Bloom Energy, a solid oxide fuel cell company, is looking for a Senior Engineer II – SOC, to join its world-class team.
Key Responsibilities
Lead security assessments, threat analysis, and vulnerability management using Falcon Exposure Management and Falcon Discover for asset discovery, risk-based prioritization, and continuous attack-surface reduction.
Own and optimize the endpoint security stack — Falcon Prevent (NGAV), Falcon Insight (EDR/XDR), Falcon Device Control, and Falcon Firewall Management — including policy design, detection tuning, and Real Time Response (RTR) containment.
Serve as the in-house L3 escalation owner and incident commander for alerts handed off by Falcon Complete Next-Gen MDR and Adversary OverWatch, driving triage, root-cause analysis, and corrective action plans.
Engineer and administer Falcon Next-Gen SIEM — data ingestion, retention, correlation content, dashboards, and build automated playbooks in Charlotte AI Agentic SOAR.
Operate and mature cloud security through Falcon Cloud Security (CNAPP), including Cloud Detection & Response (CDR), container security (Falcon for Managed Containers), and posture management across AWS/Azure workloads (EC2/ECS/EKS).
Implement and manage Identity Threat Detection & Response (ITDR) via Identity Threat Protection and Next-Gen Identity Security Privileged (NGIS+), enforcing Zero Trust, Just-in-Time / privileged access.
Implement, monitor and optimise gaps in Falcon SaaS Security Posture Management (SSPM).
Deploy and administer AIDR for Workforce to secure enterprise AI usage (shadow AI, prompt injection, data leakage) and Falcon Data Protection for DLP and data-loss controls.
Operationalise Falcon Intelligence Recon for threat intel, digital-risk / brand-exposure monitoring, and intelligence-led detection.
Manage Falcon Secure Access for enterprise browser security and friction-free managed browsing.
Develop automation for security monitoring and compliance checks across the Falcon platform using its APIs and Charlotte AI/SOAR.
Design secure system architectures (cloud, on-prem, hybrid) anchored on the Falcon agent.
Define security standards, frameworks, and controls as might be required for the SOC operation.
Align security with cyber risk and compliance needs.
Design SIEM architecture, define and implement Zero Trust for IAM strategy on the Falcon platform.
Drive Security Operations and SOC Security-Maturity Improvement.
Govern MDR relationship and close control gaps through various SOC tools.
Collaborate with various teams and stakeholders to strengthen the overall security posture, and document security designs, processes, and best practices.
Requirements
Deep, hands-on expertise operating the CrowdStrike Falcon platform end-to-end (Prevent, Insight/EDR-XDR, Device Control, Firewall Management, Discover, RTR) as a single-agent, single-console environment.
Proven experience with Falcon Complete MDR and Adversary OverWatch operating models and L3-in-house escalation workflows.
Strong expertise in Falcon Next-Gen SIEM and Charlotte AI Agentic SOAR — ingestion, retention, correlation rules, dashboards, and automated response playbooks.
Hands-on experience with Falcon Cloud Security (CNAPP/CDR) and container security across AWS/Azure (EC2, ECS, EKS).
Experience implementing Identity Threat Detection & Response (ITDR), NGIS+ privileged access, SSPM, Zero Trust and IAM strategy.
Familiarity with AIDR for Workforce, Falcon Data Protection (DLP), Falcon Adversary Intelligence Premium, Recon+, and Falcon Secure Access.
Strong understanding of security frameworks (NIST, ISO 27001, CIS, CSF) and the ability to establish system controls and access levels based on NIST standards; recommending improvements.
Ensure authorized access by investigating improper access, revoking access, reporting violations, monitoring information requests, and recommending improvements — leveraging Falcon ITDR/NGIS+ telemetry.
Strong scripting/automation skills (Python, PowerShell, Bash) and experience with the CrowdStrike Falcon API for integration and automation.
Ability to investigate complex security issues and drive resolutions; excellent communication and cross-functional collaboration skills.