Subject Matter Expert (Support&Ops)

Apply Now โ†—
๐Ÿ“ Gautam Buddha Nagar, India

About this role

Job Summary

Role Summary

The CrowdStrike Falcon L3 Engineer is responsible for advanced administration, engineering, troubleshooting, threat hunting, incident response, and operational support of the CrowdStrike Falcon platform. The role serves as the highest technical escalation point for endpoint security incidents, platform optimization, integrations, and security investigations.

Key Responsibilities

Platform Administration

  • Manage and administer the CrowdStrike Falcon platform.
  • Configure and maintain prevention policies, detection policies, firewall management, USB device control, and sensor deployment.
  • Perform health checks and platform optimization activities.
  • Manage Falcon modules including:
    • Falcon Prevent
    • Falcon Insight
    • Falcon Discover
    • Falcon Device Control
    • Falcon Firewall Management
    • Falcon Identity Protection
    • Falcon Spotlight

Incident Response & Threat Hunting

  • Lead investigation of advanced malware, ransomware, phishing, and endpoint compromise incidents.
  • Perform root cause analysis of security events.
  • Conduct proactive threat hunting using Falcon Real-Time Response (RTR).
  • Analyze Indicators of Compromise (IOC) and Indicators of Attack (IOA).
  • Support containment, eradication, and recovery activities.

Engineering & Automation

  • Design security use cases and detection rules.
  • Develop automation using Falcon APIs.
  • Integrate CrowdStrike with:
    • Microsoft Sentinel
    • Splunk
    • QRadar
    • ServiceNow
    • SOAR platforms
  • Create custom dashboards, reporting, and alerting mechanisms.

Advanced Troubleshooting

  • Act as L3 escalation point for CrowdStrike platform issues.
  • Troubleshoot sensor installation and upgrade failures.
  • Resolve endpoint communication and performance issues.
  • Support large-scale deployment and migration initiatives.

Security Governance & Compliance

  • Support security audits and compliance requirements.
  • Generate vulnerability and threat exposure reports.
  • Implement security best practices and hardening recommendations.
  • Participate in security reviews and risk assessments.

Technical Skills Required

Mandatory

  • CrowdStrike Falcon Administration
  • Falcon RTR (Real-Time Response)
  • EDR/XDR Operations
  • Threat Hunting
  • Endpoint Security
  • Incident Response
  • Malware Analysis
  • IOC/IOA Investigation
  • Windows Server Administration
  • Windows 10/11 Endpoint Management

Key Responsibilities

Role Summary

The CrowdStrike Falcon L3 Engineer is responsible for advanced administration, engineering, troubleshooting, threat hunting, incident response, and operational support of the CrowdStrike Falcon platform. The role serves as the highest technical escalation point for endpoint security incidents, platform optimization, integrations, and security investigations.

Key Responsibilities

Platform Administration

  • Manage and administer the CrowdStrike Falcon platform.
  • Configure and maintain prevention policies, detection policies, firewall management, USB device control, and sensor deployment.
  • Perform health checks and platform optimization activities.
  • Manage Falcon modules including:
    • Falcon Prevent
    • Falcon Insight
    • Falcon Discover
    • Falcon Device Control
    • Falcon Firewall Management
    • Falcon Identity Protection
    • Falcon Spotlight

Incident Response & Threat Hunting

  • Lead investigation of advanced malware, ransomware, phishing, and endpoint compromise incidents.
  • Perform root cause analysis of security events.
  • Conduct proactive threat hunting using Falcon Real-Time Response (RTR).
  • Analyze Indicators of Compromise (IOC) and Indicators of Attack (IOA).
  • Support containment, eradication, and recovery activities.

Engineering & Automation

  • Design security use cases and detection rules.
  • Develop automation using Falcon APIs.
  • Integrate CrowdStrike with:
    • Microsoft Sentinel
    • Splunk
    • QRadar
    • ServiceNow
    • SOAR platforms
  • Create custom dashboards, reporting, and alerting mechanisms.

Advanced Troubleshooting

  • Act as L3 escalation point for CrowdStrike platform issues.
  • Troubleshoot sensor installation and upgrade failures.
  • Resolve endpoint communication and performance issues.
  • Support large-scale deployment and migration initiatives.

Security Governance & Compliance

  • Support security audits and compliance requirements.
  • Generate vulnerability and threat exposure reports.
  • Implement security best practices and hardening recommendations.
  • Participate in security reviews and risk assessments.

Technical Skills Required

Mandatory

  • CrowdStrike Falcon Administration
  • Falcon RTR (Real-Time Response)
  • EDR/XDR Operations
  • Threat Hunting
  • Endpoint Security
  • Incident Response
  • Malware Analysis
  • IOC/IOA Investigation
  • Windows Server Administration
  • Windows 10/11 Endpoint Management

Skill Requirements

Role Summary

The CrowdStrike Falcon L3 Engineer is responsible for advanced administration, engineering, troubleshooting, threat hunting, incident response, and operational support of the CrowdStrike Falcon platform. The role serves as the highest technical escalation point for endpoint security incidents, platform optimization, integrations, and security investigations.

Key Responsibilities

Platform Administration

  • Manage and administer the CrowdStrike Falcon platform.
  • Configure and maintain prevention policies, detection policies, firewall management, USB device control, and sensor deployment.
  • Perform health checks and platform optimization activities.
  • Manage Falcon modules including:
    • Falcon Prevent
    • Falcon Insight
    • Falcon Discover
    • Falcon Device Control
    • Falcon Firewall Management
    • Falcon Identity Protection
    • Falcon Spotlight

Incident Response & Threat Hunting

  • Lead investigation of advanced malware, ransomware, phishing, and endpoint compromise incidents.
  • Perform root cause analysis of security events.
  • Conduct proactive threat hunting using Falcon Real-Time Response (RTR).
  • Analyze Indicators of Compromise (IOC) and Indicators of Attack (IOA).
  • Support containment, eradication, and recovery activities.

Engineering & Automation

  • Design security use cases and detection rules.
  • Develop automation using Falcon APIs.
  • Integrate CrowdStrike with:
    • Microsoft Sentinel
    • Splunk
    • QRadar
    • ServiceNow
    • SOAR platforms
  • Create custom dashboards, reporting, and alerting mechanisms.

Advanced Troubleshooting

  • Act as L3 escalation point for CrowdStrike platform issues.
  • Troubleshoot sensor installation and upgrade failures.
  • Resolve endpoint communication and performance issues.
  • Support large-scale deployment and migration initiatives.

Security Governance & Compliance

  • Support security audits and compliance requirements.
  • Generate vulnerability and threat exposure reports.
  • Implement security best practices and hardening recommendations.
  • Participate in security reviews and risk assessments.

Technical Skills Required

Mandatory

  • CrowdStrike Falcon Administration
  • Falcon RTR (Real-Time Response)
  • EDR/XDR Operations
  • Threat Hunting
  • Endpoint Security
  • Incident Response
  • Malware Analysis
  • IOC/IOA Investigation
  • Windows Server Administration
  • Windows 10/11 Endpoint Management

Other Requirements

Role Summary

The CrowdStrike Falcon L3 Engineer is responsible for advanced administration, engineering, troubleshooting, threat hunting, incident response, and operational support of the CrowdStrike Falcon platform. The role serves as the highest technical escalation point for endpoint security incidents, platform optimization, integrations, and security investigations.

Key Responsibilities

Platform Administration

  • Manage and administer the CrowdStrike Falcon platform.
  • Configure and maintain prevention policies, detection policies, firewall management, USB device control, and sensor deployment.
  • Perform health checks and platform optimization activities.
  • Manage Falcon modules including:
    • Falcon Prevent
    • Falcon Insight
    • Falcon Discover
    • Falcon Device Control
    • Falcon Firewall Management
    • Falcon Identity Protection
    • Falcon Spotlight

Incident Response & Threat Hunting

  • Lead investigation of advanced malware, ransomware, phishing, and endpoint compromise incidents.
  • Perform root cause analysis of security events.
  • Conduct proactive threat hunting using Falcon Real-Time Response (RTR).
  • Analyze Indicators of Compromise (IOC) and Indicators of Attack (IOA).
  • Support containment, eradication, and recovery activities.

Engineering & Automation

  • Design security use cases and detection rules.
  • Develop automation using Falcon APIs.
  • Integrate CrowdStrike with:
    • Microsoft Sentinel
    • Splunk
    • QRadar
    • ServiceNow
    • SOAR platforms
  • Create custom dashboards, reporting, and alerting mechanisms.

Advanced Troubleshooting

  • Act as L3 escalation point for CrowdStrike platform issues.
  • Troubleshoot sensor installation and upgrade failures.
  • Resolve endpoint communication and performance issues.
  • Support large-scale deployment and migration initiatives.

Security Governance & Compliance

  • Support security audits and compliance requirements.
  • Generate vulnerability and threat exposure reports.
  • Implement security best practices and hardening recommendations.
  • Participate in security reviews and risk assessments.

Technical Skills Required

Mandatory

  • CrowdStrike Falcon Administration
  • Falcon RTR (Real-Time Response)
  • EDR/XDR Operations
  • Threat Hunting
  • Endpoint Security
  • Incident Response
  • Malware Analysis
  • IOC/IOA Investigation
  • Windows Server Administration
  • Windows 10/11 Endpoint Management

Frequently Asked Questions

Is the salary disclosed for the Subject Matter Expert (Support&Ops) position at HCLTech?
The salary for this Subject Matter Expert (Support&Ops) role at HCLTech is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Subject Matter Expert (Support&Ops) position at HCLTech located?
This Subject Matter Expert (Support&Ops) role at HCLTech is based in Gautam Buddha Nagar, India. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
How do I apply for the Subject Matter Expert (Support&Ops) position at HCLTech?
Click the "Apply Now" button on this page. You will be redirected to HCLTech's official application portal hosted on successfactors where you can submit your application directly.
When was the Subject Matter Expert (Support&Ops) job at HCLTech posted?
This Subject Matter Expert (Support&Ops) position at HCLTech was posted on Sep 14, 2026. Apply as soon as possible โ€” early applications are often reviewed first.
Subject Matter Expert (Support&Ops)
HCLTech
Apply for this role โ†—

You'll be redirected to HCLTech's official application page on successfactors.