Be a part of it. Join the #AccelFamily

Linux Engineer - Content Research & Integration (Remote)



United States · Remote
Posted on Thursday, June 27, 2024

#WeAreCrowdStrike and our mission is to stop breaches. As a global leader in cybersecurity, our team changed the game. Since our inception, our market leading cloud-native platform has offered unparalleled protection against the most sophisticated cyberattacks. We work on large scale distributed systems, processing over 1 trillion events a day with a petabyte of RAM deployed in our Cassandra clusters - and this traffic is growing daily. We’re looking for people with limitless passion, a relentless focus on innovation and a fanatical commitment to developing and shaping our cybersecurity platform. Consistently recognized as a top workplace, CrowdStrike is committed to cultivating an inclusive, remote-first culture that offers people the autonomy and flexibility to balance the needs of work and life while taking their career to the next level. Interested in working for a company that sets the standard and leads with integrity? Join us on a mission that matters - one team, one fight.

About the Team:
The Content Research & Integration (CRI) is a team which resides within the Endpoint Protection area of CrowdStrike – an area which is responsible for enabling detections and preventions of malicious behaviors on the Falcon Platform. The CRI team is focused on strategic, forward leaning research into new Falcon Sensor capabilities to identify various tactics and techniques used by adversaries. We accomplish this by focusing on OS security/internals for all major supported platforms (Windows, Mac, and Linux) and exposing the right data to the sensor in a supportable and performant manner. Most of our projects involve months of research, planning, coordination, and implementation to be successful. We currently support several key Falcon Sensor technologies that are leveraged by detection and response teams to increase telemetry, detections, and preventions on the platform

About the Role:
CrowdStrike Falcon Host is a two-component security product. One component is a “sensor”: a driver installed on client machines that observes system activity and recognizes malicious behavior, then provides on-box prevention capability and remote telemetry to the Falcon Host cloud. The sensor processes thousands of events per second to provide deep visibility into operations on the endpoint, and performs rich correlation and computation to identify malicious events and blocks malicious activity.

The cloud component aggregates sensor telemetry for each customer’s network, correlates malicious behavior across multiple machines, and presents our customers’ operations teams with a prioritized summary of the threats detected in their environments.This is a Linux Engineer role in the engineering team that delivers code for the Linux sensor (lightweight agent). SDE’s in the team own design and development of core features on the platform. Features will cross-cut most core OS subsystems such as file system, memory, process, and networking. Many features are also built in a way that they will have shared components across Mac and Linux. The team operates under the Agile development principles and ships frequently.

In this role you will research techniques for detecting malicious activity. Once researched you will develop them into production level solutions for deployment. This role requires a combination of deep understanding of Linux kernel and user space and a large amount of solution creativity. The role is a split of research and implementation working alongside a small group of engineers.

What You’ll Do:

  • Research, design and develop software for deployment

  • Own features from design to delivery

  • Collaborate with multi-functional team spread across geographies

  • Troubleshoot issues with the product as reported from customers responsively

  • Other projects as assigned

What You’ll Need:

  • Deep knowledge of Linux Internals

  • Familiarity and ideally experience with the Linux kernel programming and/or eBPF technology

  • Can develop high-quality code in one and ideally more of the following languages: C/C++ with the following characteristics:

  • high concurrency requirements needing strong use of multi-threading

  • high reliability requirements

  • detailed requirements on low-level operating characteristics (memory usage, efficient performance, conformance to standards)

  • Experience developing enterprise software for distribution to large number of systems including CI, testing, release management and issue handling is a plus

  • Able to communicate, collaborate, and work effectively in a distributed team




Benefits of Working at CrowdStrike:

  • Remote-first culture

  • Market leader in compensation and equity awards

  • Competitive vacation and flexible working arrangements

  • Comprehensive and inclusive health benefits

  • Physical and mental wellness programs

  • Paid parental leave, including adoption

  • A variety of professional development and mentorship opportunities

  • Offices with stocked kitchens when you need to fuel innovation and collaboration

We are committed to fostering a culture of belonging where everyone feels seen, heard, valued for who they are and empowered to succeed. Our approach to cultivating a diverse, equitable, and inclusive culture is rooted in listening, learning and collective action. By embracing the diversity of our people, we achieve our best work and fuel innovation - generating the best possible outcomes for our customers and the communities they serve.

CrowdStrike is committed to maintaining an environment of Equal Opportunity and Affirmative Action. If you need reasonable accommodation to access the information provided on this website, please contact [email protected] for further assistance.

CrowdStrike participates in the E-Verify program.

Notice of E-Verify Participation

Right to Work

CrowdStrike, Inc. is committed to fair and equitable compensation practices. The base salary range for this position in the U.S. is $100,000 - $150,000 per year + variable/incentive compensation + equity + benefits. A candidate’s salary is determined by various factors including, but not limited to, relevant work experience, skills, certifications and location.Expected Close Date of Job Posting is:08-26-2024