Summary
Cloud and Things is seeking a Functional CrowdStrike Analyst to support a New York State client. The role will remotely implement and maintain CrowdStrike Falcon Cloud Security and CNAPP capabilities across Kubernetes and Amazon EKS environments, including cloud posture, workload, runtime, entitlement, detection, and container security controls. The analyst will collaborate with Technology and Cloud Engineering teams, perform end-to-end security testing, work a 45-hour week, and travel approximately once per month to Albany, New York.
Responsibilities
- Configure CrowdStrike Falcon Cloud Security and applicable CNAPP modules within the Falcon console for Kubernetes and Amazon EKS environments
- Implement and maintain Kubernetes and EKS security policies, including posture, workload, runtime, admission-control, and container security controls
- Establish Cloud Security Posture Management (CSPM) policies and tune Cloud Detection and Response (CDR) detections to align with security use cases
- Configure Cloud Workload Protection (CWP), runtime security, and Cloud Infrastructure Entitlement Management (CIEM) capabilities across development, non-production, performance, and production environments
- Execute end-to-end security use-case testing to validate image scanning, detection, containment, admission-control, entitlement analysis, and runtime protection functionality
- Collaborate with Technology and Cloud Engineering teams on implementation decisions, technical findings, issue resolution, and CNAPP deployment activities
Skills
- 3+ years of experience configuring CrowdStrike Falcon Cloud Security and applicable CNAPP modules across Kubernetes and Amazon Elastic Kubernetes Service (EKS) environments
- Hands-on experience configuring CrowdStrike Falcon Cloud Security and CNAPP modules in the Falcon console
- Experience configuring Kubernetes and EKS security policies
- Experience establishing Cloud Security Posture Management (CSPM) policies and tuning Cloud Detection and Response (CDR) detections
- Experience configuring Cloud Workload Protection (CWP) and runtime security policies across development, non-production, performance, and production environments
- Experience executing security use-case testing to validate detection, containment, and admission-control functionality
- Experience implementing end-to-end container security, including image scanning, admission control, and runtime protection
- Experience configuring Cloud Infrastructure Entitlement Management (CIEM) capabilities, including entitlement analysis
- Experience with a CNAPP platform such as CrowdStrike Falcon, Wiz, or Palo Alto Networks Prisma Cloud
- 2+ years of cloud experience
- U.S. citizenship required by client
- Ability to work a 45-hour workweek and travel approximately once per month
- Strong AWS and AWS GovCloud experience, including IAM, IAM Roles for Service Accounts (IRSA), secure networking, GuardDuty, AWS Inspector, and AWS Key Management Service (KMS)
- Ability to communicate architecture, implementation decisions, and technical findings to leadership and client stakeholders
- Awareness of NIST SP 800-53 Revision 5 and CMS ARC-AMPE guidance
- CrowdStrike certifications
- CrowdStrike Falcon experience is preferred
Qualifications
Must Haves
- 3+ years of experience configuring CrowdStrike Falcon Cloud Security and applicable CNAPP modules across Kubernetes and Amazon Elastic Kubernetes Service (EKS) environments
- Hands-on experience configuring CrowdStrike Falcon Cloud Security and CNAPP modules in the Falcon console
- Experience configuring Kubernetes and EKS security policies
- Experience establishing Cloud Security Posture Management (CSPM) policies and tuning Cloud Detection and Response (CDR) detections
- Experience configuring Cloud Workload Protection (CWP) and runtime security policies across development, non-production, performance, and production environments
- Experience executing security use-case testing to validate detection, containment, and admission-control functionality
- Experience implementing end-to-end container security, including image scanning, admission control, and runtime protection
- Experience configuring Cloud Infrastructure Entitlement Management (CIEM) capabilities, including entitlement analysis
- Experience with a CNAPP platform such as CrowdStrike Falcon, Wiz, or Palo Alto Networks Prisma Cloud
- 2+ years of cloud experience
- U.S. citizenship required by client
- Ability to work a 45-hour workweek and travel approximately once per month
- Strong AWS and AWS GovCloud experience, including IAM, IAM Roles for Service Accounts (IRSA), secure networking, GuardDuty, AWS Inspector, and AWS Key Management Service (KMS)
- Ability to communicate architecture, implementation decisions, and technical findings to leadership and client stakeholders
- Awareness of NIST SP 800-53 Revision 5 and CMS ARC-AMPE guidance
- CrowdStrike certifications
Nice to Haves
- CrowdStrike Falcon experience is preferred
Benefits
- Full-time, remote role
- Potential for extension after the 12-month duration