11 Sep
|
Argus Consulting (India)
|
India
11 Sep
Argus Consulting (India)
India
Role Overview
We are looking for an experienced CrowdStrike Implementation Specialist with strong SIEM expertise to join our Cybersecurity team. The ideal candidate will have hands-on experience architecting, designing, and deploying CrowdStrike solutions (Falcon platform, Next-Gen SIEM/LogScale, and Falcon Fusion SOAR) across enterprise environments, along with a solid understanding of SIEM implementation, content development, and use-case engineering. This role requires the ability to independently drive solution architecture, produce High-Level Design (HLD) and Low-Level Design (LLD) documents, and lead migration efforts from legacy SIEM platforms to CrowdStrike.
Key Responsibilities
- Lead end-to-end architecture and design of CrowdStrike Falcon and Next-Gen SIEM (LogScale) implementations for enterprise customers, ensuring alignment with security, scalability, and compliance requirements.
- Prepare detailed High-Level Design (HLD) and Low-Level Design (LLD) documents covering data ingestion, log source onboarding, sensor deployment, sizing/capacity planning, integration architecture, and network topology.
- Own SIEM content development — build and tune correlation rules, detections, dashboards, parsers, and use cases specific to CrowdStrike Next-Gen SIEM and third-party log sources.
- Drive migration and onboarding activities from legacy SIEM platforms (e.g., Splunk, QRadar, ArcSight, Microsoft Sentinel) to CrowdStrike, including data source mapping, parity validation, and cutover planning.
- Design and implement Falcon Fusion SOAR workflows and playbooks to automate detection, triage, and response processes.
- Conduct technical workshops and requirement-gathering sessions with client stakeholders to translate business and security requirements into actionable design documents.
- Perform health checks, performance tuning, and optimization of existing CrowdStrike/SIEM deployments to improve detection efficacy and reduce false positives.
- Collaborate with SOC, threat intelligence, and incident response teams to align detection content with the MITRE ATT&CK; framework and evolving threat landscape.
- Create and maintain runbooks, standard operating procedures (SOPs), and knowledge base articles for implementation and operational teams.
- Mentor junior engineers and analysts on CrowdStrike architecture, SIEM concepts, and content engineering best practices.
- Ensure all implementations adhere to internal security standards, client compliance requirements, and industry best practices (ISO 27001, NIST, PCI-DSS as applicable).
Required Skills & Experience
- 8–12 years of overall experience in Cybersecurity, with at least 4–5 years of hands-on CrowdStrike implementation and SIEM engineering experience.
- Solid working knowledge of the CrowdStrike Falcon platform, Falcon Next-Gen SIEM (LogScale/Humio), Falcon Fusion SOAR, Falcon Discover, and Falcon Spotlight.
- Proven experience in SIEM architecture and design, including log source onboarding,
parser/connector development, and correlation rule engineering.
- Demonstrated experience authoring HLD and LLD documents for security tool implementations and migrations.
- Hands-on experience with SIEM migration projects — planning, data validation, parallel run, and cutover management.
- Solid understanding of log sources such as Windows/Linux endpoints, firewalls, proxies, cloud platforms (Azure/AWS/GCP), Active Directory, and network devices.
- Working knowledge of scripting/query languages (e.g., LogScale Query Language, SPL, KQL, or similar) for content development and threat hunting.
- Good understanding of the MITRE ATT&CK; framework and its application to detection engineering and use-case design.
- Experience with SOAR playbook design and security automation concepts.
- Familiarity with prior/legacy SIEM platforms (Splunk, IBM QRadar, ArcSight, Microsoft Sentinel) is highly desirable for migration-related engagements.
- Strong analytical, documentation, and client-facing communication skills, with the ability to present technical designs to both technical and business stakeholders.
- Exposure to proposal/SoW preparation and technical pre-sales support is a plus.
Preferred Certifications
- CrowdStrike Certified Falcon Administrator (CCFA) / CrowdStrike Certified Falcon Responder (CCFR)- good to have
- CrowdStrike Certified Falcon Hunter (CCFH) - good to have
- CISSP, CISM, CEH, or equivalent security certification - good to have
Education
- Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent practical experience).
📌 Crowdstrike Implementation Specialist (remote) (India)
🏢 Argus Consulting (India)
📍 India