Engineer II Threat Detection - Windows (Hybrid)
Overview
CrowdStrike seeks an Engineer II to lead threat detection on Windows endpoints. This hybrid role involves analyzing emerging threats and authoring behavioral detection rules. You will collaborate across teams to mitigate intrusions and improve detection coverage at scale.
What You'll Do9
- 1Analyze emerging threats and malware telemetry to identify detectable behaviors and coverage gaps
- 2Author and optimize behavioral detection rules targeting adversary techniques on Windows endpoints
- 3Query endpoint telemetry to validate detection hypotheses and assess coverage
- 4Monitor detection precision metrics and tune detections to maintain high signal-to-noise ratios
- 5Manage detection lifecycle from development to production monitoring
- 6Collaborate with threat intelligence and incident response teams to prioritize detection development
- 7Take ownership of solving detection gaps that protect customers
- 8Work independently and cross-functionally within a cutting-edge threat detection team
- 9Stay current with AI-assisted tools and detection engineering best practices
Requirements10
- 1Eligible for CJIS clearance with U.S. citizenship or Green Card status
- 2Bachelor's degree in information security or related field or 4+ years equivalent experience
- 3Proficiency in Windows OS internals and detection platforms like Falcon sensor
- 4Experience with behavioral malware analysis and detection rule authoring
- 5Strong understanding of MITRE ATT&CK and adversary tactics
- 6Ability to translate threat intelligence into actionable detection opportunities
- 7Experience with regex optimization and detection content lifecycle management
- 8Familiarity with endpoint telemetry analysis and detection precision concepts
- 9Passion for detection engineering and continuous learning
- 10Experience with AI technologies to enhance security workflows
Salary Insight
$100 - $145k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
CrowdStrike, Inc.
VerifiedSenior Software Engineer Windows Sensor Hybrid
CrowdStrike seeks a Senior Software Engineer to lead detection technology development for Windows sensors. The role involves designing and building detection logic, researching malicious techniques, and collaborating across teams. Candidates must have strong Windows internals expertise and a passion for AI-driven security solutions.
SMART TECH SKILLS LLC
VerifiedDetection Engineering & SOAR Architect - SMART TECH SKILLS LLC
Senior Security Operations Analyst leads detection response and orchestration at a public sector organization. This role builds scalable AI-assisted workflows using CrowdStrike Falcon and Torq while enforcing Zero Trust principles. The ideal candidate drives detection engineering excellence and differentiates through advanced automation and governance.
AssetMark Financial Holdings, Inc.
VerifiedSecurity Engineer II - Cloud & IAM | AssetMark
You will own security operations for AssetMark's hybrid cloud environment, protecting AWS and Azure workloads and IAM infrastructure. You will work alongside engineering teams to embed security into the software development lifecycle, integrating CrowdStrike Falcon, Check Point Harmony, and Microsoft Defender. Your role focuses on incident response, vulnerability management, and threat modeling for key products. This position stands out for its hybrid schedule and direct impact on securing a leading advisor platform.

BCforward
VerifiedCyber Security Engineer, SOC & Incident Response
Own security monitoring and incident response for a Fortune 500 client in Phoenix, AZ. You will join BCforward's security operations team, working onsite to detect, investigate, and mitigate threats across a hybrid cloud and on-premise environment. This role demands hands-on expertise with SIEM platforms and EDR tools, with a direct impact on the client's security posture.
Cylake-Inc
VerifiedSecurity Researcher (Detection Systems)
Join Cylake-Inc in San Jose, California for an onsite opportunity. Lead the creation of next-generation cybersecurity products from the ground up. Shape the future of threat detection while growing your career with a world-class team.

Conquest Consulting
VerifiedSenior SOC Detection Engineer CrowdStrike Falcon & SOAR AI
Lead detection engineering for CrowdStrike Falcon and SOAR platforms. Own and scale threat detection solutions. Drive platform improvements. Shape security operations strategy. Differentiate by delivering proactive threat intelligence.