CrowdStrike

Threat Hunter - GovCloud, 3rd Shift (Remote)

USA - Remote Full time

As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We’re also a mission-driven company. We cultivate a culture that gives every CrowdStriker both the flexibility and autonomy to own their careers. We’re always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you.

About the Role:

The CrowdStrike OverWatch FedCloud team is seeking a motivated professional with technical skills to analyze threat actor activity, identify intrusions, create detections, and track campaigns. The FedCloud team is focused on both proactive and active threat hunting operations across our customer base in effort to continuously identify and disrupt the adversary while consistently improving detection capability and efficiency for the Falcon Host platform. If you are proficient in either host-based/network intrusion analysis, digital forensics, or cyber threat intelligence and you want to gain real-world experience in dealing with advanced threat actors (be they nation-state, criminal, hacktivist or other), we have a truly unique role for you!

The role will be on a cutting-edge, threat-hunting team regularly facing off against sophisticated threat actors. If this sounds like an exciting opportunity, we would like to hear from you.

Shift: Nights (3rd Shift). This particular position will be 100% remote and will require the candidate to support the following shift: Saturday - Tuesday from 23:00 - 09:00 ET (+0300 - 1300 UTC). Shift differential pay is provided for the role.

What You’ll Do:

  • Protect our customer's networks by identifying and understanding intrusions using Falcon Endpoint data and the broader CrowdStrike product suite.

  • Analyze adversary activity and communicate those findings to customers as part of our fast-paced time sensitive mission to help stop breaches.

  • Undertake research to improve our detection capabilities and understand our adversaries.

  • Participate in active and passive threat hunting and gain fast-paced experience in dealing with threat actors

What You’ll Need:

Required:

  • Ability to demonstrate experience in conventional network\host-based intrusion analysis, digital forensics, or handling malware.

  • A strong grasp of how Windows, MacOs and Linux operating systems function.

  • Comfortability assessing cyber threat intelligence, open-source intelligence or industry reporting.

  • Knowledge of programming and scripting languages, in particular Python or Go.

  • A strong understanding of administrative tools and how adversaries may leverage them to live-off-the-land.

  • Familiarity with adversary techniques and attack lifecycles. (e.g: adversary progression through techniques found in the MITRE ATT&CK® matrix)

  • Willingness to work in a dynamic, fast-paced, and challenging role in an unconventional team environment.

  • Ability to communicate actionable threat intelligence to both technical and executive-level stakeholders.

Preferred:

  • Deeper knowledge of operating systems other than Windows (Linux, Mac)

  • Hands-on experience hunting for and/or responding to incidents associated with eCrime and/or Nation-state adversaries.

  • Experience in a security operations center or similar environment tracking threat actors or responding to incidents.

  • Experience publishing research papers at conferences or through other mediums (blogs, articles)

  • A good understanding of current and emerging threats and the ability to demonstrate practical knowledge of security research

  • Experience with logging platforms such as LogScale, Splunk, or Kibana and creating queries to identify suspicious activity

#LI-Remote

#LI-AO1

This role may require the candidate to periodically undergo and pass alcohol and/or drug test(s) during the course of employment.This role will require the candidate to periodically undergo and pass additional background and fingerprint check(s) consistent with government customer requirements.

Benefits of Working at CrowdStrike:

  • Remote-friendly and flexible work culture

  • Market leader in compensation and equity awards

  • Comprehensive physical and mental wellness programs 

  • Competitive vacation and holidays for recharge  

  • Paid parental and adoption leaves

  • Professional development opportunities for all employees regardless of level or role

  • Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections

  • Vibrant office culture with world class amenities

  • Great Place to Work Certified™ across the globe

CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program.

CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions--including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs--on valid job requirements.

If you need assistance accessing or reviewing the information on this website or need help submitting an application for employment or requesting an accommodation, please contact us at recruiting@crowdstrike.com for further assistance.

Find out more about your rights as an applicant.

CrowdStrike participates in the E-Verify program.

Notice of E-Verify Participation

Right to Work

CrowdStrike, Inc. is committed to fair and equitable compensation practices. Placement within the pay range is dependent on a variety of factors including, but not limited to, relevant work experience, skills, certifications, job level, supervisory status, and location. The base salary range for this position for all U.S. candidates is $85,000 - $120,000 per year, with eligibility for bonuses, equity grants and a comprehensive benefits package that includes health insurance, 401k and paid time off.

For detailed information about the U.S. benefits package, please click here

Expected Close Date of Job Posting is:01-07-2026