02 Oct
|
Secure Minds
|
Gurugram
02 Oct
Secure Minds
Gurugram
CrowdStrike Implementation Specialist – SIEM (Cybersecurity)
Cybersecurity – Connected Services | Full-Time | 8–12 Years Experience
Experience
Location
Employment Type
8–12 Years
--
Full-Time
Role Overview
We are looking for an experienced CrowdStrike Implementation Specialist with strong SIEM expertise to join our Cybersecurity team. The ideal candidate will have hands-on experience architecting, designing, and deploying CrowdStrike solutions (Falcon platform, Next-Gen SIEM/LogScale, and Falcon Fusion SOAR) across enterprise environments, along with a solid understanding of SIEM implementation, content development, and use-case engineering. This role requires the ability to independently drive solution architecture, produce High-Level Design (HLD) and Low-Level Design (LLD) documents, and lead migration efforts from legacy SIEM platforms to CrowdStrike.
Key Responsibilities
- Lead end-to-end architecture and design of CrowdStrike Falcon and Next-Gen SIEM (LogScale) implementations for enterprise customers, ensuring alignment with security, scalability, and compliance requirements.
- Prepare detailed High-Level Design (HLD) and Low-Level Design (LLD) documents covering data ingestion, log source onboarding, sensor deployment, sizing/capacity planning, integration architecture, and network topology.
- Own SIEM content development — build and tune correlation rules, detections, dashboards, parsers, and use cases specific to CrowdStrike Next-Gen SIEM and third-party log sources.
- Drive migration and onboarding activities from legacy SIEM platforms (e.g., Splunk, QRadar, ArcSight, Microsoft Sentinel) to CrowdStrike, including data source mapping, parity validation, and cutover planning.
- Design and implement Falcon Fusion SOAR workflows and playbooks to automate detection, triage, and response processes.
- Conduct technical workshops and requirement-gathering sessions with client stakeholders to translate business and security requirements into actionable design documents.
- Perform health checks, performance tuning, and optimization of existing CrowdStrike/SIEM deployments to improve detection efficacy and reduce false positives.
- Collaborate with SOC, threat intelligence, and incident response teams to align detection content with the MITRE ATT&CK; framework and evolving threat landscape.
- Create and maintain runbooks, standard operating procedures (SOPs), and knowledge base articles for implementation and operational teams.
- Mentor junior engineers and analysts on CrowdStrike architecture, SIEM concepts, and content engineering best practices.
- Ensure all implementations adhere to internal security standards, client compliance requirements, and industry best practices (ISO 27001, NIST, PCI-DSS as applicable).
Required Skills & Experience
- 8–12 years of overall experience in Cybersecurity, with at least 4–5 years of hands-on CrowdStrike implementation and SIEM engineering experience.
- Strong working knowledge of the CrowdStrike Falcon platform, Falcon Next-Gen SIEM (LogScale/Humio), Falcon Fusion SOAR, Falcon Discover, and Falcon Spotlight.
- Proven experience in SIEM architecture and design, including log source onboarding, parser/connector development, and correlation rule engineering.
- Demonstrated experience authoring HLD and LLD documents for security tool implementations and migrations.
- Hands-on experience with SIEM migration projects — planning, data validation, parallel run, and cutover management.
- Solid understanding of log sources such as Windows/Linux endpoints, firewalls, proxies, cloud platforms (Azure/AWS/GCP), Active Directory, and network devices.
- Working knowledge of scripting/query languages (e.g., LogScale Query Language, SPL, KQL, or similar) for content development and threat hunting.
- Good understanding of the MITRE ATT&CK; framework and its application to detection engineering and use-case design.
- Experience with SOAR playbook design and security automation concepts.
- Familiarity with prior/legacy SIEM platforms (Splunk, IBM QRadar, ArcSight, Microsoft Sentinel) is highly desirable for migration-related engagements.
- Strong analytical, documentation, and client-facing communication skills, with the ability to present technical designs to both technical and business stakeholders.
- Exposure to proposal/SoW preparation and technical pre-sales support is a plus.
Preferred Certifications
- CrowdStrike Certified Falcon Administrator (CCFA) / CrowdStrike Certified Falcon Responder (CCFR)- good to have
- CrowdStrike Certified Falcon Hunter (CCFH) - valuable to have
- CISSP, CISM, CEH, or equivalent security certification - good to have
Education
- Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent practical experience).
📌 Information Technology Specialist (Gurugram)
🏢 Secure Minds
📍 Gurugram