Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Manager - Cloud Security Engineer (CrowdStrike)

$150k - $200k

At Kroll, we provide reactive, advisory, transformation, and managed security services to support clients at every stage of their path toward cyber and data resilience maturity. Our experts bring decades of experience in cyber risk consultancy, helping organizations across the world simplify and reduce the complexity of implementing, transforming, and managing their cyber programs. Through our strategic multi-year partnership with CrowdStrike, we combine world-class investigative expertise with an AI-native platform to redefine the future of managed detection and response, delivering faster outcomes, stronger protection, and greater resilience for organizations worldwide.

The Cyber & Data Resilience capability is hiring a Manager or Senior Manager to build and lead Kroll's CrowdStrike Falcon Cloud Security deployment practice . Falcon Cloud Security is the industry's first unified Cloud-Native Application Protection Platform (CNAPP), spanning CSPM, CWP, CIEM, KSPM, ASPM, DSPM, IaC scanning, and container and Kubernetes runtime protection across AWS, Azure, and Google Cloud — delivered through one sensor and one console, with both agent-based and agentless coverage.

Kroll clients need a partner who can deploy, configure, integrate, and tune Falcon Cloud Security end-to-end inside their Falcon tenant — registering cloud accounts at scale across AWS Organizations, Azure tenants, and GCP projects; rolling out runtime protection across VMs, containers, and Kubernetes; wiring cloud log telemetry into Falcon Next-Gen SIEM for detection engineering; building Fusion SOAR playbooks for cloud-native response; and tuning IOM (Indicators of Misconfiguration) and IOA (Indicators of Attack) policies to maximize signal and minimize noise in each client's cloud estate.

This is a player-coach role . The “Manager” or “Senior Manager” title does not mean hands-off oversight. You will personally lead engagement delivery — onboarding cloud accounts, deploying sensors and admission controllers, configuring CNAPP modules, building detection content, and integrating with the broader Falcon stack — while mentoring junior consultants and partnering with CrowdStrike account teams on scoping.

This role reports into the Engineered Defense / Tech Transformation leadership team and partners closely with Kroll’s Identity, Next-Gen SIEM, AIDR, and CrowdStrike Services delivery teams.

Deploy

  • Onboard client AWS, Azure, and GCP environments to Falcon Cloud Security at scale — using AWS CloudFormation StackSets across AWS Organizations, Bicep / Entra ID integrations for Azure tenants and management groups, and service account patterns for GCP projects and folders.

  • Deploy the Falcon sensor across cloud workloads — EC2 / Azure VMs / GCE instances, container hosts, Kubernetes nodes — and stand up agentless snapshot-based scanning to fill coverage gaps.

  • Deploy the Kubernetes Admission Controller to enforce pre-runtime policy on workload admission across EKS, AKS, GKE, and self-managed Kubernetes.

  • Roll out container image registry scanning and IaC scanning (Terraform, CloudFormation, ARM/Bicep, Kubernetes manifests, Helm) into client CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, Azure DevOps).

  • Enable serverless protection for AWS Lambda, Azure Functions, and GCP Cloud Functions.

  • Stand up CIEM across cloud identity providers (IAM users, roles, service accounts, managed identities) for least-privilege analysis.

Configure

  • Configure CSPM policies — IOM rules, custom misconfiguration detections, compliance frameworks (CIS Benchmarks, NIST, PCI-DSS, HIPAA, SOC 2), and exception management.

  • Configure CWP runtime policies — IOA detections, prevention policies, container runtime protection, drift detection.

  • Configure KSPM policies — Kubernetes posture, pod security standards, admission control rules, RBAC analysis.

  • Configure ASPM and DSPM policies for application-security posture and data-security posture across cloud data stores.

  • Configure CIEM — effective permission analysis, toxic combinations, privilege right-sizing, service-account hygiene.

  • Configure ExPRT.AI risk prioritization to surface attack paths and toxic combinations across CSPM/CWP/CIEM signals.

  • Build and tune custom detection content (IOAs, IOMs, CQL queries) for cloud-native attack techniques mapped to MITRE ATT&CK Cloud Matrix.

Integrate

  • Ingest cloud log telemetry into Falcon Next-Gen SIEM (LogScale) — AWS CloudTrail, GuardDuty findings, VPC Flow Logs, S3 access logs; Azure Activity Log, Defender for Cloud alerts, NSG Flow Logs, Entra ID sign-in logs; GCP Audit Logs, VPC Flow Logs, Security Command Center findings; EKS / AKS / GKE control plane logs; Kubernetes audit logs.

  • Build detection engineering content in Next-Gen SIEM correlating Falcon Cloud Security findings with cloud provider native logs, endpoint telemetry, and identity events for full attack-path visibility.

  • Build Falcon Fusion SOAR playbooks for cloud-native response actions: quarantine compromised workload, revoke IAM credential, isolate Kubernetes pod, remediate misconfiguration via IaC pull request, trigger MFA via Falcon Identity Protection.

  • Integrate Falcon Cloud Security with Falcon Identity Protection for cross-domain correlation between cloud workload activity and identity risk.

  • Integrate Falcon Cloud Security with Falcon Insight (EDR) for unified endpoint + cloud workload protection.

  • Integrate Falcon Cloud Security with Falcon AIDR for AI workload runtime protection in Kubernetes.

  • Build Charlotte AI prompts and agentic workflows for cloud event triage, misconfiguration remediation guidance, and executive cloud-risk reporting.

Tune and Operate

  • Tune IOM and IOA policies to reduce false positives without sacrificing detection efficacy.

  • Tune ExPRT.AI prioritization and attack path analysis to client risk tolerance and remediation capacity.

  • Optimize sensor performance and agentless scan cadence for cost and coverage balance.

  • Validate detection coverage through controlled adversary emulation against the MITRE ATT&CK Cloud Matrix.

  • Hand off operational runbooks to client cloud security teams and Kroll Managed Services for ongoing operation.

Advise (scoped to the platform)

  • Advise client cloud platform, DevSecOps, and SOC engineering teams on Falcon Cloud Security deployment architecture — agent vs. agentless coverage decisions, account onboarding patterns, Kubernetes admission control posture, IaC scanning policy in CI/CD, and integration with existing Falcon modules.

  • Partner with CrowdStrike account teams on Falcon Cloud Security pre-sales scoping, solution design, proof-of-value engagements, and joint go-to-market motions.

Build the Practice

  • Develop reusable Falcon Cloud Security deployment runbooks, configuration templates (Terraform, Bicep), integration patterns, Fusion SOAR playbook libraries, custom IOM/IOA detection libraries, and Charlotte AI workflow templates.

  • Mentor consultants on Falcon Cloud Security deployment and integration.

Hiring Requirements:

  • 5+ years (Manager) or 7+ years (Senior Manager) of hands-on experience deploying, configuring, and operating cloud security tooling in enterprise environments — with a meaningful concentration in CNAPP, CSPM, CWP, or container/Kubernetes security.

  • Hands-on deployment experience with the CrowdStrike Falcon platform — direct experience with Falcon Cloud Security (CSPM, CWP, CIEM, KSPM, IaC scanning) is required. Equivalent hands-on with a competing CNAPP (Wiz, Prisma Cloud, Lacework, Aqua, Sysdig, Orca) plus willingness to ramp on Falcon Cloud Security is acceptable.

  • Demonstrated experience deploying, configuring, and integrating cloud security platforms across AWS, Azure, and GCP — not just operating them post-deployment. Working depth across at least two of the three hyperscalers is required.

  • Hands-on with Kubernetes security — EKS, AKS, GKE, or self-managed; Pod Security Standards; admission controllers; RBAC; container runtime protection.

  • Hands-on with Infrastructure as Code — Terraform (required), CloudFormation, ARM/Bicep, Helm — and IaC security scanning in CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, Azure DevOps).

  • Strong working knowledge of cloud log analysis — AWS CloudTrail, GuardDuty, VPC Flow Logs; Azure Activity Log, Defender for Cloud, Entra ID sign-in logs; GCP Audit Logs, VPC Flow Logs, Security Command Center; Kubernetes audit logs; EKS / AKS / GKE control plane logs.

  • Working knowledge of cloud-native attack tradecraft mapped to MITRE ATT&CK Cloud Matrix — cloud credential theft, IMDS abuse, role chaining, container escape, Kubernetes RBAC abuse, S3 / blob storage exfiltration, supply-chain attacks on container images and IaC.

  • Hands-on scripting and query proficiency: Python, Bash, PowerShell, CQL (CrowdStrike Query Language) ; KQL a plus.

  • Experience building Falcon Fusion SOAR playbooks, Charlotte AI workflows, or equivalent automation content on the Falcon platform.

  • Prior consulting delivery experience — scoping, leading, and personally executing cloud security deployment engagements for external clients.

  • Bachelor’s degree in a relevant field or equivalent professional experience.

A note on experience: The years of experience above are guidelines, not gates. We will strongly consider candidates with fewer years who bring CCCS certification plus demonstrable hands-on Falcon Cloud Security deployment experience across multiple hyperscalers. Skill and certification can offset tenure.

Preferred Qualifications

  • CrowdStrike Certified Cloud Specialist (CCCS) certification — strongly preferred . Candidates without CCCS at hire will be expected to certify within their first 90 days.

  • Additional CrowdStrike credentials: CCFA, CCFR, CCSA, CCSE, CCIS.

  • Cloud-native security certifications (one or more strongly preferred): AWS Certified Security – Specialty , Microsoft Certified: Azure Security Engineer Associate (AZ-500) , Google Cloud Professional Cloud Security Engineer , Certified Kubernetes Security Specialist (CKS) , Certified Kubernetes Administrator (CKA) .

  • Foundational cloud certifications: AWS Solutions Architect (Associate or Professional), Azure Administrator / Solutions Architect Expert, Google Cloud Professional Cloud Architect.

  • Industry security certifications: CCSP (Certified Cloud Security Professional), CISSP, GCSA (GIAC Cloud Security Automation), GCLD (GIAC Cloud Security Essentials).

  • Experience deploying and tuning Falcon Next-Gen SIEM / LogScale content for cloud detection engineering (parsers, correlation rules, dashboards, case management).

  • Experience building production Falcon Fusion SOAR playbooks for cloud response at scale.

  • Experience building Charlotte AI prompts and agentic workflows for cloud security use cases.

  • Experience with competing CNAPPs (Wiz, Prisma Cloud, Lacework, Aqua, Sysdig, Orca) — particularly migration experience from those platforms to Falcon Cloud Security.

  • Hands-on with service mesh (Istio, Linkerd), secrets management (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager), and policy-as-code (OPA / Rego, Kyverno).

  • Prior consulting experience at a tier-1 firm with a CrowdStrike-focused or cloud security delivery practice (Big 4 cloud security teams, CrowdStrike Services, Mandiant, Unit 42, or equivalent).

  • Experience supporting cloud security M&A due diligence, post-acquisition cloud tenant consolidation, or cloud migration security.

  • Healthcare Coverage: Comprehensive medical, dental, and vision plans.

  • Time Off and Leave Policies: Generous paid time off (PTO), paid company holidays, generous parental and family leave.

  • Protective Insurances: Life insurance, short- and long-term disability coverage, and accident protection.

  • Compensation and Rewards: Competitive salary structures, performance-based incentives, and merit-based compensation reviews.

  • Retirement Plans: 401(k) plans with company matching.

Please note that benefits may vary by region, department and role. We encourage you to speak with your recruiter to learn more about the specific benefits available for your position.

About Kroll

Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll.

We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability.

The current salary range for this position is $150,000 to $200,000

#LI-CN1

#LI-Remote

Vacancy posted 24 days ago
Similar jobs that could be interesting for youBased on the Senior Manager - Cloud Security Engineer (CrowdStrike) in United States vacancy
  • Summary Lead the security platform engineering team to design, implement, and modernize enterprise security...  ...roadmap across endpoint protection, cloud security, data protection, email...  ...Lead design, implementation, lifecycle management, and consolidation of platforms including... 
    Senior

    brobstongroup.com - Jobboard

    Seattle, WA
    5 days ago
  • $240k - $334k

    Lead Technical Program Manager, Cloud CISO Security Engineering Location Options: Sunnyvale, CA; Kirkland, WA; New York, NY; Seattle, WA. Compensation: US: $240,000 - $334,000 (USD) + 25% bonus target + equity + benefits. Benefits: Health, dental, vision, life, disability... 
    Suggested
    Temporary work
    Local area

    Google Inc.

    New York, NY
    4 days ago
  • $217.1k - $298.55k

     ...United States Digital Space LLC is seeking a Senior Engineering Manager in McLean, Virginia, to lead their Security Infrastructure Operations team. You will be responsible for driving strategies to automate cloud security operations and ensuring seamless compliance with... 
    Senior

    United States Digital Space LLC

    McLean, VA
    2 days ago
  • $140k - $215k

     ...CrowdStrike, Inc. Full time R28810 As a global...  ...redefined modern security with the world's most...  ...Role: The Product Management team is seeking an experienced Senior Product Manager who...  ...in its cloud-based threat detection...  ...work closely with engineering, researchers, product... 
    Senior
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work
    Worldwide

    Koitecc Solutions

    Sunnyvale, CA
    4 days ago
  • $140k - $215k

     ...CrowdStrike, Inc. Full time R28828 As a global...  ...redefined modern security with the world’s most...  ...Role The Product Management team is seeking an experienced Senior Product Manager who...  ...about building great cloud security products....  ...work closely with engineering, researchers,... 
    Senior
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work
    Worldwide
    2 days per week
    3 days per week

    Koitecc Solutions

    Sunnyvale, CA
    5 days ago
  • $140k - $215k

     ...CrowdStrike Holdings, Inc. is looking for a Senior Engineer for its Cloud Security Product Group. The role involves leading backend engineering efforts and utilizing cloud-based systems to protect cloud-native workloads. Candidates should have at least 10 years of experience... 
    Senior

    CrowdStrike Holdings, Inc.

    New York, NY
    16 hours ago
  •  ...CrowdStrike is seeking an Engineering Manager to join the Proactive Security team within Cloud Security. The ideal candidate will lead a team to detect and prevent threats using advanced detection techniques. This hybrid role requires collaboration with cross-functional... 

    Dormont Manufacturing Company

    New York, NY
    4 days ago
  • $149.85k - $185k

     ...Security Engineering Manager Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to...  ...across the largest internal, external, cloud, and hybrid cloud environments. NodeZero...  ...horizontally with peer management and senior leaders What You'll Bring... 
    Full time
    Work at office
    Remote work
    Flexible hours

    Horizon3.ai

    United States
    3 days ago
  •  ...CrowdStrike Holdings, Inc. is seeking a Senior Engineer for their Sensor Security Platform. This remote role involves working on the Falcon sensor’s detection and response capabilities, focusing on developing and owning various SSP technologies. The ideal candidate... 
    Senior
    Remote work

    CrowdStrike Holdings, Inc.

    California, MO
    2 days ago
  • $140k - $215k

     ...A leading cybersecurity firm is seeking a Senior Engineer to enhance its Cloud Security Product Group. This role requires extensive experience in backend systems programming and cloud services, focusing on securing cloud-native workloads. You will lead engineering efforts... 
    Senior
    2 days per week
    3 days per week

    CrowdStrike Holdings, Inc.

    New York, NY
    5 days ago
  •  ...Deterrence is seeking a hands-on IT Manager who will oversee and scale our IT infrastructure, cloud environment, and ensure compliance within a high-stakes defense...  ...relevant to the DoD ecosystem, ensuring security and reliability across the organization. #J-18808... 
    Senior
    Work at office

    Deterrence

    Fremont, CA
    5 days ago
  •  ...The U.S. Anti-Doping Agency is seeking an IT Manager to plan and oversee IT operations ensuring secure and efficient systems that support the organization’s mission. Responsibilities include managing daily IT operations, improving existing systems, and overseeing IT projects... 
    Senior
    Flexible hours

    U.S. Anti-Doping Agency

    Colorado Springs, CO
    16 hours ago
  •  ...Senior Cloud Security Architect At BNY, our culture allows us to run our company better and...  ...cybersecurity architecture, and security engineering with strong knowledge of AI-driven...  ...enhance resilience, efficiency, and risk management. Advise senior leadership and key... 
    Senior
    Worldwide

    BNY

    New York, NY
    2 days ago
  •  ...Koitecc Solutions is looking for a Senior Program Manager to lead a large-scale ePACS program for the U.S. Army. This role involves managing enterprise security systems and ensuring cybersecurity compliance across various Army installations. The ideal candidate will have... 
    Senior

    Koitecc Solutions

    Edgewood, MD
    4 days ago
  •  ...Lenovo is seeking a Senior Product Manager to drive the strategy and execution of their Hybrid Cloud and AI Security offerings. This role requires strong expertise in cloud infrastructure and security, with a focus on delivering effective products for enterprise needs... 
    Senior
    Remote work

    Lenovo

    Morrisville, NC
    2 days ago
  • $50k

     ...Position Overview Senior Manager OT Security Engineer in Winston‑Salem, NC reporting to the Director DBS OT Security and partnering with the broader Digital Business Solutions (DBS) organization. The role requires knowledge of IT standards such as ISO 27001 and OT security... 
    Senior
    Contract work
    Temporary work
    Local area
    Remote work
    Flexible hours

    The British American Tobacco Group

    Winston Salem, NC
    4 days ago
  • $136.85k

     ...The Boeing Company is looking for an Experienced Project Management Specialist in Seattle, WA, to support Product Security Engineering teams in delivering projects. This includes scoping, planning, and leading initiatives while ensuring adherence to project management... 
    Senior

    The Boeing Company

    Seattle, WA
    4 days ago
  •  ...impactful launches. Ideal candidates have a strong background in cloud security and track record in enterprise software marketing. The role requires creativity, excellent communication, and project management skills to engage with technical audiences effectively.... 
    Senior

    Wiz

    New York, NY
    1 day ago
  •  ...is seeking a Technical DevSecOps Manager to lead agile teams in the...  ...critical systems for a national security customer. The role requires extensive...  ...skills, a deep understanding of cloud services, and a passion for mentoring engineering teams to achieve successful outcomes... 
    Senior

    General Dynamics Information Technology

    Mc Lean, VA
    1 day ago
  • Job Description Position Title: Senior Manager, Data & Cloud Security Location: Dallas (Hybrid) Your role We are seeking a highly skilled Data & Cloud Security Manager to lead and strengthen our global data and cloud security programs. This role is responsible for safeguarding... 
    Senior

    Digital Realty

    Dallas, TX
    4 days ago
  •  ...Senior Manager, Security Engineering Build the future, spark innovation and align your career with purpose. McKinstry is innovating the waste...  ...hold their own technically across application, network, cloud, and AI security domains, while driving a team and a program... 
    Senior
    Remote work
    Shift work

    EDO

    Seattle, WA
    4 days ago
  •  ...center in Washington, DC seeks a Systems Operations Manager to oversee infrastructure operations and ensure...  .... The role involves supervising a systems engineering team, developing modernization strategies, and managing cloud environments. Candidates must have a background... 
    Senior

    Page Mechanical Group Inc

    Washington DC
    5 days ago
  • A leading cybersecurity firm is seeking an experienced Senior Project Manager to join its Professional Services team. The role involves leading the full project lifecycle for deployments, managing risks, and ensuring timely project delivery. Candidates should possess over... 
    Senior

    Framework Ventures

    New York, NY
    3 days ago
  •  ...Technologies Corporation is seeking a Project Manager based in Fairborn, Ohio, to oversee and...  ...of critical programs within the national security community. You will coordinate a multi-disciplined team to execute and maintain cloud-based software services, manage client... 
    Senior

    Altamira Technologies

    Fairborn, OH
    4 days ago
  • $276k - $414k

     ...services; and its AR glasses, Spectacles.Snap Security teams protect the trust and safety of...  ...at the forefront.We’re looking for a Senior Manager to lead our Application Security team...  ...coverage while minimizing friction for engineering teamsInfluence senior engineering... 
    Senior
    Live in
    Work at office
    Local area

    Snapchat

    Bellevue, WA
    1 day ago
  • $192k - $279k

    Google Inc. is seeking a Senior Product Manager for its Distributed Cloud team in Sunnyvale, CA. This role involves developing security software and hardware solutions, guiding products from conception to launch, and working cross-functionally to enhance customer experiences... 
    Senior

    Google Inc.

    Sunnyvale, CA
    3 days ago
  •  ...Networks, Inc. is seeking a Sr Principal Software Engineer to lead technical delivery for cloud security solutions. You will collaborate with teams to design...  ...distributed systems, while ensuring alignment with product management and quality assurance. This role demands a minimum... 
    Senior

    Palo Alto Networks

    Santa Clara, CA
    5 days ago
  • $148.7k - $240.53k

     ...drives great outcomes. Job Summary As the Senior Product Manager for CDSS, you will play a crucial role in...  ...and cross-functional teams that include engineering, product marketing, sales teams to deliver web security solutions to solve customer problems with speed... 
    Senior
    Full time
    Work at office
    Visa sponsorship
    Work visa

    Palo Alto Networks

    Santa Clara, CA
    5 days ago
  •  ...Skydrop is looking for a highly experienced Senior Cloud Security Engineer to design and maintain security controls across our multi-cloud environment. The role requires deep technical expertise and a proactive approach to security. Candidates should have over 8 years... 
    Senior

    Skydrop

    Dallas, TX
    4 days ago
  •  ...A leading AI company seeks an experienced Cloud Security Engineer in Seattle. Responsibilities include designing secure cloud infrastructures, conducting assessments, and ensuring compliance with key regulations. Ideal candidates should have strong cloud platform expertise... 
    Senior

    Otter.ai

    Seattle, WA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Manager - Cloud Security Engineer (CrowdStrike). Be the first to apply!