More jobs:
Infrastructure Security; CrowdStrike EDR SME
Job in
Richardson, Dallas County, Texas, 75080, USA
Listed on 2026-07-01
Listing for:
Argyle Infotech
Full Time
position Listed on 2026-07-01
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
Crowd Strike EDR SME - Sr. Architect Level Role
Crowd Strike EDR Admin tasks:
- Crowd Strike EDR Administration:
Custom IOAs, sensor upgrades, policy management, and Endpoint Security / IDP module ownership. - Detection Engineering:
Migrated low fidelity Windows event log detections to high fidelity Crowd Strike IOA and Splunk use cases. - Incident Response & Threat Management:
Endpoint investigation, containment, remediation, and IOC lifecycle management. - Integrations & Automation:
Splunk and SOAR integrations with automated triage and response workflows.
Project: (Crowd Strike EDR Optimization):
- Evaluate existing Crowd Strike EDR detection rules and enhance them for improved coverage, leveraging Splunk telemetry to validate effectiveness.
- Replace low-fidelity Windows Event Log based Detections with Detection Rules built on Custom Crowd Strike IOAs.
- Develop and formalize a comprehensive Crowd Strike operational framework and process model to strengthen EDR governance, tuning, and lifecycle management.
- Analyze Crowd Strike telemetry and provide recommendations for optimizing Splunk log ingestion, with a focus on reducing redundant or low value events.
Key Responsibilities:
- EDR & Crowd Strike Administration:
- Designed, implemented, and maintained Custom Indicator of Attack (IOA) rules to detect advanced adversary techniques aligned with MITRE ATT&CK.
- Managed Crowd Strike Falcon sensor lifecycle, including agent upgrades, version validation, health monitoring, and deployment troubleshooting.
- Administered and optimized Crowd Strike modules including:
Endpoint Security (EPP) Identity Protection (IDP) Threat Intelligence & Prevention Policies. - Performed sensor policy configuration and updates across environments (Prod / Non‑Prod) with controlled rollout and impact analysis.
- Detection Engineering & Use Case Development:
- Migrated low‑fidelity Windows Event Log–based detections (e.g., scheduled tasks, registry persistence, Power Shell abuse) into high‑fidelity Crowd Strike IOA‑based detections.
- Built and maintained Splunk detection use cases leveraging Crowd Strike telemetry, Windows logs, and endpoint signals.
- Tuned detections to reduce false positives while maintaining strong coverage for persistence, execution, lateral movement, and privilege escalation techniques.
- Incident Response & Containment:
- Conducted endpoint investigations using Crowd Strike Falcon console (process trees, command‑line analysis, file activity).
- Executed response and containment actions, including host containment, process termination, file quarantine, and real‑time response (RTR).
- Supported SOC and IR teams during active incidents with endpoint‑level forensic analysis.
- IOC & Threat Intelligence Management:
- Managed IOC ingestion, validation, and lifecycle (hashes, IPs, domains) within Crowd Strike and integrated platforms.
- Correlated IOCs with endpoint telemetry and external threat intelligence feeds to enhance detection coverage.
- Ensured IOC policies were properly scoped to avoid operational impact.
- SOAR, Integrations & Automation:
- Collaborated on SOAR playbook design and execution for automated alert triage, enrichment, and response.
- Integrated Crowd Strike with Splunk SIEM, SOAR platforms, and other security tools for end‑to‑end visibility.
- Automated response workflows for common attack scenarios (malware, suspicious Power Shell, persistence techniques).
Skills & Tools:
- EDR Platforms:
Crowd Strike Falcon (EPP, IDP, IOA, RTR), Cisco AMP - SIEM & SOAR:
Splunk Use case (ES), SOAR platforms (playbook understanding and tuning) - Detection Engineering:
Windows internals, command‑line analysis, persistence mechanisms - Frameworks: MITRE ATT&CK
- Response:
Endpoint containment, remediation, and investigation
Soft Skills:
- Strong analytical and problem-solving skills.
- Excellent communication and documentation abilities.
- Ability to work independently and as part of a team.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×