CrowdStrike logo

Engineer II – SIEM Integrations

CrowdStrike · Posted Sep 17

Cloud-native endpoint security, threat intelligence, and AI-driven cybersecurity protection services

India - BangaloreFull-timeOnsiteSenior Level4+ years₹30.0L–₹45.0L yearly100+ applicants
CybersecurityCloud SecurityEndpoint ProtectionThreat IntelligenceArtificial IntelligenceSaaSPublic Company
Full time

Get a personal compatibility score

Add a resume for personal matches

About the role

CrowdStrike is a global leader in cybersecurity, protecting the people, processes and technologies that drive modern organizations, with an AI-native platform that processes almost 3 trillion events per day. The Get Data In (GDI) Integrations Content team at Next-Gen SIEM builds out-of-the-box integrations for third-party products to ingest and parse data into the SIEM platform. This role focuses on designing, developing, and maintaining out-of-the-box data connectors for CrowdStrike Next-Gen SIEM, ensuring seamless ingestion of security data from various third-party products.

What you will do

  • Evaluate, develop, maintain, and enhance data connectors and parsers to ingest data from third-party security products into CrowdStrike Next-Gen SIEM
  • Set up and maintain a lab or test environment for security products to validate data connectors and troubleshoot issues
  • Troubleshoot and resolve issues with existing data connectors to ensure reliable log ingestion
  • Collaborate with internal teams to define efficient logging, error handling, data normalization and documentation for data connectors
  • Research and implement best practices for ingesting security logs from Firewalls, IDS/IPS, Cloud Security products, Endpoint Security, and other security products and platforms
  • Write and maintain high-quality technical documentation for integration methods and troubleshooting guides
  • Provide on-call support for critical data ingestion issues and production incidents
  • Work with customers, customer success and customer support teams to troubleshoot and resolve data ingestion-related issues and ensure effective communication

Skills used in this role

SIEMSplunkMicrosoft SentinelExabeamQRadarSyslogCEFLEEFJSONXMLCriblFirewallsIDS/IPSEDRCASBPythonGoAWS CloudWatchAzure MonitorGCP LoggingCybersecurityData NormalizationLog Ingestion PipelinesDocumentationCommunicationCustomer Interaction

What the employer is looking for

  • Bachelor’s or Master’s degree in Computer Science or related field or equivalent work experience.
  • 4+ years of experience in cybersecurity and SIEM integrations
  • Experience in developing data connectors or ingestion pipelines for SIEM platforms such as Splunk, Sentinel, Exabeam, QRadar etc.
  • Experience in security data normalization schemas, parsing and data enrichment
  • Experience in setting up and managing environments for security products such as Firewalls, IDS/IPS, EDR, CASB, Identity Security, Email Security etc.
  • Experience with security events and its formats such as Syslog, CEF, LEEF, JSON, XML
  • Working knowledge of log processing or shipping tools such as Cribl, Splunk forwarder, Azure monitoring agent, LogScale log collector etc.
  • Proficiency in at least one programming language, preferably Python or Go
  • Strong documentation, communication and customer interaction skills
  • Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.

Preferred qualifications

  • Knowledge with cloud-native logging services such as AWS CloudWatch, Azure Monitor, or GCP Logging

Benefits and support

  • Market leader in compensation and equity awards
  • Comprehensive physical and mental wellness programs
  • Competitive vacation and holidays for recharge
  • Paid parental and adoption leaves
  • Professional development opportunities for all employees regardless of level or role
  • Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections
  • Vibrant office culture with world class amenities
  • Great Place to Work Certified™ across the globe

About CrowdStrike

CrowdStrike is a global cybersecurity leader that provides cloud-delivered endpoint and workload protection, threat intelligence, and cyberattack response services. Powered by the cloud-native CrowdStrike Falcon platform and artificial intelligence, the company helps secure critical areas of enterprise risk to stop breaches.

Industry
Cybersecurity
Company size
10001+ employees
Founded
2011
Location
Austin, Texas, USA
Funding stage
Public Company

Funding

Public Company · $430M raised

AccelWarburg PincusMarch Capital PartnersTelstra
  • 2020-10-13Post IPO DebtUndisclosed

Leadership

GK
George Kurtz

Co-Founder, President & Chief Executive Officer

BP
Burt Podbere

Chief Financial Officer

EZ
Elia Zaitsev

Chief Technology Officer

MS