Charles Schwab · 19 hours ago
Senior CrowdStrike Engineer (Endpoint Security)
Charles Schwab is seeking a Senior CrowdStrike Engineer to support endpoint security technologies within their Cybersecurity Services. This role involves leading engineering efforts for endpoint security capabilities in CrowdStrike, ensuring compliance with regulatory standards, and collaborating with various teams to enhance security solutions.
Financial Services
Responsibilities
Leading the engineering efforts and implemention of endpoint security capabilities in CrowdStrike including EDR, NG-SIEM, DLP, IDP, and Zero Trust
Leading the implementation and adoption of CrowdStrike modules while ensuring all regulatory and compliance standards are met
Collaborating with product and project teams to understand needs and enablement with security products
Strong analysis and decision-making skills with the ability to identify opportunities to mature endpoint security offerings, participate in technical cross-functional sessions, and ensure adherence to change and configuration management principles
Assessing issues and developing resolutions to meet productivity, quality goals, and objectives
A proven track record of experience in implementing enterprise security solutions including design, configuration, installation, customization, automation, and optimization of tools
Experience configuring and maturing endpoint security programs, with at least 3 years of hands-on expertise in CrowdStrike Falcon (including EDR, Identity Protection, Data Protection, Exposure Management, SaaS Security, NG-SIEM, Fusion, CWP, or FIM)
Proven track record of deploying, configuring, and tuning CrowdStrike agents across enterprise environments (Windows, macOS, Linux)
Strong understanding of endpoint detection and response (EDR), threat hunting, IOC/IOA development, and real-time response (RTR)
Experience writing and updating queries using CrowdStrike Query Language, or similar SIEM query language such as Splunk
Experience integrating CrowdStrike with SIEM/SOAR platforms
Experience integrating multiple security tools to provide enhanced visibility and monitoring capabilities
Experience developing advanced workflows leveraging the CrowdStrike platform
Ability to leverage CrowdStrike telemetry to support incident response investigations
Comfortable collaborating with SOC, threat intel, and infrastructure teams to refine detection logic and reduce false positives
Knowledge of MITRE ATT&CK, malware behaviors, and threat actor TTPs as they relate to endpoint security
Advanced experience with scripting (PowerShell, CQL, Python, Bash) for automation and custom response actions
Develop and report enterprise level metrics for endpoint security controls
Architect solutions (initial state, transition, final state architectures)
Provide compliance and audit evidence for monitored systems
Document, publish, and maintain a knowledge base of information pertaining to the functionality, processes, and procedures related to the supported tools
Qualification
Required
5+ years of experience configuring and maturing endpoint security programs, with at least 3 years of hands-on expertise in CrowdStrike Falcon (including EDR, Identity Protection, Data Protection, Exposure Management, SaaS Security, NG-SIEM, Fusion, CWP, or FIM)
Proven track record of deploying, configuring, and tuning CrowdStrike agents across enterprise environments (Windows, macOS, Linux)
Strong understanding of endpoint detection and response (EDR), threat hunting, IOC/IOA development, and real-time response (RTR)
Experience writing and updating queries using CrowdStrike Query Language, or similar SIEM query language such as Splunk
Experience integrating CrowdStrike with SIEM/SOAR platforms
Experience integrating multiple security tools to provide enhanced visibility and monitoring capabilities
Experience developing advanced workflows leveraging the CrowdStrike platform
Ability to leverage CrowdStrike telemetry to support incident response investigations
Comfortable collaborating with SOC, threat intel, and infrastructure teams to refine detection logic and reduce false positives
Knowledge of MITRE ATT&CK, malware behaviors, and threat actor TTPs as they relate to endpoint security
Advanced experience with scripting (PowerShell, CQL, Python, Bash) for automation and custom response actions
Develop and report enterprise level metrics for endpoint security controls
Architect solutions (initial state, transition, final state architectures)
Provide compliance and audit evidence for monitored systems
Document, publish, and maintain a knowledge base of information pertaining to the functionality, processes, and procedures related to the supported tools
More than 7 years of progressive experience in cybersecurity engineering
Bachelor's Degree in Computer Science, Engineering, or related field required
Preferred
CrowdStrike certifications (e.g., CCFR, CCFP) are highly desirable
CISSP, CISM, or other relevant information security industry recognized certification preferred
Benefits
Eligible for bonus or incentive opportunities
Company
Charles Schwab
We have plans for every turn you take.
H1B Sponsorship
Charles Schwab has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (579)
2024 (468)
2023 (455)
2022 (705)
2021 (483)
2020 (282)
Funding
Current Stage
Late StageRecent News
2025-10-04
Company data provided by crunchbase