Crowdstrike SME
Coforge · Delhi, Delhi, India - San Carlos, Rio San Juan, Nicaragua
Coforge · Delhi, Delhi, India - San Carlos, Rio San Juan, Nicaragua
We are looking for a **Senior CrowdStrike SME** with strong hands-on experience in **CrowdStrike Falcon administration, Endpoint Security, Vulnerability Management, Threat Detection, and Security Operations**. The candidate will be responsible for managing the CrowdStrike platform, supporting vulnerability remediation activities, monitoring endpoint security posture, and working closely with infrastructure and application teams to reduce cybersecurity risk across the environment. **Key Responsibilities** **CrowdStrike Falcon Administration** - Manage and administer CrowdStrike Falcon platform on a day-to-day basis. - Monitor sensor deployment, sensor health, and agent coverage across servers and workstations. - Create, modify, and maintain Falcon prevention, detection, and response policies. - Perform troubleshooting of Falcon sensor-related issues and coordinate with endpoint teams for resolution. - Maintain Falcon groups, host classifications, exclusions, and prevention policies. - Support onboarding of new assets, business units, and cloud workloads into CrowdStrike. - Monitor Falcon dashboards and ensure adequate endpoint visibility and protection. **Vulnerability Management** - Utilize CrowdStrike Falcon Spotlight to identify and assess vulnerabilities across the environment. - Analyze critical, high, and medium-risk vulnerabilities and support remediation activities. - Track vulnerabilities from identification through closure. - Coordinate with Windows, Linux, Network, Database, Cloud, and Application teams to ensure remediation within agreed timelines. - Validate remediation activities and confirm successful risk closure. - Prioritize vulnerabilities based on: - CVSS Score - Asset Criticality - Exposure Level - Business Risk - Known Exploitation Trends - Support emergency patching activities for critical vulnerabilities and zero-day threats. **Security Monitoring & Incident Support** - Investigate endpoint alerts generated by CrowdStrike Falcon. - Perform triage and analysis of suspicious activities detected through EDR. - Assist SOC analysts during security incident investigations. - Analyze Indicators of Compromise (IOC) and Indicators of Attack (IOA). - Support threat hunting activities utilizing Falcon event data. - Escalate security incidents based on organizational procedures.