Incident Response Principal Consultant (remote Can)

CrowdStrike CrowdStrike · Enterprise · AB, Canada, Canada · Remote

This role is for a Principal Consultant in Incident Response at CrowdStrike, a cybersecurity company. The consultant will lead incident response engagements, hunt for bad actors, perform forensic analysis on various platforms, conduct basic malware analysis, and produce reports for stakeholders. The role requires strong technical skills in incident response, forensics, network analysis, and potentially reverse engineering or cloud incident response. It emphasizes leadership, communication, and project management within a consulting environment.

What you'd actually do

  1. Lead incident response engagements
  2. Develop and use new methods to hunt for bad actors across large sets of data.
  3. Work under the direction of outside counsel to conduct intrusion investigations
  4. Perform host and/or network-based forensics across Windows, Mac, and Linux platforms.
  5. Perform basic malware analysis.

Skills

Required

  • Team leadership experience in a matrixed consulting environment
  • Incident Response experience
  • Computer Forensic Analysis experience
  • Network Forensic Analysis knowledge
  • Reverse Engineering ability
  • Incident Remediation understanding
  • Network Operations and Architecture/Engineering understanding
  • Cloud Incident Response knowledge (AWS, Azure, GCP)
  • Strong communication skills
  • Technical task completion without supervision
  • Strong project management skills
  • Thought leadership within the incident response industry

Nice to have

  • Experience with Bro/Zeek or Suricata
  • Experience with AWS, Azure, GCP incident response methodologies

What the JD emphasized

  • Incident Response
  • Computer Forensic Analysis
  • Network Forensic Analysis
  • Reverse Engineering
  • Incident Remediation
  • Cloud Incident Response