Summary
What you’ll impact
The Senior Consultant will configure and manage a cloud security platform and its CNAPP modules for a state government health agency, working directly with the organization’s Technology and Cloud Engineering teams. The role involves end-to-end implementation of CSPM, CWP, CIEM, and container security across Kubernetes and a managed Kubernetes service environments, with hands‑on testing and communication of findings.
Responsibilities
What you'll do
- Configure CrowdStrike Falcon Cloud Security and its applicable CNAPP modules in the Falcon console
- Configure Kubernetes and Amazon EKS security policies
- Establish Cloud Security Posture Management (CSPM) policies and tune Cloud Detection and Response (CDR) detections
- Configure Cloud Workload Protection (CWP) and runtime security policies across development, non-production, performance, and production environments
- Execute security use-case testing to validate detection, containment, and admission-control functionality
- Implement end-to-end container security spanning image scanning, admission control, and runtime protection
- Configure Cloud Infrastructure Entitlement Management (CIEM) capabilities, including entitlement analysis
- Communicate architecture, implementation decisions, and technical findings to leadership and client stakeholders
Requirements
What you’ll bring
- 3+ years of hands-on experience configuring CrowdStrike Falcon Cloud Security and CNAPP modules (or a comparable CNAPP platform such as Wiz or Palo Alto Prisma Cloud), with CrowdStrike experience strongly preferred
- Experience configuring Kubernetes and Amazon EKS security policies
- Experience establishing CSPM policies and tuning CDR detections
- Experience configuring CWP and runtime security policies across development, non-production, performance, and production environments
- Experience executing security use-case testing to validate detection, containment, and admission-control functionality
- Experience implementing end-to-end container security (image scanning, admission control, runtime protection)
- Experience configuring CIEM capabilities, including entitlement analysis
- Legally authorized to work in the U.S.; able to perform all work within the continental U.S.
- Able to work primarily remote with travel approximately once per month