Handle day-to-day security alerts, incidents, operational issues, and service requests in accordance with established procedures and service levels.
Investigate endpoint and identity-related security issues using CrowdStrike telemetry, Active Directory information, authentication records, and system logs.
Support containment and remediation activities, including host isolation, account restriction, evidence collection, and coordination with relevant IT teams.
Manage security requests such as policy changes, exclusions, allowlisting, investigation requests, and user or device follow-up.
- Support the administration of CrowdStrike Falcon capabilities, including Endpoint Security, Identity Protection, Fusion SOAR, Real Time Response, Spotlight, and related integrations.
- Monitor sensor health, platform coverage, policy compliance, workflow status, and operational exceptions.
- Support the configuration and maintenance of endpoint, identity, and automation policies based on approved standards.
- Develop and maintain Fusion SOAR workflows for alert enrichment, notification, case creation, triage, and response automation.
- Troubleshoot CrowdStrike sensor, policy, integration, and Active Directory-related issues with infrastructure, system, and IT support teams.
- Maintain operational procedures, investigation guides, response playbooks, workflow documentation, and knowledge articles.
- Participate in security operations, platform improvement, and automation initiatives.