$100,000 – $145,000
Listed on CrowdStrike’s own careers site. You apply with them directly — we never stand between you and the employer.
What this role is
This role analyzes emerging threats and malware to build behavioral detection rules that protect CrowdStrike's customers at scale. It suits security engineers who enjoy hands-on threat analysis and can translate attack patterns into detection logic across Windows endpoints.
Our summary, not CrowdStrike’s wording. The full posting is on their site.
Skills this role names
Log in to see which of these are already on your profile.
What they ask for
Required
- U.S. citizenship or permanent resident status eligible for CJIS clearance
- Bachelor's degree in information security, computer science, or related field, or 4+ years equivalent hands-on experience
- Experience with endpoint detection platforms or EDR tooling
- Proficiency in Windows OS internals and APIs
- Experience with behavioral malware analysis and sandboxing
- Knowledge of regular expressions for pattern-based detection
- Ability to read programming languages and PowerShell
- Python scripting for automation and analysis
- Experience analyzing endpoint telemetry to identify malicious patterns
- Knowledge of adversary TTPs and MITRE ATT&CK framework
- Ability to assess threat intelligence for detection opportunities
- Comfortable using AI-assisted tooling
- Self-starter mentality with ownership of deliverables
- Clear written and verbal communication skills
- Experience using AI technologies to enhance workflows
- Comfortable with on-call rotation
Nice to have
- Experience writing behavioral detection rules or signatures for endpoint security products
- Regex optimization and pattern matching experience
- Knowledge of detection precision concepts and false positive analysis
- Experience with detection content lifecycle management
- Understanding of behavioral detection paradigms and living-off-the-land techniques
- Experience in a security operations center
- Experience building test environments and lab automation
- Familiarity with agentic AI CLIs for detection engineering
- Open-source contributions or published security research