Sr. Engineer- Product Abuse (remote)

CrowdStrike CrowdStrike · Enterprise · United States · Remote

CrowdStrike is seeking a Sr. Engineer for their Product Abuse team, focusing on defending their AI-native cybersecurity platform against sophisticated adversaries. The role involves leading threat hunting, architecting detection and prevention capabilities, and driving security enhancements. Responsibilities include leading threat hunting operations, designing monitoring solutions, leading incident response, developing automation tooling, conducting security assessments, advocating for product security enhancements, and implementing logging strategies. The role requires 7+ years of cybersecurity experience with a focus on threat hunting, attack mitigation, and tooling, proficiency in security automation, practical experience with cloud security, and deep familiarity with abuse attack patterns. Bonus points for experience with AI coding assistants, LLM tools, data science techniques for threat signals, and SIEM platforms.

What you'd actually do

  1. Lead threat hunting operations against emergent threat activity involving platform misuse — to determine impact and drive resolution
  2. Design and implement monitoring solutions to detect anomalies and potential abuse across external-facing services, APIs, and authentication surfaces
  3. Lead technical aspects of incident response, including attack vector analysis, countermeasure implementation, and post-incident review
  4. Develop automation and purpose-built tooling to streamline detection, mitigation, and reporting workflows
  5. Instrument event-driven tooling to drive hunting efficiency and proactive prevention of evolving TTPs

Skills

Required

  • cybersecurity engineering
  • threat intelligence
  • threat hunting
  • attack mitigation
  • tooling
  • security automation
  • tool development
  • cloud computing platform security services
  • infrastructure protection
  • identity and access management
  • continuous monitoring
  • abuse-relevant attack patterns
  • credential stuffing
  • account takeover
  • API abuse
  • trial fraud
  • adversarial misuse of security tooling
  • security assessments
  • testing simulations
  • external attack surfaces
  • abuse vectors
  • product security enhancements
  • logging strategies
  • cloud-native infrastructure
  • roadmap and strategic planning
  • abuse prevention
  • follow-the-sun operational coverage
  • OSINT
  • cybercrime investigations
  • intelligence collection
  • complex adversarial networks
  • trust and safety
  • fraud detection
  • abuse engineering
  • SaaS
  • cloud platform
  • problem-solving
  • communication skills

Nice to have

  • AI coding assistants
  • LLM-based tools
  • data science techniques
  • machine learning
  • neural networks
  • streaming anomaly detection
  • threat signals
  • behavioral outliers
  • disparate datasets
  • enterprise scale
  • front-end UI design
  • large and complex codebases
  • HTML5
  • JavaScript
  • React
  • SIEM platforms
  • LogScale
  • identity and authentication systems
  • OAuth
  • SAML
  • MFA bypass techniques
  • session abuse patterns
  • network security
  • cloud security
  • logging
  • monitoring
  • threat detection
  • incident response
  • follow-the-sun security operations model
  • CrowdStrike Falcon platform
  • sensor
  • cloud
  • API architecture

What the JD emphasized

  • 7+ years of experience in a cybersecurity engineering or threat intelligence environment, with a significant focus on threat hunting, attack mitigation, and tooling
  • Practical experience with cloud computing platform security services
  • Deep familiarity with abuse-relevant attack patterns including credential stuffing, account takeover, API abuse, trial fraud, and adversarial misuse of security tooling
  • Ability to identify when external-facing services are exceeding baselines and correlate deviations with potential attack indicators
  • Comprehensive understanding of TTPs employed by threat actors and the evolving threat landscape, including nation-state and eCrime actors