Engineer II - Vulnerability Detection
CrowdStrikeResponsibilities
- Identify, evaluate, and onboard reliable vulnerability data sources for OT/IoT vendors and devices.
- Monitor threat intelligence and vulnerability disclosures to prioritize content and route CVE findings against supported device inventories.
- Maintain device inventories, correlate telemetry, fingerprint assets, and prioritize expansion opportunities.
- Troubleshoot customer escalations, participate in POVs and beta programs, and use findings to improve product capabilities.
- Identify pipeline bottlenecks, develop KPIs, track coverage metrics, and operationalize health checks and quality controls.
- Collaborate with security SMEs to develop detection content for adversary activity in industrial environments.
- Use generative AI and AI-agent workflows to automate vulnerability analysis, validation, prioritization, and remediation guidance while maintaining human verification.
Requirements
- 3–7 years of hands-on experience in OT/IoT security, vulnerability research, or related technical disciplines.
- Proficiency in Go or Python for backend/cloud development, automation, data processing, and pipeline tooling.
- Experience with OpenSearch or Elastic Search, complex queries, aggregations, and correlating large-scale datasets.
- Experience stitching heterogeneous telemetry into unified asset records and accurately identifying or fingerprinting devices.
- Proficiency with packet analysis tools such as Wireshark, Zeek, or Scapy, including custom dissectors or parsers for OT protocols.
- Experience supporting OT environments and familiarity with SCADA, DCS, HMI, Purdue Model L2/L3 systems, and related security considerations.
- Working knowledge of IoT/ICS/OT network architecture and protocols such as Modbus, DNP3, and ENIP.
- Ability to research threat intelligence, vulnerability disclosures, and adversary activity and collaborate effectively with distributed teams, customers, and partners.
Benefits
- Market-leading compensation and equity awards.
- Comprehensive physical and mental wellness programs.
- Competitive vacation and holidays.
- Paid parental and adoption leave.
- Professional development opportunities for employees at all levels and in all roles.
- Employee networks, geographic neighborhood groups, and volunteer opportunities.
- Vibrant office culture with world-class amenities.
- Great Place to Work Certified employer and equal opportunity workplace.
About CrowdStrike
CrowdStrike (Nasdaq: CRWD), a global cybersecurity leader, has redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data. Powered by the CrowdStrike Security Cloud and world-class AI, the CrowdStrike Falcon® platform leverages real-time indicators of attack, threat intelligence, evolving adversary tradecraft and enriched telemetry from across the enterprise to deliver hyper-accurate detections, automated protection and remediation, elite threat hunting and prioritized observability of vulnerabilities. Purpose-built in the cloud with a single lightweight-agent architecture, the Falcon platform delivers rapid and scalable deployment, superior protection and performance, reduced complexity and immediate time-to-value. CrowdStrike: We stop breaches.