Senior Manager - Cloud Security Engineer (CrowdStrike)
Kroll
Kroll Cyber & Data Resilience Manager or Senior Manager
At Kroll, we provide reactive, advisory, transformation, and managed security services to support clients at every stage of their path toward cyber and data resilience maturity. Our experts bring decades of experience in cyber risk consultancy, helping organizations across the world simplify and reduce the complexity of implementing, transforming, and managing their cyber programs. Through our strategic multi-year partnership with CrowdStrike, we combine world-class investigative expertise with an AI-native platform to redefine the future of managed detection and response, delivering faster outcomes, stronger protection, and greater resilience for organizations worldwide.
The Cyber & Data Resilience capability is hiring a Manager or Senior Manager to build and lead Kroll's CrowdStrike Falcon Cloud Security deployment practice. Falcon Cloud Security is the industry's first unified Cloud-Native Application Protection Platform (CNAPP), spanning CSPM, CWP, CIEM, KSPM, ASPM, DSPM, IaC scanning, and container and Kubernetes runtime protection across AWS, Azure, and Google Cloud — delivered through one sensor and one console, with both agent-based and agentless coverage.
Kroll clients need a partner who can deploy, configure, integrate, and tune Falcon Cloud Security end-to-end inside their Falcon tenant — registering cloud accounts at scale across AWS Organizations, Azure tenants, and GCP projects; rolling out runtime protection across VMs, containers, and Kubernetes; wiring cloud log telemetry into Falcon Next-Gen SIEM for detection engineering; building Fusion SOAR playbooks for cloud-native response; and tuning IOM (Indicators of Misconfiguration) and IOA (Indicators of Attack) policies to maximize signal and minimize noise in each client's cloud estate.
This is a player-coach role. The "Manager" or "Senior Manager" title does not mean hands-off oversight. You will personally lead engagement delivery — onboarding cloud accounts, deploying sensors and admission controllers, configuring CNAPP modules, building detection content, and integrating with the broader Falcon stack — while mentoring junior consultants and partnering with CrowdStrike account teams on scoping.
This role reports into the Engineered Defense / Tech Transformation leadership team and partners closely with Kroll's Identity, Next-Gen SIEM, AIDR, and CrowdStrike Services delivery teams.
Deploy
- Onboard client AWS, Azure, and GCP environments to Falcon Cloud Security at scale — using AWS CloudFormation StackSets across AWS Organizations, Bicep / Entra ID integrations for Azure tenants and management groups, and service account patterns for GCP projects and folders.
- Deploy the Falcon sensor across cloud workloads — EC2 / Azure VMs / GCE instances, container hosts, Kubernetes nodes — and stand up agentless snapshot-based scanning to fill coverage gaps.
- Deploy the Kubernetes Admission Controller to enforce pre-runtime policy on workload admission across EKS, AKS, GKE, and self-managed Kubernetes.
- Roll out container image registry scanning and IaC scanning (Terraform, CloudFormation, ARM/Bicep, Kubernetes manifests, Helm) into client CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, Azure DevOps).
- Enable serverless protection for AWS Lambda, Azure Functions, and GCP Cloud Functions.
- Stand up CIEM across cloud identity providers (IAM users, roles, service accounts, managed identities) for least-privilege analysis.
Configure
- Configure CSPM policies — IOM rules, custom misconfiguration detections, compliance frameworks (CIS Benchmarks, NIST, PCI-DSS, HIPAA, SOC 2), and exception management.
- Configure CWP runtime policies — IOA detections, prevention policies, container runtime protection, drift detection.
- Configure KSPM policies — Kubernetes posture, pod security standards, admission control rules, RBAC analysis.
- Configure ASPM and DSPM policies for application-security posture and data-security posture across cloud data stores.
- Configure CIEM — effective permission analysis, toxic combinations, privilege right-sizing, service-account hygiene.
- Configure ExPRT.AI risk prioritization to surface attack paths and toxic combinations across CSPM/CWP/CIEM signals.
- Build and tune custom detection content (IOAs, IOMs, CQL queries) for cloud-native attack techniques mapped to MITRE ATT&CK Cloud Matrix.
Integrate
- Ingest cloud log telemetry into Falcon Next-Gen SIEM (LogScale) — AWS CloudTrail, GuardDuty findings, VPC Flow Logs, S3 access logs; Azure Activity Log, Defender for Cloud alerts, NSG Flow Logs, Entra ID sign-in logs; GCP Audit Logs, VPC Flow Logs, Security Command Center findings; EKS / AKS / GKE control plane logs; Kubernetes audit logs.
- Build detection engineering content in Next-Gen SIEM correlating Falcon Cloud Security findings with cloud provider native logs, endpoint telemetry, and identity events for full attack-path visibility.
- Build Falcon Fusion SOAR playbooks for cloud-native response actions: quarantine compromised workload, revoke IAM credential, isolate Kubernetes pod, remediate misconfiguration via IaC pull request, trigger MFA via Falcon Identity Protection.
- Integrate Falcon Cloud Security with Falcon Identity Protection for cross-domain correlation between cloud workload activity and identity risk.
- Integrate Falcon Cloud Security with Falcon Insight (EDR) for unified endpoint + cloud workload protection.
- Integrate Falcon Cloud Security with Falcon AIDR for AI workload runtime protection in Kubernetes.
- Build Charlotte AI prompts and agentic workflows for cloud event triage, misconfiguration remediation guidance, and executive cloud-risk reporting.
Tune and Operate
- Tune IOM and IOA policies to reduce false positives without sacrificing detection efficacy.
- Tune ExPRT.AI prioritization and attack path analysis to client risk tolerance and remediation capacity.
- Optimize sensor performance and agentless scan cadence for cost and coverage balance.
- Validate detection coverage through controlled adversary emulation against the MITRE ATT&CK Cloud Matrix.
- Hand off operational runbooks to client cloud security teams and Kroll Managed Services for ongoing operation.
Advise (scoped to the platform)
- Advise client cloud platform, DevSecOps, and SOC engineering teams on Falcon Cloud Security deployment architecture — agent vs. agentless coverage decisions, account onboarding patterns, Kubernetes admission control posture, IaC scanning policy in CI/CD, and integration with existing Falcon modules.
- Partner with CrowdStrike account teams on Falcon Cloud Security pre-sales scoping, solution design, proof-of-value engagements, and joint go-to-market motions.
Build the Practice
- Develop reusable Falcon Cloud Security deployment runbooks, configuration templates (Terraform, Bicep), integration patterns, Fusion SOAR playbook libraries, custom IOM/IOA detection libraries, and Charlotte AI workflow templates.
- Mentor consultants on Falcon Cloud Security deployment and integration.
Hiring Requirements:
- 5+ years (Manager) or 7+ years (Senior Manager) of hands-on experience deploying, configuring, and operating cloud security tooling in enterprise environments — with a meaningful concentration in CNAPP, CSPM, CWP, or container/Kubernetes security.
- Hands-on deployment experience with the CrowdStrike Falcon platform — direct experience with Falcon Cloud Security (CSPM, CWP, CIEM, KSPM, IaC scanning) is required. Equivalent hands-on with a competing CNAPP (Wiz, Prisma Cloud, Lacework, Aqua, Sysdig, Orca) plus willingness to ramp on Falcon Cloud Security is acceptable.
- Demonstrated experience deploying, configuring, and integrating cloud security platforms across AWS, Azure, and GCP — not just operating them post-deployment. Working depth across at least two of the three hyperscalers is required.
- Hands-on with Kubernetes security — EKS, AKS, GKE, or self-managed; Pod Security Standards; admission controllers; RBAC; container runtime protection.
- Hands-on with Infrastructure as Code — Terraform (required), CloudFormation, ARM/Bicep, Helm — and IaC security scanning in CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, Azure DevOps).
- Strong working knowledge of cloud log analysis — AWS CloudTrail, GuardDuty, VPC Flow Logs; Azure Activity Log, Defender for Cloud, Entra ID sign-in logs; GCP Audit Log
- A technology firm is seeking a Software Engineer to design, develop, and integrate secure computing environments supporting critical mission objectives. The role requires experience in full-stack development, AWS services, and Infrastructure-as-Code tools. Ideal candidates...Senior
- A leading technology firm seeks a Cloud Security Engineer 4 to support the DOMEX Technology Platform in securing and maintaining compliance of cloud-based platforms across multiple secure networks. Candidates must have an active TS/SCI clearance, a bachelor's degree, and...Senior
$124k - $280k
...identify vulnerabilities, develop secure systems, and provide... ...safeguard sensitive data. In cloud security at PwC, you will be... ...cloud security strategies. As a Senior Manager, you will serve as a... ...Master's Degree in Computer Engineering, Computer Applications, Computer...SeniorFull timeH1b- ...Cloud Information Systems Security Engineer (ISSE) – Senior Level Category: Cyber Security Main location: United States, District of Columbia, Washington Alternate Location(s): United States, West Virginia, Clarksburg United States, Alabama, Huntsville Position ID:...SeniorFull time
- Peraton is seeking a Senior Cybersecurity Engineer to enhance federal government cybersecurity operations. The role involves designing and maintaining complex Splunk environments, ensuring compliance with federal cybersecurity frameworks, and collaborating with various...Senior
- Dragonfli Group in Washington, DC, is looking for a Senior Cloud Security Engineer to implement security strategies in a large federal program. The role involves managing hybrid ecosystems and ensuring compliance across environments. Candidates should have at least 8 years...SeniorPermanent employment
- ...significantly lower capital cost. As a Senior Azure Cloud Security Engineer, you will be the primary architect... ...governance, modern endpoint management, and data protection. This role requires... ...-of-breed third-party tools like CrowdStrike, Splunk, and Tenable....SeniorFor contractorsWork at office
- ...Senior Cloud Platform Security Engineer Job Description Overview CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and... ...monitoring, admission control, network policy, and secrets management. Drive sensor coverage validation, incident response...SeniorFull timeWork at officeWork from homeMonday to Thursday
- Oslitandi Tech LLC Senior Splunk Security Engineer Washington, DC·Full time This is a senior-level technical... ...NOSC supported tools and platforms. Manage multiple assignments, changing... ...deployment and orchestration within a Cloud environment. Work closely with senior...SeniorFull time
$175k - $200k
...Description Summary: We are seeking an experienced Director, Cloud Security Architecture and Engineering to serve as a hands-on leader, providing both... ...DevOps pipelines, leveraging automation for vulnerability management, code scanning, configuration validation and...Full timeWork experience placementWork at officeRemote workWork from homeFlexible hoursNight shiftWeekend work2 days per week$147k - $164k
...An innovative educational organization is searching for a Senior Engineering Manager to lead a team of skilled engineers in Washington, DC. The role involves influencing technical strategies and collaborating on engineering practices. Candidates should have over 7 years...SeniorFull timeRemote work$130.69k - $222.17k
A global advisory and technology services provider is seeking an experienced Software Security Engineer to lead critical security initiatives. Located in the Washington DC metro area, this position requires an active Top Secret clearance and over 8 years of experience in...Senior- Creative Information Technology India is looking for a Senior Cloud Security Specialist to join the Security Engineering team in Falls Church, VA. The role involves developing and implementing security solutions for cloud environments and conducting regular security reviews...Senior
$130.69k - $222.17k
...The Work ICF is seeking an experienced and driven Software Security Engineer to lead and oversee mission‑critical initiatives in support... ...DCSA). In this role, you will help safeguard applications and cloud‑based systems by integrating security best practices throughout...SeniorFull timeContract workLive inWork at officeImmediate startRemote work- ...CrowdStrike is seeking a Software Engineer to develop innovative cybersecurity solutions. Located in Washington,... ...crowd services and work closely with Security, Data Science, and Engineering... ...experience in distributed systems and cloud infrastructure. The role offers competitive...SeniorWork at officeRemote work
- ...A leading data streaming company is seeking a Senior Product Manager to join the Cloud Networking Product team. This role involves managing major product initiatives focused on reliable and secure connectivity to Confluent Cloud. The ideal candidate has over 5 years of...SeniorRemote work
- ...the U.S. Department of State's Bureau of Diplomatic Security (DS) - Training - Technical Security Engineering. The Advisor will play a critical role in refining... ...Security. Demonstrated track record of engagement with senior-level DS personnel and contract leadership....SeniorContract workWork at office
$193.2k - $227k
...Platform.About the Role:Confluent Cloud delivers a complete end-to-... ...distributed system.As a Senior Product Manager on the Cloud Networking... ...Cloud reliable, scalable, secure, cost efficient and simple... ...product, making sure that the engineering, design, sales, and...SeniorRemote workFlexible hours- ...to join our talented Team. Job Title: Senior Identity, Credential, and Access Management (ICAM) Security Engineer Location: Washington, DC... ...authentication methods for enterprise platforms on the cloud, as well as for those hosted on-premises....SeniorWork at office
- 4256 Senior Network Security Engineer 4256 | US Citizen Job Description:... ...configuration updates, firmware management, access reviews, routing/switching... ...SAN). Understanding of cloud systems and security tools... ...such as Splunk, Tenable, CrowdStrike, Panorama. Education:...Senior
- ...Senior Security Engineer Location: Washington, DC | (Hybrid - 3 days in office with travel as required... ...Security Engineer to strengthen cloud and software environments, ensuring compliance... ...(POA&Ms), and Configuration Management & Incident Response Plans. Collaborate...SeniorWork at office
- ...Title: Senior Security Engineer Location : Arlington, VA Duration: 12 months Enterprise Security... ...with firewalls, IAM solutions, log management, scanning) Python scripting, TCP/IP... ...with Network and Security Engineering, Cloud Security, and Enterprise Application...Senior
- ...As a Sr. Network Security Engineer III, you'll provide hands-on expertise securing mission-critical... ...'ll do: Design, implement, and manage firewalls, VPNs, IPS, and NAC solutions... ...role, such as Network+, Security+, Cloud+, SSCP, CASP+, CISSP, or CCNP Security....SeniorImmediate start
$65 - $75 per hour
...operational environment and Vulnerability Management related requirements/needs; Engage with... ...scanning; Work Cyber related security operations ITSM (ServiceNow) assigned tickets... ...workstation anti-virus software, DAT, and engineer updates. Performs virus scans and updates...SeniorFull time- ...Solutions Company focused on building, securing and supporting our clients' mission... ...implementation services as well as fully managed service offerings. VAE is at the... ...customers. We're seeking an experienced Senior Network Engineer who enjoys hands-on technical work, takes...SeniorPermanent employmentFull time
$180k - $240k
...Security Lead You'll be the hands-on security lead embedded with core product... ...in production. We are looking for engineers who have expertise in cloud/infrastructure security or application... ...and self-hosted customers. Vuln management: Own scanning/triage/patch SLAs;...SeniorWork at officeImmediate startFlexible hours- ...Senior IT Security Engineer Location: Hybrid 3 days on DC Interview Type: In-Person Number of Openings: 3 Short Description: IT Security... ...across the enterprise, including directory and identity management solutions Implementation of business-driven changes,...SeniorWork at officeLocal area
- ...Cybersecurity Risk Management Position Position is in the Cybersecurity Risk Management... ...NIST Special Publication 800-53 Rev. 4/5 Security and Privacy Controls for Information Systems... ..., HITRUST, CIS benchmarks, CIS Top 20, Cloud Controls Matrix (CCM), COBIT, CMMC, ISO...SeniorWork experience placement
- Accenture in Arlington, Virginia is seeking a Cloud Operations Lead Senior Manager to design and manage cloud environments for US federal government... .... The role requires extensive experience in cloud engineering, operational support in enterprise environments, and must...Senior
- ...Senior Information Security Engineer Mastercard is a global technology company in the payments industry.... ...with Network and Security Engineering, Cloud Security, and Enterprise Application... ...internal stakeholders, effectively managing multiple priorities, demands, and possess...SeniorRemote workRelocationFlexible hoursWeekend work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Manager - Cloud Security Engineer (CrowdStrike). Be the first to apply!
- cloud engineering manager Washington DC
- cloud program manager Washington DC
- director of cloud Washington DC
- cloud project manager Washington DC
- senior director information security Washington DC
- surveillance manager Washington DC
- security engineering manager Washington DC
- security systems manager Washington DC
- director global security Washington DC
- physical security manager Washington DC

