Overview In this role you help clients strengthen cyber resilience by designing and optimizing Next-Gen SOC capabilities built on the CrowdStrike Falcon platform. You will lead implementations, integrate data sources, and tune detection content to enable proactive threat detection. You'll work closely with SOC analysts to mature security operations and automate response playbooks. This opportunity lets you shape enterprise security outcomes at scale within a renowned consulting practice.
Compensation / Benefits- discretionary annual incentive program
- travel up to 50%
- immigration sponsorship may be available
Responsibilities- Design and implement Falcon Next-Gen SIEM architectures with log onboarding, data normalization, enrichment, and correlation rules
- Deploy log-ingestion pipelines using data fabric tech and API integrations (e.g., Cribl, Tines)
- Administer and optimize the CrowdStrike Falcon platform across Windows, macOS, and Linux environments
- Collaborate with SOC analysts to develop and tune Falcon threat-detection content and IOAs
- Build and maintain Falcon Fusion SOAR playbooks and integrations to automate alerts, triage, and response
- Advise clients on SOC maturity and platform capabilities
Key requirements- Bachelor's degree in computer science, cybersecurity, information systems, or equivalent experience
- 5+ years in security operations, threat detection engineering, or enterprise IT security
- 3+ years hands-on experience with CrowdStrike Falcon (including NG-SIEM, EDR/XDR, SOAR, Identity Protection, Intelligence, Charlotte AI)
- Experience with detection and response activities and MITRE ATT&CK/Cyber Kill Chain
- Proficiency in Python or other scripting language for automation
- Ability to travel up to 50%
- Limited immigration sponsorship may be available
- Independent work ethic
- Strong written and verbal communication
- Meticulous attention to detail
- CrowdStrike Falcon architecture and administration
- Falcon Next-Gen SIEM, EDR/XDR, SOAR, Identity Protection, Intelligence, Charlotte AI
- Sensor deployment, policy configuration, host grouping, exclusions, response actions