Job overview
Complete role details
Location
Hyderabad
Employment type
Other
Workplace
Onsite
Seniority
Individual Contributor
Skills
Role details
Job description
Job Description
• Manage and administer the CrowdStrike Falcon platform, including day-to-day operational activities, policy management, and security configurations.
• Configure, implement, and maintain CrowdStrike Prevention Policies, Sensor Update Policies, and endpoint protection controls to strengthen the organization's security posture.
• Design and implement custom detection rules, endpoint detection policies, and threat-hunting use cases to enhance detection coverage and security visibility.
• Support and maintain CrowdStrike-SIEM integrations, including log forwarding and security monitoring integrations with Splunk.
• Continuously monitor CrowdStrike detections and collaborate with the L2 SOC team during threat investigations, incident analysis, containment, and remediation activities.
• Develop and maintain custom queries, filters, detection rules, active channels, dashboards, and reporting solutions to improve monitoring and operational efficiency.
• Apply security frameworks and methodologies aligned with MITRE ATT&CK, incident response best practices, and modern detection engineering principles to strengthen threat detection and response capabilities.
• Utilize CrowdStrike Query Language (CQL) for advanced threat hunting, security analytics, custom detections, and operational reporting.
• Perform endpoint security assessments, policy reviews, and security optimization activities to improve preventive and detective security controls.
• Conduct adversary simulation/ SafeBreach security validation exercises to assess security control effectiveness, identify detection gaps, and provide remediation recommendations to relevant infrastructure and security teams.
• Work closely with cross-functional teams, including SOC, Infrastructure, Cloud, and Application teams, to implement security enhancements and address identified risks.
• Contribute to security governance activities, including change management, detection tuning, false-positive reduction, and continuous security improvement initiatives.
͏
Areas of responsibility
Monitoring and Incident Detection-Analyse attack trends and correlate logs across systems to identify advance threats. Enhance monitoring processes and implement improvements for faster detection, to ensure compliance with security frameworks and regulatory standards.
Incident Handling and Analysis-Perform root cause analysis, create incident response plans and implement disaster recovery measures to minimize business disruption
Threat Assessment and Analytics-Undertake forensic analysis using advanced analytics tools and implement mitigation measures to align with compliance requirements.
Stakeholder Coordination and Audit Assistance-"Liaise with cross functional teams, external vendors and auditors to ensure compliance with security frameworks.
Maintain audit documentation and ensure its accuracy while implementing processes that support audit readiness and continuous compliance."
Training and Awareness-Assist in creating and delivering cybersecurity awareness sessions, including guidance on phishing and malicious emails.
