CrowdStrike
Vulnerability Intelligence, Product Security (Remote)
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About CrowdStrike
CrowdStrike is a prominent cybersecurity technology company founded in 2011 and headquartered in Austin, Texas. The company operates with a remote-first model and focuses on cloud-native cybersecurity solutions. Its mission is to stop breaches by protecting organizations from sophisticated cyber adversaries. The flagship offering, the CrowdStrike Falcon platform, is an AI-powered solution that provides real-time protection for endpoints and cloud workloads. It includes features such as Endpoint Detection and Response (EDR), Next-Generation Antivirus (NGAV), threat intelligence, and managed threat hunting. This platform is designed to be scalable and effective, leveraging artificial intelligence and machine learning to enhance security. CrowdStrike serves a diverse range of customers, including major financial institutions, technology firms, and media companies. The company has gained recognition for its contributions to high-profile cybersecurity investigations and has received accolades for its innovation and leadership in the field.
Security at CrowdStrike
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- CrowdStrike's Application Security philosophy emphasizes setting a new standard in application security, partnering closely with product engineering teams, and prioritizing reachable threats that impact the business rather than chasing irrelevant vulnerability alerts.
- Key goals include securing the software development life cycle, leveraging monitoring and observability, and establishing an incident response plan.
Security Team
- CrowdStrike is seeking an experienced Engineering Manager to join and manage a team of Application Security Engineers, partnering closely with product engineering teams. Key skills include familiarity with AppSec tooling (SAST, DAST, etc.) and an understanding of AI-assisted development security implications.
- Publicly available information does not specify the AppSec team's reporting chain, key public-facing leaders, or an estimated team size.
Key Initiatives
CrowdStrike's AppSec initiatives include overseeing threat modeling and security architecture reviews, managing bug bounty program responses, and vulnerability remediation efforts. They emphasize securing the software development life cycle, leveraging monitoring and observability, and establishing an incident response plan. There is also a focus on understanding the security implications of AI-assisted development. Information on a Security Champions program or specific vulnerability remediation SLAs is not publicly available.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.