted attacks and ability to create customized tactical and strategic remediation plans

Responsibilities

  • Analyze logs and system artifacts looking for evidence of adversary activity in enterprise environments
  • Produce high-quality written and verbal reports, presentations, recommendations, and findings to key stakeholders, including technical audiences, management, and legal counsel
  • Contribute to developing and maturing threat hunting capabilities, including research, methodology, and scripting

Skills

Key technologies and capabilities for this role

Threat HuntingWindows ForensicsLinux ForensicsLog AnalysisSystem ArtifactsProgram ExecutionPersistence AnalysisFile System AnalysisEvent LoggingProcess AnalysisAnomaly DetectionThreat Analysis

Questions & Answers

Common questions about this position

Is this Endpoint Threat Hunting Consultant position remote?

Yes, the position is remote.

What skills are required for the Endpoint Threat Hunting Consultant role?

Required skills include threat hunting with understanding of Windows and Linux forensic artifacts, strong threat analysis skills like hypothesis-driven analysis and IOC searching, threat intelligence on targeted attacks, scripting in Python or similar, platform architecture knowledge of Windows/Linux, networking protocols, identity concepts like Active Directory, and strong communication skills.

What is the salary or compensation for this role?

This information is not specified in the job description.

What is the company culture like at CrowdStrike?

CrowdStrike cultivates a culture that gives every CrowdStriker flexibility and autonomy to own their careers, with a focus on limitless passion, relentless innovation, and commitment to customers, community, and each other.

What makes a strong candidate for this Endpoint Threat Hunting Consultant position?

Highly motivated, self-driven consultants with experience in threat hunting, analysis, intelligence, scripting, platform architecture, networking, identity, and strong communication skills stand out.

Crowdstrike

Cloud-native endpoint security solutions provider

About Crowdstrike

CrowdStrike specializes in cybersecurity, focusing on protecting businesses from cyber threats through cloud-native endpoint security solutions. Their main product, the Falcon platform, includes services like Falcon Pro, which replaces traditional antivirus with next-generation antivirus that integrates threat intelligence, Falcon Insight for endpoint detection and response, and Falcon Device Control to manage connected devices. Unlike many competitors, CrowdStrike's services are subscription-based, allowing clients to choose different levels of protection based on their needs. The company serves a diverse clientele, including many Fortune 100 companies, and is recognized as a leader in the cybersecurity field, known for its effectiveness in threat detection and response.

Austin, TexasHeadquarters
2011Year Founded
$468MTotal Funding
IPOCompany Stage
Enterprise Software, CybersecurityIndustries
5,001-10,000Employees

Benefits

Competitive Employee Stock Purchase Plan
Remote-friendly culture
Market leader in compensation and equity awards
Competitive vacation and flexible working arrangements
Comprehensive health benefits + 401k plan
Paid Parental Leave, including adoption
Wellness programs
Professional development and mentorship opportunities
Open offices have stocked kitchens, coffee, soda and treats

Risks

Increased competition from companies like Lumos could challenge CrowdStrike's market share.
Recovery from last year's outage may still affect customer trust and future sales.
Pressure to demonstrate ROI by 2025 could challenge CrowdStrike's financial transparency.

Differentiation

CrowdStrike's Falcon platform offers cloud-native endpoint security solutions, a key differentiator.
The company serves 44 of the Fortune 100, showcasing its strong market presence.
CrowdStrike's proactive threat hunting sets it apart in cybersecurity threat detection.

Upsides

Partnership with SonicWall opens new SMB market segment for CrowdStrike.
Recognition as a leader in ransomware prevention boosts CrowdStrike's market credibility.
Gamified learning initiatives help address cybersecurity skills gap, benefiting future talent pipeline.

Land your dream remote job 3x faster with AI