Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
CrowdStrike

Engineer II, Threat Detection – Windows

CrowdStrike

Engineer II, Threat Detection analyzing threats and optimizing behavioral detection rules for CrowdStrike's AI-native platform. Collaborating with various teams to enhance detection capabilities.

Posted 7/10/2026full-timeSunnyvale • California, New York, Texas, Washington • 🇺🇸 United StatesMid-LevelSenior💰 $100,000 - $145,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in behavioral detection rule authoring, endpoint telemetry analysis, and threat intelligence integration to enhance security measures. Proficient in Windows OS internals and scripting for automation, with a strong focus on maintaining detection precision and managing detection lifecycles.

Highest-signal resume keywords
Behavioral Detection Rule AuthoringEndpoint Telemetry AnalysisWindows OS InternalsScripting Proficiency in PythonCJIS Clearance Eligibility

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Behavioral Malware AnalysisDetection EngineeringTelemetry CollectionRegular ExpressionsPowerShell ScriptingMalicious Pattern IdentificationAdversary TTPs KnowledgeDetection Logic TranslationExecution Log AnalysisEndpoint Detection Platforms
Soft Skills
Clear Communication SkillsEnergetic Self-Starter MentalityOwnership and Accountability
Tools & Technologies
EDR ToolingDetection-Driven Security WorkflowsAI Technologies
Industry Keywords
Cyber Threat IntelligenceOpen-Source IntelligenceWindows ForensicsIncident ResponseThreat Analysis

Tech Stack

Tools & technologies
Python

About the role

Key responsibilities & impact
  • Analyze emerging threats, campaigns, intrusion data, and malware execution telemetry to identify detectable behaviors and coverage gaps
  • Author and optimize behavioral detection rules (Indicators of Attack) targeting adversary techniques observed on Windows endpoints
  • Query and analyze endpoint telemetry (process execution, file system, registry, memory, authentication events) to validate detection hypotheses and assess coverage
  • Monitor detection precision metrics, investigate false positives, and tune detections to maintain high signal-to-noise ratios
  • Manage detections through a structured lifecycle: development, validation, staged deployment, and production monitoring
  • Collaborate with threat intelligence and incident response teams to prioritize detection development based on active threat campaigns

Requirements

What you’ll need
  • Must be eligible for CJIS clearance (requires U.S. citizenship or Green Card/permanent resident status).
  • Bachelor's degree in information security, computer science, or related field — or 4+ years of equivalent hands-on experience in detection engineering, threat analysis, or endpoint security
  • Experience with endpoint detection platforms, EDR tooling, or detection-driven security workflows
  • Proficiency in Windows OS internals and APIs (process creation, registry, file system, memory management, authentication subsystems)
  • Experience with behavioral malware analysis, sandboxing, telemetry collection, and detectable behaviors from execution logs or Windows forensics
  • Working knowledge of regular expressions and pattern-based detection authoring
  • Ability to read and understand various programming languages and PowerShell; scripting proficiency in Python for automation and analysis
  • Experience analyzing endpoint telemetry or host-based log data to identify malicious patterns
  • Solid working knowledge of common adversary TTPs and the ability to translate threat intelligence into detection logic
  • Ability to assess cyber threat intelligence, open-source intelligence, or partner reporting for actionable detection opportunities
  • Passion for detection engineering, threat analysis, or security research, with the motivation to keep learning and growing
  • Energetic self-starter mentality with the ability to take ownership and be accountable for deliverables
  • Clear written and verbal communication skills to drive triage, convey detection rationale, and align cross-functionally with both technical and executive-level stakeholders
  • Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.

Benefits

Comp & perks
  • Market leader in compensation and equity awards
  • Comprehensive physical and mental wellness programs
  • Competitive vacation and holidays for recharge
  • Paid parental and adoption leaves
  • Professional development opportunities for all employees regardless of level or role
  • Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections
  • Vibrant office culture with world class amenities
  • Great Place to Work Certified™ across the globe