CrowdStrike
Sunnyvale, California
As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn't changed - we're here to stop breaches, and we've redefined modern security with the world's most advanced AI-native platform. We work on large scale distributed systems, processing almost 3 trillion events per day and this traffic is growing daily. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We're proud to work for a mission-driven company leveraging AI to transform the way we work. CrowdStrikers drive their careers through flexibility and autonomy while also being expected to contribute to a culture of responsible AI adoption, experimentation, and innovation. We use an AI-first mindset as a force multiplier to proactively and continuously accelerate execution, build expertise, uncover insights, and solve complex problems. We're always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you. About the Role: CrowdStrike is looking for a Vulnerability Management Engineer for our Exposure Management group. This is an Individual Contributor role in the Exposure Management Content team responsible for researching, developing and delivering our Host and Network Vulnerability Assessment detections for CrowdStrike as also collaborating on the development of new features and technical solutions. This role is hybrid, requiring 2-3 days per week on-site at our Sunnyvale, CA office. This person would work closely with other internal teams and product management to understand the requirements and needs on Vulnerability Detection capabilities for the product. They will be technically involved in the capabilities for Exposure Management to detect, track, report and prioritize vulnerabilities on assets. Strong communication and organizational skills are essential. The successful candidate should have had experience within Exposure Management, Vulnerability Analysis and Detection and be able to develop detection pipelines for vulnerabilities and other threats. Work experience in the security industry is highly desirable, including a strong understanding of some of the current prevalent products in this space. What You'll Do: Collaborate and lead a Team of Vulnerability Detection Engineers and Researchers to plan, coordinate and execute Vulnerability Detection Coverage for Exposure Management Supported Platforms Participate and lead Company Thought Leadership efforts and guidance for analysis on prevalent vulnerabilities and Risk Based Vulnerability Management. Vulnerability data discovery and validation (Data efficacy & Accuracy) Collaborate with multi-functional teams across various physical locations including product management and other engineering disciplines. Lead and manage other projects as assigned AI-Enhanced Vulnerability Detection Research: Leverage generative AI tools to accelerate vulnerability analysis, proof-of-concept development, and detection rule creation while maintaining human oversight for validation and detection accuracy. Intelligent Vulnerability Assessment Pipeline: Design and implement AI agent workflows to automate multi-step vulnerability validation processes (e.g., discovery, analysis, prioritization, remediation guidance) while ensuring human-in-the-loop verification for critical vulnerability detections and false positive reduction. What You'll Need: Minimum 5 years of overall experience as an Individual Contributor. Experience in management and leadership roles is a plus. Ability and desire to being hands on as well as empowering peers while collaborating across different functional areas and products Ability to develop, coordinate and execute on an engineering roadmap Ability to communicate and articulate crisply at all levels from executive staff to engineers Ability to communicate, collaborate, and work effectively in a distributed team Familiarity and experience with the Agile process Experience in Cybersecurity Industry Programming/scripting knowledge for automating day to day tasks - Python/ Perl, Golang. Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes. Bachelors Degree in Computer Science/Engineering Required Skills: Understanding of Vulnerabilities, mitigations and remediations Understanding of Vulnerability and Software Detection techniques Understanding of Vulnerability Prioritization Models Experience with Security/Vulnerability detections development and release Experience of Vulnerability Management product development Experience designing and implementing validation workflows for Security Based products Experience working in remote & distributed environments Solid design and problem-solving skills with a demonstrated passion for engineering excellence, pragmatism, quality, security, and performance Experience with Go and/or Python automation Experience with AI/ML models is a plus Benefits of Working at CrowdStrike: Market leader in compensation and equity awards Comprehensive physical and mental wellness programs Competitive vacation and holidays for recharge Paid parental and adoption leaves Professional development opportunities for all employees regardless of level or role Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections Vibrant office culture with world class amenities Great Place to Work Certified across the globe CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program. CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs on valid job requirements. If you need assistance accessing or reviewing the information on this website or need help submitting an application for employment or requesting an accommodation, please contact us at for further assistance. Find out more about your rights as an applicant. CrowdStrike participates in the E-Verify program. Notice of E-Verify Participation Right to Work CrowdStrike, Inc. is committed to fair and equitable compensation practices. Placement within the pay range is dependent on a variety of factors including, but not limited to, relevant work experience, skills, certifications, job level, supervisory status, and location. The base salary range for this position for all U.S. candidates is $100,000 - $145,000 per year, with eligibility for bonuses, equity grants and a comprehensive benefits package that includes health insurance, 401k and paid time off. For detailed information about the U.S. benefits package, please click here.
As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn't changed - we're here to stop breaches, and we've redefined modern security with the world's most advanced AI-native platform. We work on large scale distributed systems, processing almost 3 trillion events per day and this traffic is growing daily. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We're proud to work for a mission-driven company leveraging AI to transform the way we work. CrowdStrikers drive their careers through flexibility and autonomy while also being expected to contribute to a culture of responsible AI adoption, experimentation, and innovation. We use an AI-first mindset as a force multiplier to proactively and continuously accelerate execution, build expertise, uncover insights, and solve complex problems. We're always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you. About the Role: CrowdStrike is looking for a Vulnerability Management Engineer for our Exposure Management group. This is an Individual Contributor role in the Exposure Management Content team responsible for researching, developing and delivering our Host and Network Vulnerability Assessment detections for CrowdStrike as also collaborating on the development of new features and technical solutions. This role is hybrid, requiring 2-3 days per week on-site at our Sunnyvale, CA office. This person would work closely with other internal teams and product management to understand the requirements and needs on Vulnerability Detection capabilities for the product. They will be technically involved in the capabilities for Exposure Management to detect, track, report and prioritize vulnerabilities on assets. Strong communication and organizational skills are essential. The successful candidate should have had experience within Exposure Management, Vulnerability Analysis and Detection and be able to develop detection pipelines for vulnerabilities and other threats. Work experience in the security industry is highly desirable, including a strong understanding of some of the current prevalent products in this space. What You'll Do: Collaborate and lead a Team of Vulnerability Detection Engineers and Researchers to plan, coordinate and execute Vulnerability Detection Coverage for Exposure Management Supported Platforms Participate and lead Company Thought Leadership efforts and guidance for analysis on prevalent vulnerabilities and Risk Based Vulnerability Management. Vulnerability data discovery and validation (Data efficacy & Accuracy) Collaborate with multi-functional teams across various physical locations including product management and other engineering disciplines. Lead and manage other projects as assigned AI-Enhanced Vulnerability Detection Research: Leverage generative AI tools to accelerate vulnerability analysis, proof-of-concept development, and detection rule creation while maintaining human oversight for validation and detection accuracy. Intelligent Vulnerability Assessment Pipeline: Design and implement AI agent workflows to automate multi-step vulnerability validation processes (e.g., discovery, analysis, prioritization, remediation guidance) while ensuring human-in-the-loop verification for critical vulnerability detections and false positive reduction. What You'll Need: Minimum 5 years of overall experience as an Individual Contributor. Experience in management and leadership roles is a plus. Ability and desire to being hands on as well as empowering peers while collaborating across different functional areas and products Ability to develop, coordinate and execute on an engineering roadmap Ability to communicate and articulate crisply at all levels from executive staff to engineers Ability to communicate, collaborate, and work effectively in a distributed team Familiarity and experience with the Agile process Experience in Cybersecurity Industry Programming/scripting knowledge for automating day to day tasks - Python/ Perl, Golang. Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes. Bachelors Degree in Computer Science/Engineering Required Skills: Understanding of Vulnerabilities, mitigations and remediations Understanding of Vulnerability and Software Detection techniques Understanding of Vulnerability Prioritization Models Experience with Security/Vulnerability detections development and release Experience of Vulnerability Management product development Experience designing and implementing validation workflows for Security Based products Experience working in remote & distributed environments Solid design and problem-solving skills with a demonstrated passion for engineering excellence, pragmatism, quality, security, and performance Experience with Go and/or Python automation Experience with AI/ML models is a plus Benefits of Working at CrowdStrike: Market leader in compensation and equity awards Comprehensive physical and mental wellness programs Competitive vacation and holidays for recharge Paid parental and adoption leaves Professional development opportunities for all employees regardless of level or role Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections Vibrant office culture with world class amenities Great Place to Work Certified across the globe CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program. CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs on valid job requirements. If you need assistance accessing or reviewing the information on this website or need help submitting an application for employment or requesting an accommodation, please contact us at for further assistance. Find out more about your rights as an applicant. CrowdStrike participates in the E-Verify program. Notice of E-Verify Participation Right to Work CrowdStrike, Inc. is committed to fair and equitable compensation practices. Placement within the pay range is dependent on a variety of factors including, but not limited to, relevant work experience, skills, certifications, job level, supervisory status, and location. The base salary range for this position for all U.S. candidates is $100,000 - $145,000 per year, with eligibility for bonuses, equity grants and a comprehensive benefits package that includes health insurance, 401k and paid time off. For detailed information about the U.S. benefits package, please click here.
Idaho National Laboratory
Idaho Falls, Idaho
Position Summary: Ensure the appropriate operational security posture for the Specific Manufacturing Capability (SMC) Information System (IS) is maintained to include ensuring implementation of DoW and SMC Site cybersecurity policies, practices, and procedures. Work with IS owners and the IS Information System Security Manager (ISSM) and serve as advisor on all matters, technical and otherwise, involving security of the IS. Essential Job Functions and Responsibilities: (Knowledge, skills, and behaviors required for this position.) Conduct audits of SMC IS to ensure compliance with Joint Special Access Program (SAP) Implementation Guide (JSIG), DoW Cybersecurity Service Provider (CSSP) requirements. Lead and direct the development of IS accreditation packages (i.e., system security plan, security control assessment, risk assessment, etc.) in accordance with federal directives and the Risk Management Framework (RMF). Report all security-related incidents to the ISSM. Integrate applicable IS requirements, controls, and processes into design specifications in accordance with DoW established standards, policies, procedures, guidelines, directives, and regulations and laws (statutes). Act as the subject matter expert (SME) in the security of basic network and telecommunications services/data (e.g., perimeter defense strategies, defense-in-depth strategies, and data encryption techniques). Understand the policies, procedures, and controls required to protect network and telecommunication services and assess technical, operational, and administrative security controls as mandated by RMF standards. Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change. Ensure audit records are collected, reviewed, and documented (to include any anomalies). Ensure all IS security-related documentation is current and accessible to properly authorized individuals. Lead others in maintaining change control, ensuring configuration management of the IS to protect the system and data in accordance with technical, operational, and administrative security control requirements. Perform a variety of data collection, analysis, reporting and briefing activities associated with security operations and maintenance to ensure that the organizational security policies are implemented and maintained on the IS. Verify cybersecurity awareness training and requirements are current for IS users based on identified needs and organizational policies and within organizational time frames. Develop IS training material as needed to support end-user training requirements. Coordinate with the appropriate management and security offices to ensure IS users have the required security clearances and need-to-know authorizations before accessing information systems. Collect and track required documentation for IS user accounts. Identify, categorize, investigate, isolate, assess, and report IS cybersecurity incidents in coordination with other organizations. Coordinate with the appropriate security offices to ensure that physical controls are implemented as required. Participate in the creation, review, and assessment of policies and procedures supporting the secure use and operation of SMC information systems that includes, but is not limited to, system security plans, vulnerability management, risk management, configuration management, change management, and others. Promote awareness of cyber policy and strategy as appropriate among management and ensure sound principles are reflected in the organization's mission, vision, and goals. Assist the ISSM in meeting their duties and responsibilities. The ISSO shall assume ISSM responsibilities in the absence of the ISSM. Attend required technical and security training (e.g., operating system, networking, security management) relative to assigned duties Maintain required IA certifications. Other duties as assigned. Education, Credentials, and Work Experience: Required Level 4 -Bachelor's and 9 years of experience. Master's and 6 years of experience. PhD and 4 years of experience. Relevant experience commensurate with level. DoD 8570/8140 IAM Level II certification. IAM Level II certifications include CISSP, CAP, CISM, and GSLC. CISSP or CISM preferred .If candidate has relevant experience commensurate with level, IAM Level II may be obtained within 6 months of hire. Working experience with NIST 800-53, CNSS 1253, FISMA, and/or JSIG Rev 4. Strong analytical and problem-solving skills. Must be a US Citizen and hold an active DOE "Q" clearance (or DOD/DOJ equivalent) Strong analytical and problem-solving skills. Physical Requirements: While performing the duties of this classification, the employee is frequently required to stand, walk, sit, stoop, kneel, bend, use hands to handle materials, manipulate tools, keyboard and type, reach with hands and arms, and operate job-related equipment. The employee must occasionally lift and/or move up to 30 pounds. Sufficient visual acuity and hearing capacity to perform the essential functions and interact with people is required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions Working Conditions: The work environment is an office environment which may include stairs. The noise level is generally moderate; however, may be exposed to loud noises on occasion. Position requires working more than 8 hours/day, irregular hours, and working alone. The above statements are intended to describe the general nature and levels of work being performed by people assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of personnel so classified. Security and Privacy Language: This position includes information security and privacy responsibilities as defined by NIST SP , OMB Circular A 130, and DOE Order 206.1A. Position must complete initial and annual role-specific training as required. The incumbent must sign and comply with all required access agreements prior to being granted access to organizational systems or data. Comply with all applicable information security and privacy policies and procedures by following established protocols, with an understanding that non-compliance may result in sanctions. Benefits and Relocation Medical, Dental, Vision, and Flexible Spending Accounts 401(k) with a 4.2% employer contribution and up to 4.8% match (regular positions) or self-contribute access (postdoctoral positions) Paid time off (personal leave) Employee Education Program (tuition assistance for eligible positions) Comprehensive Relocation Package Benefit eligibility subject to multiple factors, including employment status and position classification. At this time, BEA will not sponsor any H1-B visas obtained outside of the United States of America (U.S.A.), including consular visas. INL is a science-based, applied engineering national laboratory dedicated to supporting the U.S. Department of Energy's mission in nuclear energy research, science, and national defense. With more than 6,300 scientists, researchers, and support staff, the laboratory works with national and international governments, universities and industry partners to change the world's energy future and secure our nation's critical infrastructure. INL Mission: Our mission is to discover, demonstrate and secure innovative nuclear energy solutions, other clean energy options and critical infrastructure. INL Vision: Our vision is to change the world's energy future and secure our nation's critical infrastructure. Selective Service Requirements: To be eligible for employment at INL males born after December 31, 1959 must have registered with the Selective Service System (SSS). For more information see . Equal Employment Opportunity: Idaho National Laboratory (INL) is an Equal Employment Opportunity (EEO) employer. It is the policy of INL to provide equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information. Reasonable Accommodation: We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation. Other Information: When applying to positions please provide a resume and answer all questions on the following screens. Applicants, who fail to provide a resume or answer the questions, may be deemed ineligible for consideration. INL does not accept resumes from third party vendors unsolicited.
Position Summary: Ensure the appropriate operational security posture for the Specific Manufacturing Capability (SMC) Information System (IS) is maintained to include ensuring implementation of DoW and SMC Site cybersecurity policies, practices, and procedures. Work with IS owners and the IS Information System Security Manager (ISSM) and serve as advisor on all matters, technical and otherwise, involving security of the IS. Essential Job Functions and Responsibilities: (Knowledge, skills, and behaviors required for this position.) Conduct audits of SMC IS to ensure compliance with Joint Special Access Program (SAP) Implementation Guide (JSIG), DoW Cybersecurity Service Provider (CSSP) requirements. Lead and direct the development of IS accreditation packages (i.e., system security plan, security control assessment, risk assessment, etc.) in accordance with federal directives and the Risk Management Framework (RMF). Report all security-related incidents to the ISSM. Integrate applicable IS requirements, controls, and processes into design specifications in accordance with DoW established standards, policies, procedures, guidelines, directives, and regulations and laws (statutes). Act as the subject matter expert (SME) in the security of basic network and telecommunications services/data (e.g., perimeter defense strategies, defense-in-depth strategies, and data encryption techniques). Understand the policies, procedures, and controls required to protect network and telecommunication services and assess technical, operational, and administrative security controls as mandated by RMF standards. Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change. Ensure audit records are collected, reviewed, and documented (to include any anomalies). Ensure all IS security-related documentation is current and accessible to properly authorized individuals. Lead others in maintaining change control, ensuring configuration management of the IS to protect the system and data in accordance with technical, operational, and administrative security control requirements. Perform a variety of data collection, analysis, reporting and briefing activities associated with security operations and maintenance to ensure that the organizational security policies are implemented and maintained on the IS. Verify cybersecurity awareness training and requirements are current for IS users based on identified needs and organizational policies and within organizational time frames. Develop IS training material as needed to support end-user training requirements. Coordinate with the appropriate management and security offices to ensure IS users have the required security clearances and need-to-know authorizations before accessing information systems. Collect and track required documentation for IS user accounts. Identify, categorize, investigate, isolate, assess, and report IS cybersecurity incidents in coordination with other organizations. Coordinate with the appropriate security offices to ensure that physical controls are implemented as required. Participate in the creation, review, and assessment of policies and procedures supporting the secure use and operation of SMC information systems that includes, but is not limited to, system security plans, vulnerability management, risk management, configuration management, change management, and others. Promote awareness of cyber policy and strategy as appropriate among management and ensure sound principles are reflected in the organization's mission, vision, and goals. Assist the ISSM in meeting their duties and responsibilities. The ISSO shall assume ISSM responsibilities in the absence of the ISSM. Attend required technical and security training (e.g., operating system, networking, security management) relative to assigned duties Maintain required IA certifications. Other duties as assigned. Education, Credentials, and Work Experience: Required Level 4 -Bachelor's and 9 years of experience. Master's and 6 years of experience. PhD and 4 years of experience. Relevant experience commensurate with level. DoD 8570/8140 IAM Level II certification. IAM Level II certifications include CISSP, CAP, CISM, and GSLC. CISSP or CISM preferred .If candidate has relevant experience commensurate with level, IAM Level II may be obtained within 6 months of hire. Working experience with NIST 800-53, CNSS 1253, FISMA, and/or JSIG Rev 4. Strong analytical and problem-solving skills. Must be a US Citizen and hold an active DOE "Q" clearance (or DOD/DOJ equivalent) Strong analytical and problem-solving skills. Physical Requirements: While performing the duties of this classification, the employee is frequently required to stand, walk, sit, stoop, kneel, bend, use hands to handle materials, manipulate tools, keyboard and type, reach with hands and arms, and operate job-related equipment. The employee must occasionally lift and/or move up to 30 pounds. Sufficient visual acuity and hearing capacity to perform the essential functions and interact with people is required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions Working Conditions: The work environment is an office environment which may include stairs. The noise level is generally moderate; however, may be exposed to loud noises on occasion. Position requires working more than 8 hours/day, irregular hours, and working alone. The above statements are intended to describe the general nature and levels of work being performed by people assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of personnel so classified. Security and Privacy Language: This position includes information security and privacy responsibilities as defined by NIST SP , OMB Circular A 130, and DOE Order 206.1A. Position must complete initial and annual role-specific training as required. The incumbent must sign and comply with all required access agreements prior to being granted access to organizational systems or data. Comply with all applicable information security and privacy policies and procedures by following established protocols, with an understanding that non-compliance may result in sanctions. Benefits and Relocation Medical, Dental, Vision, and Flexible Spending Accounts 401(k) with a 4.2% employer contribution and up to 4.8% match (regular positions) or self-contribute access (postdoctoral positions) Paid time off (personal leave) Employee Education Program (tuition assistance for eligible positions) Comprehensive Relocation Package Benefit eligibility subject to multiple factors, including employment status and position classification. At this time, BEA will not sponsor any H1-B visas obtained outside of the United States of America (U.S.A.), including consular visas. INL is a science-based, applied engineering national laboratory dedicated to supporting the U.S. Department of Energy's mission in nuclear energy research, science, and national defense. With more than 6,300 scientists, researchers, and support staff, the laboratory works with national and international governments, universities and industry partners to change the world's energy future and secure our nation's critical infrastructure. INL Mission: Our mission is to discover, demonstrate and secure innovative nuclear energy solutions, other clean energy options and critical infrastructure. INL Vision: Our vision is to change the world's energy future and secure our nation's critical infrastructure. Selective Service Requirements: To be eligible for employment at INL males born after December 31, 1959 must have registered with the Selective Service System (SSS). For more information see . Equal Employment Opportunity: Idaho National Laboratory (INL) is an Equal Employment Opportunity (EEO) employer. It is the policy of INL to provide equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information. Reasonable Accommodation: We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation. Other Information: When applying to positions please provide a resume and answer all questions on the following screens. Applicants, who fail to provide a resume or answer the questions, may be deemed ineligible for consideration. INL does not accept resumes from third party vendors unsolicited.