Senior Manager, CrowdStrike Cloud Security, Cyber Engineered Defense
$150k - $200kAt Kroll, we provide reactive, advisory, transformation, and managed security services to support clients at every stage of their path toward cyber and data resilience maturity. Our experts bring decades of experience in cyber risk consultancy, helping organizations across the world simplify and reduce the complexity of implementing, transforming, and managing their cyber programs. Through our strategic multi-year partnership with CrowdStrike, we combine world-class investigative expertise with an AI-native platform to redefine the future of managed detection and response, delivering faster outcomes, stronger protection, and greater resilience for organizations worldwide.
The Cyber & Data Resilience capability is hiring a Manager or Senior Manager to build and lead Kroll's CrowdStrike Falcon Cloud Security deployment practice . Falcon Cloud Security is the industry's first unified Cloud-Native Application Protection Platform (CNAPP), spanning CSPM, CWP, CIEM, KSPM, ASPM, DSPM, IaC scanning, and container and Kubernetes runtime protection across AWS, Azure, and Google Cloud — delivered through one sensor and one console, with both agent-based and agentless coverage.
Kroll clients need a partner who can deploy, configure, integrate, and tune Falcon Cloud Security end-to-end inside their Falcon tenant — registering cloud accounts at scale across AWS Organizations, Azure tenants, and GCP projects; rolling out runtime protection across VMs, containers, and Kubernetes; wiring cloud log telemetry into Falcon Next-Gen SIEM for detection engineering; building Fusion SOAR playbooks for cloud-native response; and tuning IOM (Indicators of Misconfiguration) and IOA (Indicators of Attack) policies to maximize signal and minimize noise in each client's cloud estate.
This is a player-coach role . The “Manager” or “Senior Manager” title does not mean hands-off oversight. You will personally lead engagement delivery — onboarding cloud accounts, deploying sensors and admission controllers, configuring CNAPP modules, building detection content, and integrating with the broader Falcon stack — while mentoring junior consultants and partnering with CrowdStrike account teams on scoping.
This role reports into the Engineered Defense / Tech Transformation leadership team and partners closely with Kroll’s Identity, Next-Gen SIEM, AIDR, and CrowdStrike Services delivery teams.
Deploy
Onboard client AWS, Azure, and GCP environments to Falcon Cloud Security at scale — using AWS CloudFormation StackSets across AWS Organizations, Bicep / Entra ID integrations for Azure tenants and management groups, and service account patterns for GCP projects and folders.
Deploy the Falcon sensor across cloud workloads — EC2 / Azure VMs / GCE instances, container hosts, Kubernetes nodes — and stand up agentless snapshot-based scanning to fill coverage gaps.
Deploy the Kubernetes Admission Controller to enforce pre-runtime policy on workload admission across EKS, AKS, GKE, and self-managed Kubernetes.
Roll out container image registry scanning and IaC scanning (Terraform, CloudFormation, ARM/Bicep, Kubernetes manifests, Helm) into client CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, Azure DevOps).
Enable serverless protection for AWS Lambda, Azure Functions, and GCP Cloud Functions.
Stand up CIEM across cloud identity providers (IAM users, roles, service accounts, managed identities) for least-privilege analysis.
Configure
Configure CSPM policies — IOM rules, custom misconfiguration detections, compliance frameworks (CIS Benchmarks, NIST, PCI-DSS, HIPAA, SOC 2), and exception management.
Configure CWP runtime policies — IOA detections, prevention policies, container runtime protection, drift detection.
Configure KSPM policies — Kubernetes posture, pod security standards, admission control rules, RBAC analysis.
Configure ASPM and DSPM policies for application-security posture and data-security posture across cloud data stores.
Configure CIEM — effective permission analysis, toxic combinations, privilege right-sizing, service-account hygiene.
Configure ExPRT.AI risk prioritization to surface attack paths and toxic combinations across CSPM/CWP/CIEM signals.
Build and tune custom detection content (IOAs, IOMs, CQL queries) for cloud-native attack techniques mapped to MITRE ATT&CK Cloud Matrix.
Integrate
Ingest cloud log telemetry into Falcon Next-Gen SIEM (LogScale) — AWS CloudTrail, GuardDuty findings, VPC Flow Logs, S3 access logs; Azure Activity Log, Defender for Cloud alerts, NSG Flow Logs, Entra ID sign-in logs; GCP Audit Logs, VPC Flow Logs, Security Command Center findings; EKS / AKS / GKE control plane logs; Kubernetes audit logs.
Build detection engineering content in Next-Gen SIEM correlating Falcon Cloud Security findings with cloud provider native logs, endpoint telemetry, and identity events for full attack-path visibility.
Build Falcon Fusion SOAR playbooks for cloud-native response actions: quarantine compromised workload, revoke IAM credential, isolate Kubernetes pod, remediate misconfiguration via IaC pull request, trigger MFA via Falcon Identity Protection.
Integrate Falcon Cloud Security with Falcon Identity Protection for cross-domain correlation between cloud workload activity and identity risk.
Integrate Falcon Cloud Security with Falcon Insight (EDR) for unified endpoint + cloud workload protection.
Integrate Falcon Cloud Security with Falcon AIDR for AI workload runtime protection in Kubernetes.
Build Charlotte AI prompts and agentic workflows for cloud event triage, misconfiguration remediation guidance, and executive cloud-risk reporting.
Tune and Operate
Tune IOM and IOA policies to reduce false positives without sacrificing detection efficacy.
Tune ExPRT.AI prioritization and attack path analysis to client risk tolerance and remediation capacity.
Optimize sensor performance and agentless scan cadence for cost and coverage balance.
Validate detection coverage through controlled adversary emulation against the MITRE ATT&CK Cloud Matrix.
Hand off operational runbooks to client cloud security teams and Kroll Managed Services for ongoing operation.
Advise (scoped to the platform)
Advise client cloud platform, DevSecOps, and SOC engineering teams on Falcon Cloud Security deployment architecture — agent vs. agentless coverage decisions, account onboarding patterns, Kubernetes admission control posture, IaC scanning policy in CI/CD, and integration with existing Falcon modules.
Partner with CrowdStrike account teams on Falcon Cloud Security pre-sales scoping, solution design, proof-of-value engagements, and joint go-to-market motions.
Build the Practice
Develop reusable Falcon Cloud Security deployment runbooks, configuration templates (Terraform, Bicep), integration patterns, Fusion SOAR playbook libraries, custom IOM/IOA detection libraries, and Charlotte AI workflow templates.
Mentor consultants on Falcon Cloud Security deployment and integration.
Hiring Requirements:
5+ years (Manager) or 7+ years (Senior Manager) of hands-on experience deploying, configuring, and operating cloud security tooling in enterprise environments — with a meaningful concentration in CNAPP, CSPM, CWP, or container/Kubernetes security.
Hands-on deployment experience with the CrowdStrike Falcon platform — direct experience with Falcon Cloud Security (CSPM, CWP, CIEM, KSPM, IaC scanning) is required. Equivalent hands-on with a competing CNAPP (Wiz, Prisma Cloud, Lacework, Aqua, Sysdig, Orca) plus willingness to ramp on Falcon Cloud Security is acceptable.
Demonstrated experience deploying, configuring, and integrating cloud security platforms across AWS, Azure, and GCP — not just operating them post-deployment. Working depth across at least two of the three hyperscalers is required.
Hands-on with Kubernetes security — EKS, AKS, GKE, or self-managed; Pod Security Standards; admission controllers; RBAC; container runtime protection.
Hands-on with Infrastructure as Code — Terraform (required), CloudFormation, ARM/Bicep, Helm — and IaC security scanning in CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, Azure DevOps).
Strong working knowledge of cloud log analysis — AWS CloudTrail, GuardDuty, VPC Flow Logs; Azure Activity Log, Defender for Cloud, Entra ID sign-in logs; GCP Audit Logs, VPC Flow Logs, Security Command Center; Kubernetes audit logs; EKS / AKS / GKE control plane logs.
Working knowledge of cloud-native attack tradecraft mapped to MITRE ATT&CK Cloud Matrix — cloud credential theft, IMDS abuse, role chaining, container escape, Kubernetes RBAC abuse, S3 / blob storage exfiltration, supply-chain attacks on container images and IaC.
Hands-on scripting and query proficiency: Python, Bash, PowerShell, CQL (CrowdStrike Query Language) ; KQL a plus.
Experience building Falcon Fusion SOAR playbooks, Charlotte AI workflows, or equivalent automation content on the Falcon platform.
Prior consulting delivery experience — scoping, leading, and personally executing cloud security deployment engagements for external clients.
Bachelor’s degree in a relevant field or equivalent professional experience.
A note on experience: The years of experience above are guidelines, not gates. We will strongly consider candidates with fewer years who bring CCCS certification plus demonstrable hands-on Falcon Cloud Security deployment experience across multiple hyperscalers. Skill and certification can offset tenure.
Preferred Qualifications
CrowdStrike Certified Cloud Specialist (CCCS) certification — strongly preferred . Candidates without CCCS at hire will be expected to certify within their first 90 days.
Additional CrowdStrike credentials: CCFA, CCFR, CCSA, CCSE, CCIS.
Cloud-native security certifications (one or more strongly preferred): AWS Certified Security – Specialty , Microsoft Certified: Azure Security Engineer Associate (AZ-500) , Google Cloud Professional Cloud Security Engineer , Certified Kubernetes Security Specialist (CKS) , Certified Kubernetes Administrator (CKA) .
Foundational cloud certifications: AWS Solutions Architect (Associate or Professional), Azure Administrator / Solutions Architect Expert, Google Cloud Professional Cloud Architect.
Industry security certifications: CCSP (Certified Cloud Security Professional), CISSP, GCSA (GIAC Cloud Security Automation), GCLD (GIAC Cloud Security Essentials).
Experience deploying and tuning Falcon Next-Gen SIEM / LogScale content for cloud detection engineering (parsers, correlation rules, dashboards, case management).
Experience building production Falcon Fusion SOAR playbooks for cloud response at scale.
Experience building Charlotte AI prompts and agentic workflows for cloud security use cases.
Experience with competing CNAPPs (Wiz, Prisma Cloud, Lacework, Aqua, Sysdig, Orca) — particularly migration experience from those platforms to Falcon Cloud Security.
Hands-on with service mesh (Istio, Linkerd), secrets management (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager), and policy-as-code (OPA / Rego, Kyverno).
Prior consulting experience at a tier-1 firm with a CrowdStrike-focused or cloud security delivery practice (Big 4 cloud security teams, CrowdStrike Services, Mandiant, Unit 42, or equivalent).
Experience supporting cloud security M&A due diligence, post-acquisition cloud tenant consolidation, or cloud migration security.
Healthcare Coverage: Comprehensive medical, dental, and vision plans.
Time Off and Leave Policies: Generous paid time off (PTO), paid company holidays, generous parental and family leave.
Protective Insurances: Life insurance, short- and long-term disability coverage, and accident protection.
Compensation and Rewards: Competitive salary structures, performance-based incentives, and merit-based compensation reviews.
Retirement Plans: 401(k) plans with company matching.
Please note that benefits may vary by region, department and role. We encourage you to speak with your recruiter to learn more about the specific benefits available for your position.
About Kroll
Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll.
We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability.
The current salary range for this position is $150,000 to $200,000
#LI-CN1
#LI-Remote
$160k - $250k
...in cybersecurity, CrowdStrike protects the people... ...ve redefined modern security with the world’s most... ...’s products. As a Senior Application Security Engineer you will dig deep... ...secure configuration of cloud-native and... ...existing malware-based defenses. Founder George Kurtz...SeniorRemote jobWork experience placementWork at officeLocal area- ...the highest levels of security, safety, and... ...automotive, aerospace, defense, industrial, medical... ...OPPORTUNITYThe Wind River Cloud Platform Product Management team is part of the... ...directly to the Senior Director, Product Management... ...product management, engineering, pre-sales , sales,...SeniorFull timeWork at officeLocal areaVisa sponsorshipFlexible hours
$166k - $220k
Anduril Industries is a defense technology company with a mission... ....ABOUT THE TEAMAnduril's Security Engineering team is looking for a Security... ...focus on Identity and Access Management and build and maintain world... ...identities across IdPs, cloud providers, SaaS tools, and internal...SeniorFull timeWork experience placementImmediate start$166k - $220k
Anduril Industries is a defense technology company with a mission to transform U.S. and... ..., not years.ABOUT THE TEAMAnduril's Security Engineering team is looking for a security engineer... ...implement defensive security controls for cloud, production, and corporate...SeniorFull timeWork experience placementImmediate start$166k - $220k
Anduril Industries is a defense technology company with a mission to transform U... ...years.ABOUT THE TEAM We're seeking an Senior Offensive Security Engineer to grow Anduril's offensive security... ...with assessment of cloud based and containerized environments...SeniorFull timeWork experience placementImmediate start$166k - $220k
Anduril Industries is a defense technology company with a mission to transform U.S... ...domain.ABOUT THE JOBWe are seeking a Senior IT Security Engineer to architect, build, and own classified... ...patchingExperience standing up and managing Active Directory, DNS, DHCP, and enterprise...SeniorFull timeWork experience placementImmediate start$146k - $194k
Anduril Industries is a defense technology company with a mission... ...THE JOBWe are seeking a Senior Security Network Engineer to serve as the senior technical... ...be embedded within the Cyber team, which owns all... ...classified WAN networks and manage connectivity across all sites...SeniorPermanent employmentFull timeWork experience placementImmediate start$160k - $165k
Position Summary The Senior Network Security Engineer leads the design, implementation... ...across on-premises, cloud, and hybrid environments. This... ...2 requirements.Design and manage firewalls, VPNs, IDS/IPS, micro... ...by integrating layered defense systems from equipment, technology...SeniorContract workTemporary workWork experience placementLive outWork at officeRemote workFlexible hours$108k - $232k
...OverviewThis role mitigates security threats by... ...attack surface management is no longer an option... ...IPs, open ports, cloud environments, etc.... ...& Proactive Defense: Work closely with... ...experience in Security Engineering or... ...architecture security.Cyber Attack Mechanisms...SeniorTemporary work$166k - $220k
...Anduril Industries is a defense technology company with a mission... ...THE TEAM Anduril's Security Engineering team is looking for a security... ...implement security controls across cloud, production, and corporate... ...log aggregation, secrets management, or endpoint security tools...SeniorFull timeFor contractorsWork experience placementRemote work- ...Location Type Hybrid Department Engineering Cloud & Security Security About Beacon AI We’re... ...secured a dozen Department of Defense contracts and worked with three major... ...security engineering, not just program management. Key Responsibilities Security...SeniorPermanent employmentFull timeWork at officeLocal areaRemote work3 days per week
$160k - $200k
...your name on itAs a Senior Enterprise Security Engineer, you design and... ...leader within the Cyber Defense Engineering organization... ...to the Engineering Manager, Cyber Defense... ...Microsoft Intune, FleetDM, CrowdStrike Falcon, Okta Verify... ...from major cloud providers (AWS, GCP...SeniorTemporary workLocal areaWorldwide- ...Loews Hotels & Co is seeking a Senior Engineer for Endpoint Security to design, deploy and maintain enterprise... ...and IT Service teams to strengthen defenses and respond to threats. The role... ...AV/EDR, MDM, encryption, and patch management, plus experience in governance...SeniorRemote jobHome office
- ...Anduril Industries is seeking a Security Engineer focused on Identity and Access Management to build and operate strong defensive controls for critical defense technology platforms... ...systems, and create integrations with IdPs, cloud providers, and internal tools. The...Senior
- ...ENS Solutions, LLC seeks a senior security professional to implement and operate next-generation cyber defense for government and commercial... ...requires hands-on security engineering, strong AD and network... ...ability to work with senior management while mentoring teammates....Senior
$5,000 per month
...role. Imagine One Technology & Management, Ltd. is seeking two (2) Senior Security Systems Engineers. These positions are contingent... ...accredited. Research and apply Defense Information Systems Agency (DISA... ...of Cybersecurity and cyber boundary defense techniques and...SeniorInterim role- ...advanced analytic, data engineering, and technology... ...of the Department of Defense (DoD), Intelligence... ...Information Systems Security Engineer - Senior (ISSE Senior) to support... ..., engineering cloud-based architectures,... ...executing the NIST Risk Management Framework (RMF) to...SeniorFull timeFor contractors
$82.3k - $220k
...solutions. From military defense and space exploration to biomedical engineering, lives often... ...Summary:The Secure Solutions Group within... ...Directorate is seeking a Senior System Security... ...that resist cyber, reverse engineering... ...recommend solutions to management.• Configure,...SeniorFull timeLocal area$118.7k - $206k
...a trusted provider of secure, IP enabled, cloud-based, network solutions... ...has an opening for a Senior Information Systems Security Engineer (ISSE) for the TAC2O... ...position will be providing managed IT support of TAC2O... ...for high-priority defense intelligence collection...SeniorFull timeTemporary workInterim roleWork at officeLocal areaRemote work- ..., highly regulated, highly secure environments, including the U.S. Department of Defense (DoD), law enforcement, health... ...Group. OTS is seeking a Senior Security/COMSEC Engineer in Norfolk, Virginia. This... ..., reporting, Local Element management, and day-to-day operational...SeniorContract workLocal area
$184k - $287.5k
NVIDIA's Automotive Offensive Security team believes the best defense is a good offense. Securing a sophisticated automotive operating system means... ...needed to find them at scale. We're looking for a senior engineer who can break low-level systems and then automate the...SeniorFull time$140k - $190k
...Description About Agile Defense At Agile Defense we... ...Title : Information System Security Officers (ISSO), Senior Security Engineers & Security Engineering... ...with network engineers, cloud engineers, field... ...Certified Information Security Manager (CISM) Other relevant...SeniorTemporary workImmediate startRemote workRelocation packageDay shift$166k - $220k
...Anduril Industries is a defense technology company with a mission... ...ABOUT THE TEAM Anduril's Security Engineering team is looking for a... ...focus on Identity and Access Management and build and maintain world... ...unify identities across IdPs, cloud providers, SaaS tools, and internal...SeniorFull timeFor contractorsWork experience placement- ...particular focus on Defense and National Security mission sets. We leverage... ..., Analytics, Engineering, Mission Support, and... ...currently seeking a Senior Data Security Engineer... ...Data Rights Management (DRM) and data-centric... ...architects, ICAM engineers, cloud engineers, system...SeniorFor contractorsWork at office
$175k - $200k
...DoppelDoppel is building the future of social engineering defense. Our AI-native platform uses... ...Risk Protection, Human Risk Management and Email Security, Doppel connects threats into a real... ...support and scale our product and cloud security efforts by embedding security...SeniorWork at officeImmediate startRemote work- ...Credence seeks a Senior Program Engineer-Systems Security to safeguard Air Force armament systems at Eglin AFB, FL. You will lead security engineering, supply chain risk management, information assurance, anti-tamper, and platform information assurance for classified programs...Senior
- ...start with trust. The Security Engineering team plays a critical... ...at scale. As a Senior Security Software Engineer... ...Product Security, Platform Defense, and Security... ...Experience working with cloud-native architectures,... ..., vulnerability management, or security engineering...SeniorLive inWork at office
$150k - $175k
...Industries is a rapidly growing defense technology company focused... ...focus on national security. We are dedicated to solving... ....The RoleWe are seeking a Senior Platform Security Engineer to lead security efforts across... ...(C2) applications, APIs, cloud infrastructure, and...SeniorPermanent employmentWork experience placementWork at officeLocal areaWeekend work$92.5k - $171.5k
...the Trusted Disruptor in defense tech. With customers’... ...space, air, land, sea and cyber domains in the interest of national security. Job Title: Senior Specialist, System Security Engineer - Secret Clearance... ...analysis, and security management. Responsible for integration...SeniorLocal areaRemote workFlexible hours- ...Snap Inc. in Los Angeles is seeking a Senior Security Engineer to join the Infrastructure Security team. You will design, architect, and implement... ...security controls across Snap's backend services and multi‑cloud infrastructure, with emphasis on visibility, hardening,...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Manager, CrowdStrike Cloud Security, Cyber Engineered Defense. Be the first to apply!
- cloud engineering manager United States
- director of cloud United States
- cloud infrastructure manager United States
- director cloud operations United States
- cloud project manager United States
- cloud security manager United States
- cloud program manager United States
- cloud operations manager United States
- project manager national security United States
- senior director information security United States



