Sr. Engineer - Cloud Posture Detection (hybrid, Isr)

CrowdStrike CrowdStrike · Enterprise · Tel Aviv, Israel

This role focuses on cloud security detection engineering, researching cloud threats and vulnerabilities, and writing detection rules as code to identify risks and opportunities for improvement within CrowdStrike's cloud security product. It involves data analytics, risk management, software development, and threat research.

What you'd actually do

  1. performing research into cloud threats, vulnerabilities, and abuses, to determine configuration best practices that can be used to secure cloud services and assets.
  2. developing and deploying detection rules as code into the FCS product ecosystem
  3. writing descriptions that customers will use to understand and action alerts generated by these rules.

Skills

Required

  • cloud security-related operations and engineering roles
  • threat detection
  • incident response
  • risk management
  • data analytics
  • searching large data sets
  • correlating attributes
  • interpreting results
  • extracting insights
  • forming data-driven conclusions
  • searching data with analytics tools including Elastic Search, Splunk, or a SIEM
  • AWS, Azure, GCP, OCI
  • industry security standards and control frameworks such as NIST, CISA, CIS, HIPAA, HISTRUST, PCI and others
  • developing, deploying, and maintaining code in formalized software development/CICD workflows including the use of BitBucket to manage code deployments
  • Agile methodology
  • DevOps
  • Python
  • GO
  • author and run Elastic Search queries
  • interpret results from large data sets
  • Proficient in the English language with strong written and verbal communication skills
  • passion for quality and experience optimizing results

Nice to have

  • detection rules with the Open Policy Agent query language, Rego
  • Detection Engineering
  • Formalized training or certification in cloud computing, including administration, development, engineering, or architecture

What the JD emphasized

  • cloud security-related operations and engineering roles
  • threat detection
  • incident response
  • risk management
  • data analytics
  • searching large data sets
  • correlating attributes
  • interpreting results
  • extracting insights
  • forming data-driven conclusions
  • searching data with analytics tools including Elastic Search, Splunk, or a SIEM
  • AWS, Azure, GCP, OCI
  • industry security standards and control frameworks such as NIST, CISA, CIS, HIPAA, HISTRUST, PCI and others
  • developing, deploying, and maintaining code in formalized software development/CICD workflows including the use of BitBucket to manage code deployments
  • Agile methodology
  • DevOps
  • Python
  • GO
  • author and run Elastic Search queries
  • interpret results from large data sets
  • detection rules with the Open Policy Agent query language, Rego
  • Detection Engineering