Incident Response Analyst - Defensive Operations

1 Month ago • 3-5 Years • Operations

Job Summary

Job Description

The Incident Response Defensive Operations (IRDO) team is seeking a detail-oriented analyst to improve the Cybersecurity Incident Response program. This role involves identifying workflow inefficiencies, addressing capability gaps, and managing projects to enhance the efficiency of the Cybersecurity IR team. The analyst will also collaborate with the Threat Detection and Engineering (TIDE) team to improve IR tooling. Responsibilities include analyzing workflows, investigating gaps, leading cross-functional projects, automating workflows, contributing to the CSIRT Attack Surface Management program, and facilitating communication between the IR team and TIDE. The role requires a strong understanding of cybersecurity operations, incident response, and project management.
Must have:
  • 3-5 years of experience in cybersecurity operations
  • Experience with workflow automation
  • Experience with ServiceNow, Jira or similar tools
  • Strong IT background and expertise with OSX
  • Strong analytical and problem-solving skills
  • Excellent communication and interpersonal skills
Good to have:
  • Scripting knowledge (e.g., Python)
  • Familiarity with Splunk or other SIEM platforms
  • Experience with host and network forensics
  • Background in malware analysis
  • Familiarity with agile project management
  • Technical security certifications
Perks:
  • Remote-friendly and flexible work culture
  • Market leader in compensation and equity awards
  • Comprehensive physical and mental wellness programs
  • Competitive vacation and holidays for recharge
  • Paid parental and adoption leaves
  • Professional development opportunities
  • Employee Resource Groups and volunteer opportunities
  • Vibrant office culture with world class amenities
  • Great Place to Work Certified™

Job Details

As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We’re also a mission-driven company. We cultivate a culture that gives every CrowdStriker both the flexibility and autonomy to own their careers. We’re always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you.

About the Role:

The Incident Response Defensive Operations (IRDO) team is seeking a detail-oriented, proactive Analyst to help drive strategic improvements to our Cybersecurity Incident Response program. This role is designed for someone who thrives at the intersection of operations, project management, and technical problem-solving.

You’ll work alongside Incident Response analysts and engineers to identify pain points in existing workflows, close capability gaps, and manage high-impact projects that enhance the efficiency, effectiveness, and overall analyst experience of the Cybersecurity IR team. You’ll also serve as a key liaison with our Threat Detection and Engineering (TIDE) team, ensuring smooth collaboration on detection engineering, automation, and improvements to our IR tooling.

As part of this role, you'll also contribute to the CSIRT Attack Surface Management program - an initiative focused on evaluating and improving the organisation’s ability to detect and respond to threats across critical domains including email, applications, networks, and endpoints.

 

What You'll Do:

  • Analyse incident response workflows to identify inefficiencies and friction points; propose and implement improvements.

  • Investigate operational and technical capability gaps - such as containment or access limitations and coordinate efforts to close them.

  • Lead and support cross-functional projects aimed at improving IR tooling, processes, and analyst experience.

  • Build or coordinate the development of workflow automations that reduce manual overhead and streamline response processes.

  • Contribute to the CSIRT Attack Surface Management program by assessing detection coverage, visibility, and response readiness across key attack surfaces.

  • Serve as the intermediary between the IR team and TIDE, translating analyst needs into actionable engineering requirements and helping prioritize improvements.

  • Maintain visibility on evolving IR needs and ensure proactive delivery of scalable, reliable operational enhancements.

What You'll Need:

Education & Experience:

  • Bachelor's Degree (or equivalent experience) in a computer-related field

  • 3-5 years of experience in cybersecurity operations, incident response, or a similar domain (or equivalent combination of education and experience).

  • Hands-on experience with workflow automation - such as building automation playbooks, creating scripts, or leveraging tools like TINES, AWS Lambda, or SOAR platforms.

Technical Expertise:

  • Experience with ServiceNow, Jira, or similar workflow/ticketing tools

  • Strong IT background (networking fundamentals, systems) and expertise with OSX

  • Strong analytical and problem-solving skills with a passion for operational efficiency.

  • Experience with project management or process improvement in a technical environment.

  • Excellent communication and interpersonal skills; ability to interface with both technical and non-technical stakeholders.

  • Familiarity with cybersecurity technologies and concepts, particularly incident response, containment, and automation.

Analytical & Communication Skills:

  • Effective communication skills in English (verbal and written)

  • Ability to maintain strict confidentiality and operate independently in high-pressure situations

Preferred Skills & Attributes:

  • Scripting knowledge (e.g., Python, Perl, Bash, PowerShell)

  • Familiarity with Splunk or other advanced SIEM platforms

  • Experience with host and network forensics

  • Background in malware analysis

  • Familiarity with agile project management and compliance frameworks

  • Technical security certifications or advanced academic credentials

#LI-GT1

Benefits of Working at CrowdStrike:

  • Remote-friendly and flexible work culture

  • Market leader in compensation and equity awards

  • Comprehensive physical and mental wellness programs

  • Competitive vacation and holidays for recharge

  • Paid parental and adoption leaves

  • Professional development opportunities for all employees regardless of level or role

  • Employee Resource Groups, geographic neighbourhood groups and volunteer opportunities to build connections

  • Vibrant office culture with world class amenities

  • Great Place to Work Certified™ across the globe

CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program.

CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions--including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs--on valid job requirements.

If you need assistance accessing or reviewing the information on this website or need help submitting an application for employment or requesting an accommodation, please contact us at recruiting@crowdstrike.com for further assistance.

Similar Jobs

Epic Games - Third Party Risk Management Analyst

Epic Games

Cary, North Carolina, United States (On-Site)
3 Months ago
NBC Universal - Senior Project Manager: Syndication Content Engagement Manager

NBC Universal

Brentford, England, United Kingdom (On-Site)
1 Month ago
Nice - Senior Specialist Software Engineer (Dot Net, AWS)

Nice

Pune, Maharashtra, India (Hybrid)
2 Weeks ago
Sprinkler - Senior Product Manager

Sprinkler

Gurugram, Haryana, India (On-Site)
1 Month ago
bytedance - Asset Manager, Datacenter Infrastructure and Services

bytedance

Singapore (On-Site)
3 Months ago
IGT - Computer Operator III

IGT

Cranston, Rhode Island, United States (On-Site)
2 Weeks ago
Hawkeye Innovations - VAR Replay Operator

Hawkeye Innovations

Vienna, Vienna, Austria (Hybrid)
2 Months ago
Netflix - Promotional Assets Coordinator, Launch Operations

Netflix

Mumbai, Maharashtra, India (On-Site)
8 Months ago
Eqvilent - Lead of Trading Operations

Eqvilent

(Remote)
1 Month ago
Coherent corp. - Chemical Operator Trainee

Coherent corp.

Saxonburg, Pennsylvania, United States (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Canva - Senior Backend Engineer (Java)

Canva

Auckland, Auckland, New Zealand (Remote)
2 Weeks ago
Team Liquid - Project Manager

Team Liquid

Jakarta, Indonesia (On-Site)
1 Month ago
Loyalty Juggernaut - Content Writer

Loyalty Juggernaut

(Remote)
1 Month ago
DPDzero - Senior Software Engineer

DPDzero

Bengaluru, Karnataka, India (On-Site)
8 Months ago
Sailpoint - Project Manager - Training Operations

Sailpoint

Pune, Maharashtra, India (Remote)
1 Month ago
Tesla - Account Manager - Autobidder - Energy Optimization & Trading Software

Tesla

Saint-Ouen-sur-Seine, Île-de-France, France (On-Site)
4 Months ago
AECOM - Financial Planning & Analysis Analyst III

AECOM

Bucharest, Bucharest, Romania (Hybrid)
1 Week ago
Roblox - Senior Engineering Manager, Ads & Brand Experiences (Full Stack)

Roblox

San Mateo, California, United States (On-Site)
6 Days ago
Univision - Senior Product Manager, Gamification

Univision

Los Angeles, California, United States (On-Site)
3 Weeks ago
Gala games - Senior DevOps Engineer Contractor

Gala games

Pakistan (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Bucharest, Bucharest, Romania

IGT gaming - Producer / Game Project Manager

IGT gaming

Timișoara, Timiș, Romania (Hybrid)
1 Week ago
Ubisoft - Senior Level Designer

Ubisoft

Bucharest, Bucharest, Romania (Hybrid)
2 Months ago
Amber - Junior QA Tester

Amber

Botoșani, Botoșani County, Romania (On-Site)
3 Months ago
Veeam Software - Veeam Sales Internship Program

Veeam Software

Bucharest, Bucharest, Romania (Hybrid)
1 Month ago
endava - Mendix Developer

endava

Bucharest, Bucharest, Romania (On-Site)
3 Weeks ago
luxsoft - Senior DevOps Engineer (with Python experience)

luxsoft

Romania (Remote)
3 Weeks ago
Electronic Arts - Quality Designer

Electronic Arts

Bucharest, Bucharest, Romania (On-Site)
1 Day ago
PwC - Developing Senior Auditor

PwC

Timișoara, Timiș, Romania (Hybrid)
3 Months ago
Wind River - Senior Member Technical Staff - Linux Kernel

Wind River

Galați, Județul Galați, Romania (On-Site)
5 Days ago
Crowd Strick - Platform Security Operations Engineer III

Crowd Strick

Bucharest, Bucharest, Romania (Hybrid)
1 Month ago

Get notifed when new similar jobs are uploaded

Operations Jobs

Accenture - Payroll Operations New Associate

Accenture

Bengaluru, Karnataka, India (On-Site)
3 Weeks ago
Doola - Operations Agent

Doola

Philippines (Remote)
2 Months ago
Marsh McLennan - Coordinator - Insurance Operations

Marsh McLennan

Jakarta, Indonesia (Hybrid)
4 Weeks ago
beghou consulting - Associate Consultant, Commercial Operations & Analytics

beghou consulting

New York, New York, United States (Hybrid)
2 Days ago
easygo - Operations Manager

easygo

Melbourne, Victoria, Australia (On-Site)
1 Week ago
Interactive Brokers - Senior Clearing Operations Associate

Interactive Brokers

Budapest, Hungary (Hybrid)
1 Month ago
beghou consulting - Associate Manager, Commercial Operations & Analytics

beghou consulting

New York, New York, United States (Hybrid)
4 Weeks ago
Accenture - Insurance Operations Analyst

Accenture

Navi Mumbai, Maharashtra, India (On-Site)
2 Months ago
Thumbtack - Commercial Operations Analyst

Thumbtack

Philippines (Remote)
1 Month ago
 Pearl Abyss - Black Desert PC China Operation Manager

Pearl Abyss

(On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

About The Company

CrowdStrike was founded in 2011 to fix a fundamental problem: The sophisticated attacks that were forcing the world’s leading businesses into the headlines could not be solved with existing malware-based defenses. Founder George Kurtz realized that a brand new approach was needed — one that combines the most advanced endpoint protection with expert intelligence to pinpoint the adversaries perpetrating the attacks, not just the malware. There’s much more to the story of how Falcon has redefined endpoint protection but there’s only one thing to remember about CrowdStrike: We stop breaches.

United States (Remote)

Sydney, New South Wales, Australia (On-Site)

Paris, Île-de-France, France (Remote)

United Kingdom (Remote)

Saudi Arabia (Remote)

View All Jobs

Get notified when new jobs are added by Crowd Strick

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug