Position Overview:We are seeking an experienced
Cybersecurity Engineer to build and operate our detection and security monitoring capability on the CrowdStrike Falcon platform. This engineer will own the onboarding of new log sources, the authoring and tuning of detection content, and the day-to-day security telemetry that keeps a fast-moving defense engineering organization protected. Working closely with IT and engineering, this individual will translate raw log data into reliable, low-noise detections and help the company mature toward a defensible, compliance-ready security posture. The ideal candidate is comfortable operating independently, thinks like both a defender and an attacker, and can turn ambiguous telemetry into actionable detection logic.
What You'll Do:- Implement, configure, and operate CrowdStrike Falcon Next-Gen SIEM as the organization's core detection and monitoring platform.
- Author, tune, and maintain CQL searches, correlation rules, and dashboards to support detection and investigation.
- Onboard new log sources, including connectors, data pipelines, and third-party source integrations.
- Parse and normalize incoming telemetry against the CrowdStrike Parsing Standard or ECS.
- Write, tune, and maintain detection rules on production content, driving down false positives without sacrificing coverage.
- Operate across Falcon's EDR, identity, and cloud telemetry to build a complete picture of the environment.
- Partner with IT and engineering to close detection gaps and improve the organization's overall security posture.
What You'll Need:- Experience: 3-5+ years in security engineering, detection engineering, or SOC operations.
- Hands-on production experience implementing, configuring, and operating CrowdStrike Falcon Next-Gen SIEM.
- CQL proficiency - searches, correlation rules, and dashboards.
- Demonstrated log onboarding - connectors, data pipelines, third-party source integration.
- Parsing and normalization against the CrowdStrike Parsing Standard or ECS.
- Proven detection rule authoring, tuning, and false-positive reduction on production content.
- Falcon platform fluency across EDR, identity, and cloud telemetry.
You'll Stand Out:- CrowdStrike certifications - CCSE, CCSA, CCFA, CCFH.
- Detection-as-code practice using Git and CI/CD.
- Falcon Fusion SOAR development, or Tines, Torq, XSOAR.
- Cloud security - AWS, Azure, GCP logging, CSPM, Kubernetes.
- Threat hunting or purple team background.
- Defense compliance - CMMC, NIST 800-171, FedRAMP.
What We Offer:- Competitive salary
- ACS Equity Package
- Health, Dental, Vision Insurance
- Paid Time Off