Job Description
Job Description
We are seeking a highly experienced Senior Detection Engineer to lead the development and optimization of advanced threat detection and response capabilities.
This role requires deep expertise in CrowdStrike Falcon Endpoint, Next-Gen SIEM, CS Identity Protection (IDP), FUSION, SOAR platforms, and cloud security.
The ideal candidate will serve as the subject matter expert (SME) for the entire CrowdStrike ecosystem, including sensor deployment, troubleshooting, automation, and query development.
Key Responsibilities
- Develop and maintain high-fidelity detection rules using CrowdStrike Falcon, Next-Gen SIEM, and FUSION.
- Leverage CS IDP to detect identity-based threats and lateral movement.
- Write and optimize queries using CrowdStrike Query Language (FQL/CQL) for threat hunting and detection validation.
- Build and tune detections for cloud environments (AWS, Azure, GCP) and integrate with cloud-native logging tools.
- Function as the primary SME for CrowdStrike, including Falcon, IDP, FUSION, and related modules.
- Troubleshoot and resolve sensor deployment issues, agent health problems, and telemetry gaps.
- Serve as the escalation point for CrowdStrike-related errors, automation failures, and detection tuning.
- Design and implement automated response playbooks using SOAR platforms to reduce dwell time and automate/streamline triage.
- Conduct threat modeling for enterprise systems, cloud platforms, and business-critical applications.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day.
We are an equal opportunity/affirmative action employer that believes everyone matters.
Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances.
If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Skills and Requirements
- 5+ years in detection engineering, threat hunting, or security operations.
- Deep expertise with CrowdStrike Falcon Endpoint, Next-Gen SIEM, CS IDP, FUSION, and SOAR platforms.
- Strong experience with cloud security (AWS, Azure).
- Proficiency in CrowdStrike Query Language (FQL/CQL) and scripting (Python, PowerShell).
- Proven ability to troubleshoot CrowdStrike sensor issues, agent health, and platform integration.
- Familiarity with MITRE ATT&CK, NIST 800-53, and modern detection frameworks.
- Expertise in CRBL and/or CRBL-like data optimization tools - CrowdStrike certifications (e.g., CCFA, CCFH)
- Experience with threat intelligence platforms and adversary emulation.
- Familiarity with CI/CD pipelines, detection-as-code, and infrastructure-as-code practices.