Incident Response Senior Consultant - Weekend Shift (remote)

CrowdStrike CrowdStrike · Enterprise · United States · Remote

This role is for a Senior Incident Response Consultant at CrowdStrike, focusing on cybersecurity investigations. While the company mentions an "AI-native platform", the core responsibilities of this role involve traditional incident response, forensics, and malware analysis, not direct AI/ML model development or deployment. The role requires leading investigations, hunting for threats using data, performing forensic analysis on various platforms, and basic malware analysis. It emphasizes experience in incident response, computer forensics, network forensics, reverse engineering, and remediation. The company's platform may leverage AI, but the consultant's direct work is not centered on building or managing AI models.

What you'd actually do

  1. Lead incident response engagements
  2. Develop and use new methods to hunt for bad actors across large sets of data.
  3. Work under the direction of outside counsel to conduct intrusion investigations
  4. Perform host and/or network-based forensics across Windows, Mac, and Linux platforms.
  5. Perform basic malware analysis.

Skills

Required

  • Team leadership experience in a matrixed consulting environment
  • Incident Response: experience conducting or managing incident response investigations for organizations, investigating targeted threats such as the Advanced Persistent Threat, Organized Crime, and Hacktivists.
  • Computer Forensic Analysis: a background using a variety of forensic analysis tools in incident response investigations to determine the extent and scope of compromise.
  • Network Forensic Analysis: strong knowledge of network protocols, network analysis tools like Bro/Zeek or Suricata, and ability to perform analysis of associated network logs.
  • Reverse Engineering: ability to understand the capabilities of static and dynamic malware analysis.
  • Incident Remediation: strong understanding of targeted attacks and able to create customized tactical and strategic remediation plans for compromised organizations.
  • Network Operations and Architecture/Engineering: strong understanding of secure network architecture and strong background in performing network operations.
  • Cloud Incident Response: knowledge in any of the following areas: AWS, Azure, GCP incident response methodologies.
  • Communications: strong ability to communicate executive and/or detailed level findings to clients; ability to effectively communicate tasks, guidance, and methodology with internal teams
  • Capable of completing technical tasks without supervision.
  • Desire to grow and expand both technical and soft skills.
  • Strong project management skills.
  • Contributing thought leader within the incident response industry.
  • Ability to foster a positive work environment and attitude.
  • Ability to travel on short notice, up to 30% of the time.

Nice to have

  • BA or BS / MA or MS degree in Computer Science, Computer Engineering, Math, Information Security, Information Assurance, Information Security Management, Intelligence Studies, Cybersecurity, Cybersecurity Policy, or a related field.

What the JD emphasized

  • Incident Response
  • Computer Forensic Analysis
  • Network Forensic Analysis
  • Reverse Engineering
  • Incident Remediation
  • Cloud Incident Response