×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Infrastructure Security; CrowdStrike EDR SME

Job in Richardson, Dallas County, Texas, 75080, USA
Listing for: Argyle Infotech
Full Time position
Listed on 2026-07-01
Job specializations:
  • IT/Tech
    Cybersecurity
Job Description & How to Apply Below
Position: Infrastructure Security (CrowdStrike EDR SME)

Crowd Strike EDR SME - Sr. Architect Level Role

Crowd Strike EDR Admin tasks:

  • Crowd Strike EDR Administration:
    Custom IOAs, sensor upgrades, policy management, and Endpoint Security / IDP module ownership.
  • Detection Engineering:
    Migrated low fidelity Windows event log detections to high fidelity Crowd Strike IOA and Splunk use cases.
  • Incident Response & Threat Management:
    Endpoint investigation, containment, remediation, and IOC lifecycle management.
  • Integrations & Automation:
    Splunk and SOAR integrations with automated triage and response workflows.

Project: (Crowd Strike EDR Optimization):

  • Evaluate existing Crowd Strike EDR detection rules and enhance them for improved coverage, leveraging Splunk telemetry to validate effectiveness.
  • Replace low-fidelity Windows Event Log based Detections with Detection Rules built on Custom Crowd Strike IOAs.
  • Develop and formalize a comprehensive Crowd Strike operational framework and process model to strengthen EDR governance, tuning, and lifecycle management.
  • Analyze Crowd Strike telemetry and provide recommendations for optimizing Splunk log ingestion, with a focus on reducing redundant or low value events.

Key Responsibilities:

  • EDR & Crowd Strike Administration:
    • Designed, implemented, and maintained Custom Indicator of Attack (IOA) rules to detect advanced adversary techniques aligned with MITRE ATT&CK.
    • Managed Crowd Strike Falcon sensor lifecycle, including agent upgrades, version validation, health monitoring, and deployment troubleshooting.
    • Administered and optimized Crowd Strike modules including:
      Endpoint Security (EPP) Identity Protection (IDP) Threat Intelligence & Prevention Policies.
    • Performed sensor policy configuration and updates across environments (Prod / Non‑Prod) with controlled rollout and impact analysis.
  • Detection Engineering & Use Case Development:
    • Migrated low‑fidelity Windows Event Log–based detections (e.g., scheduled tasks, registry persistence, Power Shell abuse) into high‑fidelity Crowd Strike IOA‑based detections.
    • Built and maintained Splunk detection use cases leveraging Crowd Strike telemetry, Windows logs, and endpoint signals.
    • Tuned detections to reduce false positives while maintaining strong coverage for persistence, execution, lateral movement, and privilege escalation techniques.
  • Incident Response & Containment:
    • Conducted endpoint investigations using Crowd Strike Falcon console (process trees, command‑line analysis, file activity).
    • Executed response and containment actions, including host containment, process termination, file quarantine, and real‑time response (RTR).
    • Supported SOC and IR teams during active incidents with endpoint‑level forensic analysis.
  • IOC & Threat Intelligence Management:
    • Managed IOC ingestion, validation, and lifecycle (hashes, IPs, domains) within Crowd Strike and integrated platforms.
    • Correlated IOCs with endpoint telemetry and external threat intelligence feeds to enhance detection coverage.
    • Ensured IOC policies were properly scoped to avoid operational impact.
  • SOAR, Integrations & Automation:
    • Collaborated on SOAR playbook design and execution for automated alert triage, enrichment, and response.
    • Integrated Crowd Strike with Splunk SIEM, SOAR platforms, and other security tools for end‑to‑end visibility.
    • Automated response workflows for common attack scenarios (malware, suspicious Power Shell, persistence techniques).

Skills & Tools:

  • EDR Platforms:
    Crowd Strike Falcon (EPP, IDP, IOA, RTR), Cisco AMP
  • SIEM & SOAR:
    Splunk Use case (ES), SOAR platforms (playbook understanding and tuning)
  • Detection Engineering:
    Windows internals, command‑line analysis, persistence mechanisms
  • Frameworks: MITRE ATT&CK
  • Response:
    Endpoint containment, remediation, and investigation

Soft Skills:

  • Strong analytical and problem-solving skills.
  • Excellent communication and documentation abilities.
  • Ability to work independently and as part of a team.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary