Sr. Threat Response Specialist, Falcon Complete (remote, Aus)

CrowdStrike CrowdStrike · Enterprise · WA, Australia +2 · Remote

CrowdStrike is seeking a Senior Threat Response Specialist for their Falcon Complete MDR team. The role involves staying updated on emerging threats, contributing to detection engineering, providing expert support during incident investigations, educating other teams on threats and best practices, and developing the organizational knowledge base. The role requires experience in response or research, incident handling, threat research, and utilizing cyber threat intelligence. Experience with AI and automation tooling in an operational and intelligence capacity is also required.

What you'd actually do

  1. Emerging Threat Response: Stay up to date on emerging threats and threat actors. Contribute to initiatives to proactively identify, assess, and mitigate new and evolving threat campaigns. Collaborate with CrowdStrike threat intelligence teams to integrate the latest threat data into the Falcon Complete threat response program.
  2. Threat Detection Enablement: Use threat research to fuel the detection engineering team for developing and fine-tuning detection mechanisms on Endpoint, Identity, Cloud, and supported NG-SIEM integrations.
  3. Expert Support: Serve as the go-to expert on emerging threats facing the Falcon Complete team. Collaborate with security analysts during incident investigations into novel threats, providing expert insight and threat knowledge across Endpoint, Identity, Cloud, and supported NG-SIEM technologies.
  4. Knowledge Sharing: Educate and advise security analysts, detection engineers, intelligence analysts, and automation/AI engineers on emerging and topical threats, security solution best practices, and effective response techniques.
  5. Knowledge Base Development: Contribute to efforts to enhance the organizational knowledge base to support Managed Detection and Response. Establish and maintain comprehensive response knowledge artifacts across various security domains and ensure that these are up-to-date with the latest security threats and technological advancements. Collaborate with other teams within the Falcon Complete Security Engineering organization to ensure these are delivered to security analysts in the most effective way possible (e.g. integration with artificial intelligence systems or other existing tooling, wiki based knowledge articles, or used for automation opportunities).

Skills

Required

  • Minimum of 5 years of experience in a response or research focused security role
  • at least 3 years focused on supporting Incident Response, security operations or MDR teams
  • Incident Handling: experience conducting or managing incident response for organizations, investigating targeted threats such as the Advanced Persistent Threat, Organized Crime, and Hacktivists.
  • Threat Research: experience performing threat research to identify and cluster campaigns and emerging threats
  • Incident Remediation: strong understanding of targeted attacks and able to create customized tactical and strategic remediation plans for compromised organizations.
  • Significant experience utilizing cyber threat intelligence in a security operations environment
  • Deep understanding of how attack vectors manifest in EDR and SIEM telemetry/logs and how to investigate them.
  • Knowledge of automation tools and scripting languages (e.g., Python, PowerShell)
  • Experience using AI and automation tooling in an operational and intelligence capacity.

Nice to have

  • AI engineers

What the JD emphasized

  • Minimum of 5 years of experience in a response or research focused security role
  • at least 3 years focused on supporting Incident Response, security operations or MDR teams
  • Experience using AI and automation tooling in an operational and intelligence capacity

Other signals

  • AI-native platform
  • AI and automation tooling
  • AI engineers