Senior Security Engineer - Crowdstrike
See all open roles at mosaic451 →
Likely real
- 32 open roles at this company in 30 days (mass-hiring blitz)
See your fit for this role and apply with a truthfully tailored résumé.
About the role
What You'll Do:
Lead cross-tool security engineering efforts, advising on best practices for closing detection and reporting gaps that span multiple platforms
Diagnose and resolve reporting and visibility gaps created when a tool in the environment is deprecated, replaced, or reconfigured — for example, reconstructing lost reporting coverage by combining endpoint telemetry with Splunk data
Design, implement, and document data flows and integration points across endpoint protection, SIEM, and other security tools supporting the program
Build and tune detection logic, correlation searches, and dashboards that hold up as individual tools in the stack change, are replaced, or are retired
Lead the technical transition work when a security tool is deprecated, replaced, or reconfigured, ensuring no loss of detection or reporting coverage
Integrate tools such as CrowdStrike, Splunk, Cribl, CyberArk, Suricata, Tenable, Tanium, Thales, CASB, Trellix, Axonius, and others to close cross-platform visibility gaps
Develop automation and correlation workflows using APIs across the security tool stack to reduce manual reporting and analysis work
Support threat hunting and incident response efforts that require correlating evidence across more than one tool or data source
Support endpoint and platform security compliance with NIST, FISMA, and agency-specific requirements
Maintain current, accurate documentation of tool configurations, data flows, and integration architecture across the stack
Serve as the team's point of contact for cross-tool security engineering issues
What You've Done:
Ability to attain DHS EOD
Master's degree or equivalent, plus 12 years of relevant experience
Demonstrated, hands-on experience across more than one security tool category (endpoint/EDR, SIEM, vulnerability management, network detection, or similar)
Hands-on experience with an EDR/endpoint platform (e.g., CrowdStrike Falcon) — administration, detection engineering, or response
Hands-on experience with Splunk (or an equivalent SIEM) — search, correlation searches, and dashboard/reporting development
Demonstrated experience correlating and integrating data across disparate security platforms to close a visibility, detection, or reporting gap
Scripting/automation proficiency (Python, PowerShell, or similar) for cross-tool data pipelines and API integrations
Experience owning a tool deprecation or migration without losing detection or reporting coverage
Effective communicator at all levels, both written and verbal
Professional, customer-oriented, and even-keeled under pressure
Preferred Qualifications:
Experience supporting federal agency security operations centers
Additional security certifications (CISSP, GIAC, Security+)
Experience with CrowdStrike's cloud workload protection capabilities
Knowledge of CISA directives and CDM program requirements
Background in threat hunting and advanced persistent threat detection
Experience with security orchestration and automation platforms
Familiarity with Zero Trust Architecture implementation
Work Environment:
Hybrid work model with 3 day/week on-site presence near National Harbor, Maryland
Must be able to pass a Federal background investigation - US Citizenship required
Participation in on-call rotation for security incident response
What We Offer:
401(k), including an employer match of 100% of the first 3% contributed and 50% of the next 2% contributed
Medical, Dental, and Vision Insurance (available on the 1st day of the month following your first day of employment)
Group Term Life, Short-Term Disability, Long-Term Disability
Voluntary Life, Hospital Indemnity, Accident, and/or Critical Illness
Participation in the Discretionary Time Off (DTO) Program
11 Paid Holidays Annually
Stop applying to ghosts.
OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.
Do more with OyaPilot