Engineer II - Vulnerability Detection
CrowdStrike · India - Pune
onsitefull-time3-6 years
posted 3d
Sign in to applyAs a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. We work on large scale distributed systems, processing almost 3 trillion events per day and this traffic is growing daily. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We're proud to work for a mission-driven company leveraging AI to transform the way we work. CrowdStrikers drive their careers through flexibility and autonomy while also being expected to contribute to a culture of responsible AI adoption, experimentation, and innovation. We use an AI-first mindset as a force multiplier to proactively and continuously accelerate execution, build expertise, uncover insights, and solve complex problems. We’re always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you. The Product Group: IOT Security Product Group is focussed on developing products and solutions for ICS/ OT and other IOT verticals like Healthcare. The charter for the team is to use CrowdStrike's platform capabilities and threat intelligence, and build modules and features, integrate with partner products and platforms to establish ourselves as the leading security vendor in this space. About the Role: This role will have a solid understanding of the IOT ICS domain. He/ she will understand the Purdue model, the assets, criticality and the data pertaining to security and its sources to provide accurate asset visibility, vulnerabilities. This involves understanding the domain and systems and software like SCADA servers, HMI, EW, DCS and understanding how adversaries may exploit these resources to advance their modes of interest. This person will be required to identify the data sources, gather the data, analyse the data, identify its criticality, and also automate simple tasks. They will also be responsible for troubleshooting issues with current data and making enhancements. What You'll Do: Identify, evaluate, and onboard vulnerability data sources relevant to OT/IoT vendors and devices, assessing reliability, timeliness, and coverage quality. Monitor threat intelligence and vulnerability disclosures to inform content prioritization. Handling and troubleshooting Customer escalations, to validate content quality and inform product improvements. Maintain a structured device inventory and prioritize expansion opportunities based on customer and market needs. Identify pipeline bottlenecks and propose process improvements to enhance content quality and delivery. Contribute to KPI development and baseline metric tracking for pipeline performance and content coverage Operationalize health checks and quality controls across the vulnerability content pipeline. Establish and maintain a cadence for monitoring new CVE disclosures against the supported device inventory, triaging and routing findings appropriately Engage with customers in POVs and beta programs to improve platform capabilities. Collaborate with security SMEs to develop detection content focused on adversary activity in industrial environments Leverage generative AI tools to accelerate vulnerability analysis, proof-of-concept development, and detection rule creation while maintaining human oversight for validation and detection accuracy. Design and implement AI agent workflows to automate multi-step vulnerability validation processes (e.g., discovery, analysis, prioritization, remediation guidance) while ensuring human-in-the-loop verification for critical vulnerability detections and false positive reduction. Oth