Sr. Engineer - Cloud Posture Detection (hybrid)

CrowdStrike CrowdStrike · Enterprise · New York, NY

This role focuses on developing detection rules for cloud security posture management (CSPM) within CrowdStrike's AI-native cybersecurity platform. The engineer will research cloud threats, analyze configurations, and write detection content as code to identify risks and security weaknesses in AWS, Azure, and GCP environments. The role involves data analytics, risk management, and software development using languages like Python or Go.

What you'd actually do

  1. performing research into cloud threats, vulnerabilities, and abuses, to determine configuration best practices that can be used to secure cloud services and assets.
  2. developing and deploying detection rules as code into the FCS product ecosystem
  3. writing descriptions that customers will use to understand and action alerts generated by these rules.
  4. analyzing configurations like multi-factor authentication settings, access controls, encryption policies, and other security posture indicators to create detection content.
  5. researching cloud security issues and developing detection content as code

Skills

Required

  • cloud security-related operations and engineering roles
  • threat detection
  • incident response
  • risk management
  • cloud security posture management (CSPM, DSPM, or similar)
  • data analytics
  • searching large data sets
  • correlating attributes
  • interpreting results
  • extracting insights
  • forming data-driven conclusions
  • searching data with analytics tools including Elastic Search, Splunk, or a SIEM
  • AWS, Azure, GCP, OCI
  • NIST, CISA, CIS, HIPAA, HISTRUST, PCI
  • developing, deploying, and maintaining code in formalized software development/CICD workflows
  • BitBucket
  • Agile methodology
  • Python, Go, Java, C#, or JavaScript
  • author and run Elastic Search queries
  • interpret results from large data sets
  • strong written and verbal communication skills
  • passion for quality
  • experience optimizing results

Nice to have

  • writing detection rules with the Open Policy Agent query language, Rego
  • Detection Engineering
  • Cloud Posture/Content Engineering
  • cloud security posture management platforms or tools (CSPM, DSPM, ASPM, or similar)
  • Formalized training or certification in cloud computing

What the JD emphasized

  • United States Citizenship OR Permanent Residency is necessary to retain access to resources for this role
  • periodically undergo and pass additional background and fingerprint check(s) consistent with government customer requirements