Software Detection Engineer - Cloud, Identity Protection (Hybrid, ISR)

Crowdstrke
Tel Aviv
Workplace: HybridFull timeFunction: Communications, PR & CommunityEducation: bachelorsSkills: ["Leadership","Collaboration","Problem-solving"]

Build globally distributed, fault-tolerant identity threat detection systems that analyze billions of authentication events to detect Active Directory attacks, credential theft, and lateral movement across hybrid and multi-cloud environments. Design and implement real-time detection pipelines over Kafka, develop the detection engine and rule framework, and integrate machine-learning and LLM-based reasoning into production flows. Own detection operations including observability, latency SLOs, and safe rollouts in a polyglot Python/Go/Java stack.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Crowdstrke
Crowdstrke
1 month ago

Software Detection Engineer - Cloud, Identity Protection (Hybrid, ISR)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 11 days agoStatus: Live

Job Summary

Build globally distributed, fault-tolerant identity threat detection systems that analyze billions of authentication events to detect Active Directory attacks, credential theft, and lateral movement across hybrid and multi-cloud environments. Design and implement real-time detection pipelines over Kafka, develop the detection engine and rule framework, and integrate machine-learning and LLM-based reasoning into production flows. Own detection operations including observability, latency SLOs, and safe rollouts in a polyglot Python/Go/Java stack.
Location: Tel Aviv
Workplace: Hybrid
Employment Type: Full time
Job Function: Communications, PR & Community
Seniority: Mid level

Key Responsibilities

  • •Design and implement real-time detection rules and pipelines over high-throughput Kafka event streams, maintaining sub-second latency at massive scale.
  • •Build a pluggable detection engine and rule framework to transform authentication telemetry into indicators and customer-facing alerts.
  • •Develop ML and behavioral-anomaly models and integrate LLM-based detection reasoning into production detection flows.
  • •Translate security research into production-grade detections by partnering with security researchers.
  • •Own detections in production, including observability, latency SLOs, feature-flagged rollouts, and incident response for the detection pipeline.

Pay and Benefits

Perks:EquityWellness StipendParental Leave

Key Requirements

  • •Programming mastery in Python with strong expertise in data structures, algorithms, and distributed systems (Go experience is a plus).
  • •6+ years building backend/distributed systems at scale.
  • •Hands-on experience with event-streaming/message-queue architectures (Kafka or similar) and distributed data processing.
  • •Experience with relational and document stores (PostgreSQL, MongoDB) and caching (Redis).
  • •BS or MS in Computer Science or related engineering discipline.
Experience:CybersecurityIdentity protectionDistributed systemsEvent streamingMachine learning
Education:Bachelor's
Skills:LeadershipCollaborationProblem-solving
Tech Stack:PythonGoJavaKafkaPostgreSQLMongoDBRedisProtobuf/gRPCGraphQLAWSLogScale/NG-SIEMLLMGenAIAzureEntraOktaActive Directory

Company Brief

Crowdstrke
Provides cloud-native endpoint protection, threat intelligence, and security operations solutions that prevent breaches and stop sophisticated cyberattacks across endpoints, cloud workloads, identity, and APIs for enterprises worldwide.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Sunnyvale, United States
Founded: 2011
Glassdoor
Glassdoor: 4.4
WebsiteLinkedIn