In this role, you will support day-to-day security operations, investigate endpoint and identity-related security issues, and help administer and improve the CrowdStrike Falcon platform. You will also contribute to the automation of security workflows using Fusion SOAR, scripting, APIs, and AI-assisted capabilities.
This position is suitable for an early-career security professional who enjoys hands-on troubleshooting, security investigation, platform administration, and continuous improvement.
Job Description
- Handle day-to-day security alerts, incidents, operational issues, and service requests in accordance with established procedures and service levels.
- Investigate endpoint and identity-related security issues using CrowdStrike telemetry, Active Directory information, authentication records, and system logs.
- Support containment and remediation activities, including host isolation, account restriction, evidence collection, and coordination with relevant IT teams.
- Manage security requests such as policy changes, exclusions, allowlisting, investigation requests, and user or device follow-up.
- Support the administration of CrowdStrike Falcon capabilities, including Endpoint Security, Identity Protection, Fusion SOAR, Real Time Response, Spotlight, and related integrations.
- Monitor sensor health, platform coverage, policy compliance, workflow status, and operational exceptions.
- Support the configuration and maintenance of endpoint, identity, and automation policies based on approved standards.
- Develop and maintain Fusion SOAR workflows for alert enrichment, notification, case creation, triage, and response automation.
- Troubleshoot CrowdStrike sensor, policy, integration, and Active Directory-related issues with infrastructure, system, and IT support teams.
- Maintain operational procedures, investigation guides, response playbooks, workflow documentation, and knowledge articles.
- Participate in security operations, platform improvement, and automation initiatives.
Requirements
- Bachelor's degree in Computer Engineering, Cybersecurity, Information Security, Computer Science, or a related discipline.
- Practical experience in at least one of the following areas:
- Security alert investigation or incident handling
- EDR or endpoint security platform administration
- Active Directory or identity security administration and troubleshooting
- Security automation, SOAR, scripting, or API integration
- Good platform administration and troubleshooting skills, preferably with CrowdStrike Falcon or a comparable endpoint and identity security platform.
- Good understanding of EDR concepts, endpoint telemetry, threat detection, containment, and incident response.
- Good knowledge of Microsoft Active Directory, including users, groups, permissions, authentication, Group Policy, and domain controllers.
- Hands-on experience with SOAR, workflow automation, Python, PowerShell, scripting, or APIs is preferred.
- Experience using AI tools to support security investigation, workflow automation, case summarisation, or knowledge retrieval is an advantage.
- CrowdStrike or Microsoft Active Directory and identity-related certifications are an advantage but not mandatory.
- Strong analytical, documentation, communication, and cross-team collaboration skills.
- Able to manage operational tasks, follow through on investigations, and coordinate remediation within agreed timelines.