Source description
About the role
Job Summary
We are looking for a skilled CrowdStrike Engineer to manage and optimise the CrowdStrike Falcon platform, including EDR, platform administration, SOAR automation using Fusion, and vulnerability / exposure management. The role involves endpoint security operations, detection and response, automation, reporting, and remediation coordination in an enterprise SOC environment.
Key Responsibilities
- CrowdStrike EDR Operations
Monitor and triage security alerts from CrowdStrike EDR, including malware, suspicious activity, lateral movement, and behavioural detections.
Perform endpoint-level investigation using process tree analysis, file hash review, user activity, command-line details, and related telemetry.
Execute approved response actions such as host isolation, indicator blocking, process termination, and escalation to L2/L3 teams.
Conduct threat hunting and support incident investigation using MITRE ATT&CK aligned analysis.
Coordinate with MDR / Falcon Complete teams
- CrowdStrike Platform Administration
Manage Falcon console administration including tenant hygiene, host groups, policies, sensor grouping logic, RBAC and role assignments.
Monitor endpoint and mobile sensor coverage, sensor health, policy compliance and operational gaps.
Validate platform integrations with Entra ID / Active Directory, ServiceNow, SIEM / NG-SIEM, and other agreed security tools.
Perform platform configuration reviews, policy validation, operational reporting, and controlled change execution.
Maintain documentation, SOPs, knowledge articles, evidence exports and ServiceNow ticket traceability.
- CrowdStrike Fusion / SOAR Automation
Design and maintain Fusion SOAR playbooks for SOC automation, alert enrichment, incident assignment, ticket creation and response orchestration.
Automate repetitive SOC tasks to improve consistency, reduce manual effort and accelerate detection-to-response timelines.
Integrate SOAR workflows with ITSM processes and relevant security tools.
Review automation outcomes, false positives, failure conditions and exception handling to improve playbook maturity.
Support reporting on automation adoption, rule coverage and response efficiency.
- Vulnerability & Exposure Management
Analyse vulnerability and exposure findings from CrowdStrike Spotlight / Exposure Management.
Prioritise remediation based on severity, exploitability, asset criticality, internet exposure and business risk.
Coordinate with infrastructure, application and resolver teams for patching, mitigation, exceptions and revalidation.
Track vulnerability ageing, remediation SLA adherence, exception status and risk acceptance documentation.
Prepare vulnerability assessment, remediation, rescan and executive summary reports.
Required Skills & Experience
Technical Skills
Hands-on experience with CrowdStrike Falcon EDR is mandatory.
Good understanding of Falcon platform administration, host groups, policies, sensor health, RBAC and console hygiene.
Experience or strong working knowledge of CrowdStrike Fusion / SOAR automation and incident response workflows.
Working knowledge of CrowdStrike Spotlight / Exposure Management, vulnerability prioritisation and remediation tracking.
Strong understanding of endpoint security, Windows / Linux endpoint internals, threat hunting and incident response.
Good knowledge of MITRE ATT&CK, IOC analysis, malware triage, PowerShell / command-line investigation and log analysis.
Familiarity with SIEM / NG-SIEM, ServiceNow, Entra ID / AD integrations and reporting dashboards.
Scripting knowledge in PowerShell or Python will be an advantage.
Behavioural / Soft Skills
Strong analytical and investigative mindset.
Ability to handle high-severity incidents under pressure.
Clear written and verbal communication for stakeholder updates and escalation handling.
Good documentation, reporting and process adherence skills.
Ability to work collaboratively with SOC, infrastructure, application and customer teams.
Preferred Certifications
CrowdStrike Falcon certifications / CrowdStrike University training for EDR L1, L2 or L3.
Security+, CySA+, CEH, SC-200 or equivalent SOC / IR certification.
ITIL Foundation or experience working with ITSM processes.
More at PeopleLogic Business Solutions
Related open roles
IT/OT Network
Bangalore · Hybrid
Infra & Cloud Security Engineer
Mumbai · Hybrid
Data Protection & Certificate Services Analyst (DLP)
Bangalore · Hybrid
Cyber Security Analyst (Threat Intelligence)
Hyderabad · Onsite
Application Security / SAST / DevSecOps
Bangalore · Hybrid
Okta (Implementation and integration)
Bangalore · Hybrid