← Back to jobs
CR

Sr. Analyst, Falcon Complete (Remote)

Crowdstrike
USA - Remote Remote Senior Full-time

As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. We work on large scale distributed systems, processing almost 3 trillion events per day and this traffic is growing daily. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We're proud to work for a mission-driven company leveraging AI to transform the way we work. CrowdStrikers drive their careers through flexibility and autonomy while also being expected to contribute to a culture of responsible AI adoption, experimentation, and innovation. We use an AI-first mindset as a force multiplier to proactively and continuously accelerate execution, build expertise, uncover insights, and solve complex problems. We’re always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you.


About the Role:

CrowdStrike is looking for highly motivated, self-driven, technical analysts dedicated to making a difference in global security by protecting organizations against the most advanced attackers in the world. Our CrowdStrike virtual security operations center offers opportunities to expand your skill set through a wide variety of experiences, detecting and responding to incidents as they occur in real-time for our customers.

Am I a Senior Analyst, Endpoint Protection Team Candidate?

  • Do you have a passion for hunting down advanced threats and leading complex incident response investigations from start to finish?

  • Are you self-motivated and ready to take ownership of the most challenging cases your team faces?

  • Do you crave new and innovative work that actually matters to your customer?

  • Do you have an extensive Incident Response or Information Security background and the desire to put it to work at scale?

  • Do you excel at communicating clearly and professionally with customers, including in high-pressure escalation scenarios?

  • Do you love developing others and leaving your team measurably stronger than you found it?

  • Do you have a desire to contribute to the security community through thought leadership, mentoring, and industry engagement?

  • Are you excited about the evolving role of AI in security operations, including AI models, prompt engineering, and agentic SOC workflows?

What You'll Do:

  • Lead complex investigations across endpoint, identity, email, network, and cloud environments, serving as technical lead for high-severity and multi-customer incidents.

  • Conduct advanced analysis of EDR telemetry, forensic artifacts, and network data to determine root cause, attacker TTPs, and full scope of compromise.

  • Investigate sophisticated Microsoft 365 attacks including business email compromise (BEC) and adversary-in-the-middle (AITM), and provide expert-level guidance to customers.

  • Perform advanced review of static and dynamic malware analysis to understand threat behavior, identify indicators of compromise, and inform detection and remediation strategies.

  • Develop and lead strategic and surgical remediation plans for compromised environments, including coordination of third-party platform containment actions across customer infrastructure.

  • Actively mentor and develop Analyst team members, contributing to training materials, knowledge base content, and team capability development.

  • Identify and drive process improvements, contribute to SOP development, and build automation to enhance detection and response capabilities.

  • Represent CrowdStrike through thought leadership activities including blog posts, CrowdCasts, and external speaking engagements.

  • Deliver expert-level customer communications, managing technical escalations and serving as a trusted advisor during critical incidents.

What You'll Need:

Successful candidates will have extensive experience in one or more of the following areas:

  • Incident Handling: expert-level experience leading and managing complex incident response investigations, including the ability to take ownership of high-severity, multi-host, and multi-customer incidents from triage through remediation. Proven experience investigating host/user compromises, organized crime groups, and sophisticated nation-state adversaries.

  • Threat Landscape Awareness: deep expertise in attack vectors, threat actor tactics, techniques, and procedures (TTPs), with advanced proficiency applying and extending MITRE ATT&CK to drive detection improvements and investigation strategies.

  • Computer Forensic Analysis: advanced experience conducting forensic analysis across host, memory, and network artifacts using a broad toolkit to determine full scope and root cause of compromise.

  • Malware Analysis: advanced ability to perform static and dynamic malware analysis, including reverse engineering concepts and behavioral analysis.

  • Operating System Fundamentals: expert-level knowledge of Windows, Mac, and/or Linux operating systems, with particular depth in at least one of these areas.

  • Systems Administration: advanced experience administering and securing enterprise network environments, with strong knowledge of IT architecture, authentication systems, and common attack paths across infrastructure.

  • Network Analysis Fundamentals: expert-level knowledge of network protocols and traffic analysis, with the ability to identify attack patterns, lateral movement, and exfiltration in network data.

  • Identity Platform Awareness: deep expertise with identity and access management platforms such as Okta, Microsoft Entra ID, and Active Directory, including advanced knowledge of identity-based attack techniques and credential abuse patterns.

  • Email Security Awareness: advanced experience investigating and remediating Microsoft 365 security incidents, including sophisticated business email compromise (BEC) and adversary-in-the-middle (AITM) attack chains.

  • Third-Party Log Analysis: advanced proficiency querying and correlating log sources across cloud platforms, network devices, identity providers, and email platforms within a SIEM environment to build detection logic and drive complex investigations.

  • Incident Remediation: proven expertise developing and executing strategic and surgical remediation plans for compromised environments, including complex multi-host and multi-platform scenarios with third-party containment coordination.

  • Network Operations and Architecture/Engineering: expert-level understanding of secure network architecture with advanced hands-on experience navigating and troubleshooting enterprise network environments to support complex incident investigations.

  • Programming/Scripting: experience developing scripts and automation using Python, PowerShell, or Bash to build investigative tooling, automate remediation workflows, and expand detection and response capabilities.

  • AI Platforms:
    Experience working across various AI models, platforms, and tooling including MCP servers and agentic frameworks. Applies AI broadly across security operations — from investigation acceleration and workflow automation to internal capability development, prompt engineering, and driving AI adoption and maturity across the team.

  • Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.

Additionally, all candidates must possess the following qualifications:

  • Capable of leading complex technical investigations independently and serving as a subject matter expert.

  • Actively mentors peers and junior team members, with a demonstrated commitment to team development.

  • Contributing thought leader within the incident response industry.

  • Project management skills with the ability to drive process improvement initiatives to completion.

  • Ability to foster a positive work environment and attitude.

Requirements:

  • Must be willing to work 4x10 schedule, including a day on the weekend.

  • This role is only open to US citizens and Green Card holders.

Education:

BA or BS / MA or MS degree in Computer Science, Computer Engineering, Math, Information Security, Information Assurance, Information Security Management, Intelligence Studies, Cybersecurity, Cybersecurity Policy, or a related field. Applicants without a degree but with relevant work experience and/or training will be considered.


#LI-RC2
#LI-Remote

This role may require the candidate to periodically undergo and pass alcohol and/or drug test(s) during the course of employment.

Benefits of Working at CrowdStrike:

  • Market leader in compensation and equity awards

  • Comprehensive physical and mental wellness programs 

  • Competitive vacation and holidays for recharge  

  • Paid parental and adoption leaves

  • Professional development opportunities for all employees regardless of level or role

  • Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections

  • Vibrant office culture with world class amenities

  • Great Place to Work Certified™ across the globe

CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program.

CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions--including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs--on valid job requirements.

If you need assistance accessing or reviewing the information on this website or need help submitting an application for employment or requesting an accommodation, please contact us at recruiting@crowdstrike.com for further assistance.

Find out more about your rights as an applicant.

CrowdStrike participates in the E-Verify program.

Notice of E-Verify Participation

Right to Work

CrowdStrike, Inc. is committed to fair and equitable compensation practices. Placement within the pay range is dependent on a variety of factors including, but not limited to, relevant work experience, skills, certifications, job level, supervisory status, and location. The base salary range for this position for all U.S. candidates is $125,000 - $180,000 per year, with eligibility for bonuses, equity grants and a comprehensive benefits package that includes health insurance, 401k and paid time off.

For detailed information about the U.S. benefits package, please click here

Expected Close Date of Job Posting is:10-14-2026

More jobs at Crowdstrike

See all Crowdstrike jobs →

Similar roles

Free Access

Subscribe to view full job details

Get unlimited access to job listings, apply links, and weekly curated picks. Plus, learn how Latentra's career placement program can land your next role — we only charge after you're hired.

No spam. Unsubscribe anytime. Learn about our program

Chat with us