> Markdown version of [/jobs/ext/234857-crowdstrike-identity-security-engineer-itdr-cspm](https://www.wearedevelopers.com/jobs/ext/234857-crowdstrike-identity-security-engineer-itdr-cspm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # CrowdStrike Identity Security Engineer (ITDR/CSPM) - **Company:** DRAGONFLI GROUP LLC - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Temporary contract - **Skills:** Java (Programming Language), .NET Framework, Active Directory, Automation of Tests, Microsoft Azure, Cloud Computing Security, Cloud Engineering, Configuration Management, Cyber Security, Identity and Access Management, Information Security Management, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, Kerberos (Protocol), Network Security, Lightweight Directory Access Protocols (LDAP), OAuth, Azure Active Directory, Zero Trust Network Access, Runbook, Security Assertion Markup Language (SAML), Mitre Att&ck, Falcon Platform, Splunk, Servicenow - **Published:** May 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=becf96a055e2ec91 ## About the Role Do you have experience in Security technology solutions implementations?, Do you have a Bachelor's degree?, We are seeking a highly experienced CrowdStrike ITDR / Cloud Security Subject Matter Expert to take full ownership of the Identity Threat Detection & Response (ITDR) and Cloud-Native Application Protection (CNAPP/CSPM) domains on behalf of a large federal agency. This is an ownership-oriented role - not a support function. You will serve as the definitive technical authority for CrowdStrike Falcon Identity Protection and Cloud Security, proactively identifying threats and misconfigurations, leading governance and stakeholder communications, and driving continuous improvements to the agency's identity and cloud security posture. The right candidate brings 7 or more years of cybersecurity experience, including at least 2-3 years of hands-on CrowdStrike Falcon platform administration, and thrives in environments where autonomy and accountability go hand in hand. This role is fully remote., This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S., Must-Have: * 7+ years of cybersecurity experience with a minimum of 2-3 years of hands-on administration of the CrowdStrike Falcon platform * Demonstrated expertise with CrowdStrike Falcon Identity Protection, including policy configuration, threat detection, and conditional access * Strong working knowledge of CrowdStrike Cloud Security, specifically CSPM * Deep understanding of identity and access management concepts: Active Directory, Azure AD/Entra ID, LDAP, Kerberos, SAML, and OAuth * Hands-on cloud security experience with Microsoft Azure including IAM, network security, and posture management * Solid understanding of privileged access management and identity-based attack techniques (lateral movement, credential theft, Kerberoasting, pass-the-hash) * Proven ability to work autonomously, set priorities, and drive outcomes without close supervision * Strong written and verbal communication skills, including ability to explain technical risk to non-technical stakeholders * Background in consulting or client-facing delivery roles * Bachelor's degree in a related field or equivalent practical experience (4 additional years of relevant experience) * At least one of the following active certifications: CWNE, CNDA (EC-Council), CEH (EC-Council), GPPA (GIAC), GCUX (GIAC), GCWN (GIAC), GMON (GIAC), GSE (GIAC), ITIL v3 Foundations, CCSP (ISC2), CISSP (ISC2), CISSP-ISSAP (ISC2), CISSP-ISSEP (ISC2), SSCP (ISC2), GWEB (GIAC), GISF (GIAC), GISP (GIAC), GSSP-.NET (GIAC), GSSP-JAVA (GIAC), GSEC (GIAC), or GSLC (GIAC) * US Citizenship or Permanent Residency required; must be eligible for and willing to obtain a public trust clearance * All work must be performed within the continental United States Preferred / Nice-to-Have: * CrowdStrike Certified Cyber Security (CCCS) certification * Experience with Splunk and ServiceNow SOMS * Familiarity with Zero Trust architecture and frameworks including NIST and MITRE ATT&CK * Experience integrating CrowdStrike with third-party identity and security tooling * Previous federal contracting experience Skill(s): Technical Skills: * CrowdStrike Falcon Identity Protection (ITDR) - policy configuration, detection tuning, conditional access * CrowdStrike Cloud Security / CSPM - IOM and IOA policy management, cloud posture assessment * Microsoft Azure - IAM, Entra ID, network security, posture management * Active Directory and Azure Active Directory / Entra ID administration * Identity and access management protocols: LDAP, Kerberos, SAML, OAuth * Privileged access management (PAM) concepts and tooling * Threat detection and identity-based attack technique knowledge (lateral movement, Kerberoasting, pass-the-hash, credential theft) * Runbook and detection logic development * Security metrics and executive reporting / dashboard creation * Automation development for security operations * Splunk (preferred) * ServiceNow SOMS (preferred) * Zero Trust architecture frameworks (NIST, MITRE ATT&CK) Soft Skills: * Self-directed initiative - proactively identifies risks and drives solutions without waiting for direction * Executive-level communication - translates complex technical risk to non-technical stakeholders * Governance and stakeholder management - owns and leads recurring client governance calls * Critical thinking and independent judgment * Continuous improvement mindset * Accountability - treats the client's security posture as their own * Written communication - runbooks, reports, recommendations ## Description * Own end-to-end strategy, implementation, and operational health of CrowdStrike Falcon Identity Protection and the CSPM capabilities within CrowdStrike Cloud Security * Proactively identify identity-based threats, misconfigurations, and cloud security gaps; drive remediation to closure in accordance with client policies and procedures * Configure, tune, and maintain identity protection policies, IOM and IOA policies, and risk-based authentication controls * Serve as the escalation point and trusted technical advisor to client leadership on identity and cloud security matters * Develop runbooks, detection logic, and automation to reduce manual effort and improve response times * Monitor the threat landscape and translate emerging risks into actionable hardening recommendations * Coordinate and lead governance calls with stakeholders; produce agenda, notes, and follow-up actions independently * Partner with other cybersecurity teams to integrate CrowdStrike telemetry into broader security operations * Produce metrics, dashboards, and executive-level reporting on identity and cloud security posture * Apply deep knowledge of identity-based attack techniques - including lateral movement, credential theft, Kerberoasting, and pass-the-hash - to inform detection and response strategy ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)