As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. We work on large scale distributed systems, processing almost 3 trillion events per day and this traffic is growing daily. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We're proud to work for a mission-driven company leveraging AI to transform the way we work. CrowdStrikers drive their careers through flexibility and autonomy while also being expected to contribute to a culture of responsible AI adoption, experimentation, and innovation. We use an AI-first mindset as a force multiplier to proactively and continuously accelerate execution, build expertise, uncover insights, and solve complex problems. We’re always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you.
About the Role:
The Get Data In (GDI) Integrations Lab team at Next-Gen SIEM builds and maintains world-class lab environments that accelerate security research, detection engineering, and third-party integrations. We provide the reliable, scalable infrastructure and comprehensive product coverage that enable CrowdStrike's data-connector, SOAR-connector, detection-content, threat-research, and Exposure Management teams to design, test, validate, and ship security integrations faster and at scale.
Our purpose is to eliminate barriers to integration development through automated provisioning, consistent testing environments, realistic event simulation, and proactive maintenance of a large fleet of third-party security product instances. We host and simulate 70+ live third-party products across a multi-cloud (AWS / Azure / GCP) and on-premises footprint, and we partner closely with CrowdStrike's Technology Ecosystem / Business Development team to procure the licenses that power the lab.
We are looking for a passionate Cloud Infrastructure & Security Engineer to design, automate, and operate this environment. This is a hands-on infrastructure role: you will stand up and maintain the networking, cloud accounts, security appliances, and automation that dozens of engineering teams depend on every day. The ideal candidate has deep experience in cloud infrastructure, network security, Infrastructure-as-Code, and administering enterprise security products (firewalls, IDS/IPS, email security, identity, cloud security), and enjoys turning manual toil into self-service automation.
What You'll Do:
Design, build, and operate the Next-Gen SIEM Lab's multi-cloud infrastructure — AWS hub-and-spoke networking (VPCs, Transit Gateway, NAT/Internet Gateways, subnets, route tables, jumphosts), plus Azure and GCP environments.
Deploy, configure, and maintain a large fleet of third-party security products in the lab — firewalls and network security appliances (Palo Alto, Check Point, Fortinet FortiGate, Cisco ASA, F5 BIG-IP), email security (Abnormal, FortiMail, Proofpoint, Mimecast), NDR (Corelight), DDI (Infoblox vNIOS), threat intel (ThreatQ), Active Directory domains, and cloud-native services.
Develop and maintain Infrastructure-as-Code (Terraform) — build reusable, per-vendor-product modules so any product can be stood up on demand, managed through GitLab with remote state, locking, and CI/CD pipelines.
Build and run the automated event-simulation platform that generates realistic test data for connectors (AWS Lambda + EventBridge, Secret Manager / Thycotic, Docker images in Artifactory, GitLab CI/CD, Kubernetes, CloudWatch, SNS alerting) — expanding coverage across new connectors.
Implement and operate automated patch and compliance management (AWS Systems Manager Patch Manager, Fleet Manager, Maintenance Windows, State Manager, Security Hub) to keep the fleet secure and compliant across regions and time zones.
Automate access provisioning and reduce operational toil — build self-service workflows for credential, license, and host requests, and manage IAM/RBAC across AWS, Azure, and GCP with least-privilege and attack-surface-reduction principles.
Partner with the Technology Ecosystem / Business Development team to procure NFR licenses and onboard new third-party products, and coordinate with ProdSec, InfoSec, and TechOps on access, compliance, and security reviews.
Support internal stakeholders (data-connector, SOAR, detection-content, threat-research, and Exposure Management teams) via the `#ask-ngsiem-lab` channel, and provide on-call support for critical lab and production-environment issues.
Write and maintain high-quality technical documentation — architecture diagrams, product setup guides, runbooks, and access guides.
What You'll Need:
10+ years of experience in cloud infrastructure, network security, and/or systems infrastructure engineering.
Strong hands-on expertise with AWS (VPC, Transit Gateway, IAM, EC2, Lambda, Systems Manager, CloudWatch, Secrets Manager) and working knowledge of Azure and/or GCP networking, identity, and IAM/RBAC.
Proven experience with Infrastructure-as-Code (Terraform) and version control (GitLab/Git) for provisioning and managing cloud infrastructure at scale.
Solid networking and network-security fundamentals — routing, VPN, DNS, subnetting, transit/hub-and-spoke design, and firewall administration.
Hands-on experience deploying, configuring, and administering enterprise security products — firewalls / NGFW (Palo Alto, Check Point, Fortinet, Cisco ASA), IDS/IPS, F5 load balancers, and/or identity, email-security, or cloud-security platforms.
Proficiency in at least one programming/scripting language, preferably Python , and comfort with Linux administration and Bash scripting.
Experience with CI/CD pipelines, Docker, and Kubernetes.
Strong documentation, communication, and cross-team collaboration skills, and the ability to support internal stakeholders effectively.
Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.
Bonus Points:
Experience with CI/CD-driven infrastructure automation and container workflows (GitLab CI, JFrog Artifactory, Kubernetes).
Familiarity with cloud-native logging/monitoring services (AWS CloudWatch, Azure Monitor, GCP Logging) and secrets management (Thycotic/Delinea, AWS Secrets Manager).
Experience building self-service / provisioning-automation platforms that reduce operational toil.
Exposure to SIEM/XDR data ingestion, log formats (Syslog, CEF, LEEF, JSON, XML), or security detection/threat-research workflows.
Relevant certifications (AWS Solutions Architect / Advanced Networking / Security, HashiCorp Terraform Associate, CCNP, firewall vendor certifications).
Experience with Active Directory / Windows Server and hybrid on-prem + cloud environments.
#LI-SM2
Benefits of Working at CrowdStrike:
CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program.
CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions--including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs--on valid job requirements.
If you need assistance accessing or reviewing the information on this website or need help submitting an application for employment or requesting an accommodation, please contact us at recruiting@crowdstrike.com for further assistance.

CrowdStrike (Nasdaq: CRWD), a global cybersecurity leader, has redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data.
Powered by the CrowdStrike Security Cloud and world-class AI, the CrowdStrike Falcon® platform leverages real-time indicators of attack, threat intelligence, evolving adversary tradecraft and enriched telemetry from across the enterprise to deliver hyper-accurate detections, automated protection and remediation, elite threat hunting and prioritized observability of vulnerabilities.
Purpose-built in the cloud with a single lightweight-agent architecture, the Falcon platform delivers rapid and scalable deployment, superior protection and performance, reduced complexity and immediate time-to-value.
CrowdStrike: We stop breaches.