Haystack
← Back to Jobs
Other
CI

CrowdStrike Analyst

ComTec Information SystemsHouston, TX🇺🇸United StatesPosted 11 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Houston, TX, United States
Posted
Yesterday
AWSSplunkPowerShellPython

Job Description

Title: CrowdStrike Analyst

Location: The Woodlands, TX or Little Rock, AR

Job Overview

We are seeking a CrowdStrike Analyst with strong hands-on experience in the CrowdStrike Falcon platform, endpoint detection and response, threat hunting, security investigation, and incident response. The candidate will monitor and investigate endpoint threats, analyze security telemetry, identify malicious activity, and support automated detection and response.


Responsibilities

  • Monitor and investigate security alerts and incidents using CrowdStrike Falcon.
  • Perform threat detection, threat hunting, incident investigation, and response.
  • Analyze endpoint telemetry, processes, command lines, network activity, users, and file behavior.
  • Investigate malware, ransomware, phishing, credential attacks, and suspicious PowerShell activity.
  • Use CrowdStrike Falcon Insight/EDR capabilities for endpoint investigation and response.
  • Develop and tune detection queries and investigation workflows using CrowdStrike Query Language (CQL).
  • Perform proactive threat hunting based on MITRE ATT&CK techniques and threat intelligence.
  • Correlate CrowdStrike data with Splunk/SIEM, Cribl, and other security data sources.
  • Execute or coordinate endpoint containment, remediation, and recovery activities.
  • Use CrowdStrike APIs, scripting, and automation to improve security operations.
  • Support AI-assisted / AI-driven detection and response (AIDR) workflows where applicable.
  • Document incidents, investigation findings, root cause, and remediation actions.

Required Skills

  • 3+ years of hands-on experience with CrowdStrike Falcon or equivalent EDR/XDR platforms.
  • Strong experience in threat detection, threat hunting, incident response, and endpoint investigation.
  • Hands-on experience with CrowdStrike Falcon EDR/Insight and CQL.
  • Strong understanding of Windows and Linux security, malware, ransomware, and attacker techniques.
  • Knowledge of MITRE ATT&CK, IOC/IOA analysis, threat intelligence, and security operations.
  • Experience with Splunk or another SIEM for event correlation and investigation.
  • Scripting/automation experience with Python, PowerShell, or similar tools.
  • Experience working with security APIs and SOAR/automation workflows.
  • Strong analytical, troubleshooting, and communication skills.

Preferred Skills

  • CrowdStrike certifications.
  • Experience with Falcon Fusion or similar automated response capabilities.
  • Experience integrating CrowdStrike with Splunk, Cribl, SOAR, or security data platforms.
  • Experience with AI/GenAI, AI agents, or AI-driven security operations.
  • Experience developing automated threat detection and response workflows.
  • Knowledge of cloud security and AWS security services.

Similar jobs