ClovisRecruiter Since 2001
the smart solution for Clovis jobs

Detection Engineer - EPP Content (Remote)

Company: CrowdStrike
Location: Reedley
Posted on: May 3, 2021

Job Description:

At CrowdStrike were on a mission - to stop breaches. Our groundbreaking technology, services delivery, and intelligence gathering together with our innovations in machine learning and behavioral-based detection, allow our customers to not only defend themselves, but do so in a future-proof manner. Weve earned numerous honors and top rankings for our technology, organization and people clearly confirming our industry leadership and our special culture driving it. We also offer flexible work arrangements to help our people manage their personal and professional lives in a way that works for them. So if youre ready to work on unrivaled technology where your desire to be part of a collaborative team is met with a laser-focused mission to stop breaches and protect people globally, lets talk. About the Team The EPP Content team is a central part of CrowdStrikes mission - We Stop Breaches." In Content, we research attacker behavior to understand their tools and techniques, and build software to detect and prevent malicious activity. Our goal is to automatically stop the bad guys where possible, and to provide useful visibility and guidance to security analysts when new previously unknown adversary activity occurs. Our detection strategies are often performed directly on the endpoint, and frequently. This ability to leverage a variety of tools across the CrowdStrike stack allows us to accomplish our detection goals while balancing resource utilization and efficacy for our customers. About the Role As a Detection Engineer within the EPP Content team you will be focused on the analysis and development of detections for attack techniques across all operating systems. Youll work collaboratively to implement these detections within the Falcon sensor which is a lightweight kernel-level module that observes system activity, recognizes malicious behavior, provides on-box prevention capability, and sends relevant security related telemetry to the Falcon cloud. Youll help develop creative and resourceful ways to identify gaps and detect threats while leveraging core OS telemetry such as file system, memory, process, and network. Youll collaborate with multiple teams within engineering, and will be expected to make significant contributions to the design and implementation of major development projects. We're looking for smart people who want to be challenged and take ownership of what they build.ResponsibilitiesIdentify gaps in detection capabilities:Understand and track attacker tactics, techniques, and procedures (TTPs) as described in ATT&CK Familiarize with offensive security tools and techniques across platforms Evaluate product detection capabilities by planning and executing attack emulation scenarios Design and build detection logic: Extend our existing codebase and test suites utilizing C++, Python, and other tools as appropriate. Brainstorm, define, and build collaboratively across multiple teams. Build elegant, robust, and reliable solutions for complex technical problems.Collaborate as a team-member:Obsess about learning, and champion the newest technologies & tricks with others, raising the technical IQ of the team. Troubleshoot issues within the product when necessary, assisting customer support. Deliver and accept feedback with grace and courtesy. What Youll Need 5+ years of experience with EITHER one of: Defensive security operations, such as threat intelligence, malware analysis, threat hunting, or detection development; and an interest in threat emulation, or Offensive security operations, such as red-teaming, threat emulation, or offensive capability development; and an interest in detection engineering Team player able to lead, mentor, communicate, collaborate, and work effectively in a globally distributed team. Bonus Points Awarded For Prior experience with threat hunting and/or endpoint detection engineering concepts such as gap analysis, detection tuning, and detection testing (e.g. ATT&CK Evaluations, Caldera, Atomic Red-Team) Prior experience building or operating red-team/pen-test/C2 frameworks (e.g. Metasploit, Cobalt Strike, PoshEmpire, CALDERA, Apfel, Empyre) Low-level OS knowledge and experience with one of more of our supported sensor platforms including Windows, macOS, and Linux. Prior development or testing experience with python. Prior experience delivering software via agile processes. #LI-DG1 #LI-RemoteBenefitsof Working at CrowdStrike: Market leader in compensation and equity awards Competitive vacation policy Comprehensive health benefits + 401k plan Paid parental leave, including adoption Flexible work environment Wellness programs Stocked fridges, coffee, soda, and lots of treats We are committed to building an inclusive culture of belonging that not only embraces the diversity of our people but also reflects the diversity of the communities in which we work and the customers we serve. We know that the happiest and highest performing teams include people with diverse perspectives and ways of solving problems so we strive to attract and retain talent from all backgrounds and create workplaces where everyone feels empowered to bring their full, authentic selves to work. CrowdStrike is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex including sexual orientation and gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law. CrowdStrike participates in the E-Verify program. Notice of E-Verify Participation Right to WorkSDL2017

Keywords: CrowdStrike, Clovis , Detection Engineer - EPP Content (Remote), Other , Reedley, California

Click here to apply!

Didn't find what you're looking for? Search again!

I'm looking for
in category
within


Log In or Create An Account

Get the latest California jobs by following @recnetCA on Twitter!

Clovis RSS job feeds