Security Operations Lead
EarnestFull Time
Senior (5 to 8 years), Expert & Leadership (9+ years)
Demonstrated experience leading incident investigations from escalation through resolution, leveraging multiple data sources and coordinating with cross-functional teams. Proficiency with EDR platforms (e.g., Falcon), SIEM/SOAR technologies, and network forensics tools (e.g., Zeek, Suricata, Wireshark) to support deep investigations. Advanced investigative skills, including host- and network-level log analysis, endpoint telemetry review, and use of threat intelligence to determine scope and impact.
Develop and deliver scenario-based training exercises for CSIRT to strengthen investigative skills and readiness. Take ownership of projects assigned by CSIRT leadership, implementing improvements that enhance workflows, tools, and response effectiveness. Manage escalated incidents by gathering and analyzing evidence from logs, endpoint telemetry, and threat-intel sources; perform and adapt investigative or containment actions from playbooks—such as host isolation, phishing email removal —and confirm remediation. Conduct in-depth research on topics that support team operations and improve investigative capabilities. Maintain clear documentation of investigative steps, evidence, decisions, and project progress to support transparency and knowledge sharing. Identify gaps in detection coverage, workflows, or tooling, and collaborate on new detection logic, playbook refinements, and automation opportunities. Contribute to the creation and maintenance of runbooks, knowledge articles, and other deliverables that strengthen CSIRT’s incident response capabilities.
Cloud-native endpoint security solutions provider
CrowdStrike specializes in cybersecurity, focusing on protecting businesses from cyber threats through cloud-native endpoint security solutions. Their main product, the Falcon platform, includes services like Falcon Pro, which replaces traditional antivirus with next-generation antivirus that integrates threat intelligence, Falcon Insight for endpoint detection and response, and Falcon Device Control to manage connected devices. Unlike many competitors, CrowdStrike's services are subscription-based, allowing clients to choose different levels of protection based on their needs. The company serves a diverse clientele, including many Fortune 100 companies, and is recognized as a leader in the cybersecurity field, known for its effectiveness in threat detection and response.