Subject Matter Expert (Support&Ops)
About this role
Job Summary
Role Summary
The CrowdStrike Falcon L3 Engineer is responsible for advanced administration, engineering, troubleshooting, threat hunting, incident response, and operational support of the CrowdStrike Falcon platform. The role serves as the highest technical escalation point for endpoint security incidents, platform optimization, integrations, and security investigations.
Key Responsibilities
Platform Administration
- Manage and administer the CrowdStrike Falcon platform.
- Configure and maintain prevention policies, detection policies, firewall management, USB device control, and sensor deployment.
- Perform health checks and platform optimization activities.
- Manage Falcon modules including:
- Falcon Prevent
- Falcon Insight
- Falcon Discover
- Falcon Device Control
- Falcon Firewall Management
- Falcon Identity Protection
- Falcon Spotlight
Incident Response & Threat Hunting
- Lead investigation of advanced malware, ransomware, phishing, and endpoint compromise incidents.
- Perform root cause analysis of security events.
- Conduct proactive threat hunting using Falcon Real-Time Response (RTR).
- Analyze Indicators of Compromise (IOC) and Indicators of Attack (IOA).
- Support containment, eradication, and recovery activities.
Engineering & Automation
- Design security use cases and detection rules.
- Develop automation using Falcon APIs.
- Integrate CrowdStrike with:
- Microsoft Sentinel
- Splunk
- QRadar
- ServiceNow
- SOAR platforms
- Create custom dashboards, reporting, and alerting mechanisms.
Advanced Troubleshooting
- Act as L3 escalation point for CrowdStrike platform issues.
- Troubleshoot sensor installation and upgrade failures.
- Resolve endpoint communication and performance issues.
- Support large-scale deployment and migration initiatives.
Security Governance & Compliance
- Support security audits and compliance requirements.
- Generate vulnerability and threat exposure reports.
- Implement security best practices and hardening recommendations.
- Participate in security reviews and risk assessments.
Technical Skills Required
Mandatory
- CrowdStrike Falcon Administration
- Falcon RTR (Real-Time Response)
- EDR/XDR Operations
- Threat Hunting
- Endpoint Security
- Incident Response
- Malware Analysis
- IOC/IOA Investigation
- Windows Server Administration
- Windows 10/11 Endpoint Management
Key Responsibilities
Role Summary
The CrowdStrike Falcon L3 Engineer is responsible for advanced administration, engineering, troubleshooting, threat hunting, incident response, and operational support of the CrowdStrike Falcon platform. The role serves as the highest technical escalation point for endpoint security incidents, platform optimization, integrations, and security investigations.
Key Responsibilities
Platform Administration
- Manage and administer the CrowdStrike Falcon platform.
- Configure and maintain prevention policies, detection policies, firewall management, USB device control, and sensor deployment.
- Perform health checks and platform optimization activities.
- Manage Falcon modules including:
- Falcon Prevent
- Falcon Insight
- Falcon Discover
- Falcon Device Control
- Falcon Firewall Management
- Falcon Identity Protection
- Falcon Spotlight
Incident Response & Threat Hunting
- Lead investigation of advanced malware, ransomware, phishing, and endpoint compromise incidents.
- Perform root cause analysis of security events.
- Conduct proactive threat hunting using Falcon Real-Time Response (RTR).
- Analyze Indicators of Compromise (IOC) and Indicators of Attack (IOA).
- Support containment, eradication, and recovery activities.
Engineering & Automation
- Design security use cases and detection rules.
- Develop automation using Falcon APIs.
- Integrate CrowdStrike with:
- Microsoft Sentinel
- Splunk
- QRadar
- ServiceNow
- SOAR platforms
- Create custom dashboards, reporting, and alerting mechanisms.
Advanced Troubleshooting
- Act as L3 escalation point for CrowdStrike platform issues.
- Troubleshoot sensor installation and upgrade failures.
- Resolve endpoint communication and performance issues.
- Support large-scale deployment and migration initiatives.
Security Governance & Compliance
- Support security audits and compliance requirements.
- Generate vulnerability and threat exposure reports.
- Implement security best practices and hardening recommendations.
- Participate in security reviews and risk assessments.
Technical Skills Required
Mandatory
- CrowdStrike Falcon Administration
- Falcon RTR (Real-Time Response)
- EDR/XDR Operations
- Threat Hunting
- Endpoint Security
- Incident Response
- Malware Analysis
- IOC/IOA Investigation
- Windows Server Administration
- Windows 10/11 Endpoint Management
Skill Requirements
Role Summary
The CrowdStrike Falcon L3 Engineer is responsible for advanced administration, engineering, troubleshooting, threat hunting, incident response, and operational support of the CrowdStrike Falcon platform. The role serves as the highest technical escalation point for endpoint security incidents, platform optimization, integrations, and security investigations.
Key Responsibilities
Platform Administration
- Manage and administer the CrowdStrike Falcon platform.
- Configure and maintain prevention policies, detection policies, firewall management, USB device control, and sensor deployment.
- Perform health checks and platform optimization activities.
- Manage Falcon modules including:
- Falcon Prevent
- Falcon Insight
- Falcon Discover
- Falcon Device Control
- Falcon Firewall Management
- Falcon Identity Protection
- Falcon Spotlight
Incident Response & Threat Hunting
- Lead investigation of advanced malware, ransomware, phishing, and endpoint compromise incidents.
- Perform root cause analysis of security events.
- Conduct proactive threat hunting using Falcon Real-Time Response (RTR).
- Analyze Indicators of Compromise (IOC) and Indicators of Attack (IOA).
- Support containment, eradication, and recovery activities.
Engineering & Automation
- Design security use cases and detection rules.
- Develop automation using Falcon APIs.
- Integrate CrowdStrike with:
- Microsoft Sentinel
- Splunk
- QRadar
- ServiceNow
- SOAR platforms
- Create custom dashboards, reporting, and alerting mechanisms.
Advanced Troubleshooting
- Act as L3 escalation point for CrowdStrike platform issues.
- Troubleshoot sensor installation and upgrade failures.
- Resolve endpoint communication and performance issues.
- Support large-scale deployment and migration initiatives.
Security Governance & Compliance
- Support security audits and compliance requirements.
- Generate vulnerability and threat exposure reports.
- Implement security best practices and hardening recommendations.
- Participate in security reviews and risk assessments.
Technical Skills Required
Mandatory
- CrowdStrike Falcon Administration
- Falcon RTR (Real-Time Response)
- EDR/XDR Operations
- Threat Hunting
- Endpoint Security
- Incident Response
- Malware Analysis
- IOC/IOA Investigation
- Windows Server Administration
- Windows 10/11 Endpoint Management
Other Requirements
Role Summary
The CrowdStrike Falcon L3 Engineer is responsible for advanced administration, engineering, troubleshooting, threat hunting, incident response, and operational support of the CrowdStrike Falcon platform. The role serves as the highest technical escalation point for endpoint security incidents, platform optimization, integrations, and security investigations.
Key Responsibilities
Platform Administration
- Manage and administer the CrowdStrike Falcon platform.
- Configure and maintain prevention policies, detection policies, firewall management, USB device control, and sensor deployment.
- Perform health checks and platform optimization activities.
- Manage Falcon modules including:
- Falcon Prevent
- Falcon Insight
- Falcon Discover
- Falcon Device Control
- Falcon Firewall Management
- Falcon Identity Protection
- Falcon Spotlight
Incident Response & Threat Hunting
- Lead investigation of advanced malware, ransomware, phishing, and endpoint compromise incidents.
- Perform root cause analysis of security events.
- Conduct proactive threat hunting using Falcon Real-Time Response (RTR).
- Analyze Indicators of Compromise (IOC) and Indicators of Attack (IOA).
- Support containment, eradication, and recovery activities.
Engineering & Automation
- Design security use cases and detection rules.
- Develop automation using Falcon APIs.
- Integrate CrowdStrike with:
- Microsoft Sentinel
- Splunk
- QRadar
- ServiceNow
- SOAR platforms
- Create custom dashboards, reporting, and alerting mechanisms.
Advanced Troubleshooting
- Act as L3 escalation point for CrowdStrike platform issues.
- Troubleshoot sensor installation and upgrade failures.
- Resolve endpoint communication and performance issues.
- Support large-scale deployment and migration initiatives.
Security Governance & Compliance
- Support security audits and compliance requirements.
- Generate vulnerability and threat exposure reports.
- Implement security best practices and hardening recommendations.
- Participate in security reviews and risk assessments.
Technical Skills Required
Mandatory
- CrowdStrike Falcon Administration
- Falcon RTR (Real-Time Response)
- EDR/XDR Operations
- Threat Hunting
- Endpoint Security
- Incident Response
- Malware Analysis
- IOC/IOA Investigation
- Windows Server Administration
- Windows 10/11 Endpoint Management
Frequently Asked Questions
Is the salary disclosed for the Subject Matter Expert (Support&Ops) position at HCLTech?
Where is the Subject Matter Expert (Support&Ops) position at HCLTech located?
How do I apply for the Subject Matter Expert (Support&Ops) position at HCLTech?
When was the Subject Matter Expert (Support&Ops) job at HCLTech posted?
You'll be redirected to HCLTech's official application page on successfactors.