Full-Time
Updated on 9/4/2026
Cloud-native endpoint security platform provider
$90k - $125k/yr
Company Historically Provides H1B Sponsorship
Sunnyvale, CA, USA
Hybrid
Two days on-site per week required.
Master's, PhD
See people who can refer or advise you
CrowdStrike provides cloud-native endpoint security for businesses, protecting computers and servers from cyber threats. Its Falcon platform runs in the cloud and includes Falcon Pro (next-generation antivirus with threat intelligence and fast threat response), Falcon Insight (endpoint detection and response), and Falcon Device Control (manages and restricts network-connected devices). It differentiates itself by offering a fully cloud-first security suite that integrates intelligence and automated responses across multiple tools, serving many Fortune 100 companies and other large organizations in finance, healthcare, and energy. Its goal is to help organizations prevent, detect, and quickly respond to threats through a scalable, subscription-based platform.
Company Size
10,001+
Company Stage
IPO
Headquarters
Austin, Texas
Founded
2011
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Competitive Employee Stock Purchase Plan
Remote-friendly culture
Market leader in compensation and equity awards
Competitive vacation and flexible working arrangements
Comprehensive health benefits + 401k plan
Paid Parental Leave, including adoption
Wellness programs
Professional development and mentorship opportunities
Open offices have stocked kitchens, coffee, soda and treats
CrowdStrike is positioned as a leading investment opportunity in cybersecurity as AI creates new threats from bad actors. The company's AI-powered platform specialises in endpoint protection, using artificial intelligence to detect abnormal device usage patterns. CrowdStrike's annual recurring revenue grew 25% in its most recent quarter. Over half its customers use at least six different modules, demonstrating successful upselling. However, the company posted only $5 million in net income that quarter, hovering near break-even for several years. The stock trades at a price-to-sales ratio of 41, which analysts consider expensive even for the cybersecurity sector. Whilst CrowdStrike is recognised as an industry leader with multiple product offerings beyond endpoint protection, its high valuation may deter some investors despite its strong market position.
CrowdStrike extends its endpoint advantage to secure the Software Supply Chain. As AI rewrites how software gets built, CrowdStrike stops malicious open-source packages at the endpoint before they execute. CrowdStrike introduced Real-Time Supply Chain Attack Protection, a new Falcon platform innovation that blocks malicious open-source packages at the endpoint before their embedded code can run. AI has changed how software gets built. Coding agents now assemble applications from open-source packages pulled off public registries at machine speed, faster than anyone can review what comes in. A poisoned package runs its code on the endpoint the moment it installs. The endpoint is the point of execution, and where the Falcon sensor already operates. CrowdStrike blocks malicious packages in real time, before that code can run. "Attackers know that compromising one trusted package can give them a path into thousands of organizations. That makes the software supply chain one of the most powerful attack surfaces in the AI era," said Michael Sentonas, president of CrowdStrike. "The endpoint is where malicious code executes, and only CrowdStrike turns it into the control point that stops the attack." Software Supply Chain Risk Converges on the Endpoint Adversaries have industrialized poisoning the packages enterprises trust. CrowdStrike's 2026 Threat Hunting Report found DPRK-nexus adversary STARDUST CHOLLIMA poisoned 131 trusted AI framework packages, while eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day. The risk no longer stops at engineering. As AI agents spread across the business, any endpoint can pull a package to finish a task, and the attack surface widens to the whole enterprise. A poisoned package does not look like malware. It arrives as an ordinary file and runs its code the moment it installs. Legacy endpoint tools were built to catch executables, not to govern the packages that assemble AI software. Standalone scanners, proxies, and browser-based tools flag compromises days after poisoned packages have already landed. If not stopped at the endpoint before embedded scripts execute, a poisoned package moves downstream, giving adversaries a foothold. Stopping Malicious Packages Before They Run CrowdStrike Real-Time Supply Chain Attack Protection stops malicious packages the moment they reach the endpoint, intercepting at the command line, before any embedded script runs. Because CrowdStrike already enforces at that checkpoint through the same sensor, adversary intelligence, and response orchestration securing the endpoint, protection carries forward into whatever the package tries to do next: execution, credential access, lateral movement. No new agent, and no coverage gaps. * Block Malicious Packages at Download: The Falcon sensor intercepts open-source package manager transactions - npm install, pip install - across npm and PyPI on Windows, macOS, and Linux, before any embedded script runs. Protection extends to every endpoint where agentic applications run, not just developer workstations. * Stop the Attack Before it Starts: Security teams can set granular controls to govern what code reaches their endpoints - including minimum package age requirements - so the most common vector of supply chain compromise never gets a foothold. * Automated Investigation and Response: The moment a package is flagged, CrowdStrike automatically runs a lookback across every endpoint and triggers remediation through Charlotte Agentic SOAR. * Global Package Inventory: Delivers complete visibility into every software package installed across every endpoint, so when a package is compromised, security teams know exactly where it lives and can act immediately. Securing the Software Enterprises Build on AI Software will only be built faster and with more automation. CrowdStrike makes the endpoint the control point for the software supply chain, so enterprises can build on AI without leaving the door open to the adversary.
CrowdStrike Unveils the Next Evolution of the Agentic SOC. Autonomous attacks move across systems at machine speed - only CrowdStrike can investigate every domain simultaneously. CrowdStrike unveiled the next evolution of the agentic SOC. AI agents execute attack actions across multiple systems at machine speed. The investigation has to move the same way. CrowdStrike delivers the first coordinated, multi-agent investigations across endpoint, identity, SaaS, cloud, and network simultaneously, turning what once took hours into minutes, with verdicts defenders can trust. "We're already seeing AI agents execute attacks across multiple systems at the same time," said Michael Sentonas, president of CrowdStrike. "AI agents in the SOC are table stakes. Agents working together across every domain, on the same investigation, that's the new standard. CrowdStrike's architecture and expert validation make this possible, and confidently answer the question every CISO is asking: how do I trust what my agents found, and how do I know it's right?" AI Attacks Break Isolated Investigations on Fragmented Data First-generation AI SOC tools dispatch individual agents to investigate alerts in sequence. AI attacks don't move that way. They exploit credentials, socially engineer, and operate across multiple services in parallel at machine speed. An agent investigating one domain alone produces a piece of the puzzle, not a verdict. When vendors bolt agents onto fragmented data stacks, every connectivity gap becomes an investigation gap. By the time the pieces are assembled, the breach has already happened. Unified Data. Expert-Trained Agents. Coordinated Investigations. Only CrowdStrike delivers a single sensor, single console, single platform architecture generating nearly four trillion events daily across endpoint, identity, SaaS, cloud, and network. CrowdStrike's elite analysts reinforce agents with expert decisions from every MDR and IR engagement, making agents smarter with every breach stopped. On this foundation, Charlotte AI dispatches domain agents in parallel, all operating on a new shared context layer, a persistent memory across every agent, investigation, and tenant. What one agent learns, they all know, eliminating handoffs and letting agents work the same investigation together across domains. Agents investigate the way elite analysts work, weighing evidence and converging on a single trusted hypothesis with visible reasoning and justification to back it up. Analysts no longer stitch isolated findings together. Agents do - at machine speed * Coordinated Multi-Agent Investigations: Investigations cover every domain simultaneously, including threats targeting enterprise AI systems: model abuse, prompt injection, and exfiltration through AI assistants. Agents deliver a trusted verdict with staged response actions. Analysts stop doing the grind and start making the call. * Shared Context Layer: Building upon Enterprise Graph, the AI-ready data layer unifying telemetry across the enterprise, the shared context layer makes coordinated investigations possible. Every agent shares one memory of the environment. What one learns, they all know. The more investigations run, the more precise future investigations become. * Certified Data Pipelines: Built on Falcon Onum streaming pipeline technology, these pipelines filter out noise at ingestion so agents only process what matters, working faster and more precisely. Detection runs inside the pipeline, so threats are caught in-stream before data ever lands. Certified by Falcon Complete, no security-relevant data is dropped while connecting any third-party source directly into Falcon Next-Gen SIEM and reducing data storage costs by up to 50 percent. * Single-Governed Automation Workspace: Charlotte Agentic SOAR brings Charlotte AI AgentWorks and Falcon Foundry together in one workspace, letting teams build and govern no-code agents on the model of their choice alongside custom applications and workflows on Falcon data. Customers set the autonomy level for each workflow, from human-in-the-loop approval to fully autonomous execution. Bidirectional MCP connects any third-party agent into Falcon and any CrowdStrike agent - custom or Agentic Security Workforce - out to external tools, bringing every agent, model, and tool together in one workspace, from build to response.
CrowdStrike launches AI security tools for enterprises. Thu, 3rd Sep 2026 (Today) CrowdStrike has unveiled new security products for AI-driven operations, software supply chain protection and identity management, expanding its Falcon platform into three areas of growing concern for corporate security teams. The most prominent update is what CrowdStrike describes as the next stage of its Agentic Security Operations Centre. Multiple AI agents can investigate a security incident across endpoint, identity, software-as-a-service, cloud and network environments at the same time. The system is designed to address attacks that move across different systems in parallel rather than along a linear path. In that model, separate tools focused on separate domains can leave analysts to piece together incomplete findings after the event. CrowdStrike said its approach allows domain-specific agents to work from a shared context layer, enabling each one to use information gathered by the others during the same investigation. The aim is to produce a single conclusion rather than a string of disconnected alerts. The updated system also covers threats targeting enterprise AI systems, including model abuse, prompt injection and data exfiltration through AI assistants. Alongside the investigation tools, CrowdStrike introduced a single workspace for building and governing automated response processes with varying levels of human oversight. Michael Sentonas, President, CrowdStrike, said the changes reflect the pace and spread of AI-based attacks. "IT Brief is already seeing AI agents execute attacks across multiple systems at the same time. "AI agents in the SOC are table stakes. Agents working together across every domain, on the same investigation, that's the new standard. CrowdStrike's architecture and expert validation make this possible, and confidently answer the question every CISO is asking: how do I trust what my agents found, and how do I know it's right?" Supply chain A second product launch focused on software supply chain attacks, an area that has become more urgent as developers and automated coding tools rely heavily on open-source packages from public repositories. CrowdStrike introduced Real-Time Supply Chain Attack Protection, which it said blocks malicious open-source packages at the endpoint before any embedded code can run. The tool targets package manager activity such as npm and pip installations across Windows, macOS and Linux. CrowdStrike argues that the endpoint has become the critical control point because harmful package code executes at installation. It said the product can intercept those transactions before scripts run, then trigger investigation and remediation across affected endpoints. The product also gives security teams a package inventory across endpoints, allowing them to identify where a compromised dependency has been installed. Teams can set controls such as minimum package age requirements in an effort to reduce exposure to newly poisoned packages. CrowdStrike linked the launch to threat activity it has observed in package ecosystems. It cited findings from its threat-hunting research that said a DPRK-linked actor known as STARDUST CHOLLIMA poisoned 131 trusted AI framework packages, while an eCrime actor called ALTERED SPIDER compromised more than 300 software dependencies in a single day. Sentonas said supply chain compromise had become a major entry point for attackers. "Attackers know that compromising one trusted package can give them a path into thousands of organisations. That makes the software supply chain one of the most powerful attack surfaces in the AI era. "The endpoint is where malicious code executes, and only CrowdStrike turns it into the control point that stops the attack." Identity controls The third launch was an Agentic Identity Provider, intended to create and manage trusted identities for AI agents acting inside corporate systems. The move addresses a problem now emerging as software agents carry out tasks, access applications and move data with little direct human involvement. Traditional identity systems were built around user logins, passwords and manually provisioned accounts, whereas autonomous agents are often represented through service accounts, API keys or workload identities. CrowdStrike said its Agentic Identity Provider automatically registers AI agents when they come online, issues cryptographically verifiable identities and grants short-lived access tokens limited to the minimum access needed for each task. It also said every action can be tied back to the human user or workload on whose behalf the agent is acting. The product sits alongside the company's wider Continuous Identity model, which replaces standing access rights with real-time authorisation and revocation. CrowdStrike argues that before an AI agent can be continuously authorised, it first has to be established as a recognised identity within the organisation's control systems. Scott Kriz, GM of Continuous Identity at CrowdStrike, said existing identity products were not designed for autonomous software actors. "Securing AI agents demands solutions built for how they operate. "Continuous Identity modernised identity security for the agentic era, but you cannot continuously authorise an identity you were never able to establish, and traditional identity providers break the moment an agent acts on its own. Agentic IdP is the identity provider for AI agents."
Introducing the CrowdStrike Agentic Identity Provider, the foundation for AI Agent Identity Security. CrowdStrike's Agentic IdP creates trusted identities for AI agents, accelerating the shift to Continuous Identity AUSTIN, Texas and Fal.Con 2026, Las Vegas - September 2, 2026 - CrowdStrike (NASDAQ: CRWD) today introduced the CrowdStrike Agentic Identity Provider (Agentic IdP), establishing Falcon Next-Gen Identity Security as the identity control plane for the agentic enterprise and the Falcon platform as the standard to operationalize and secure AI agents. Identity is the front line of modern attacks, and AI agents accelerate the threat at scale. They execute code, access systems, and move data with real credentials, at machine speed, with no one watching. Before they can be continuously authorized, they must first be established as trusted identities, something traditional identity providers were never built to do. Agentic IdP establishes every agent as a trusted identity, brokers only the access needed for as long as needed, and ties every action back to the human or system behind it. This is the foundation that makes Continuous Identity possible. "Securing AI agents demands solutions built for how they operate," said Scott Kriz, GM of Continuous Identity at CrowdStrike. "Continuous Identity modernized identity security for the agentic era, but you cannot continuously authorize an identity you were never able to establish, and traditional identity providers break the moment an agent acts on its own. Agentic IdP is the identity provider for AI agents." Continuous Identity for AI Agents AI agents operate at machine speed with system-level privilege, making point-in-time authorization a liability, not a security model. CrowdStrike's Continuous Identity replaces static policies and standing privileges with real-time, risk-aware enforcement, granting access the moment it is needed and revoking it the moment it is not. CrowdStrike Agentic Identity Provider An identity provider is the system of record every downstream security decision depends on. For humans, that authority is built on logins, passwords, and manual onboarding. Agents have none of it. Traditional identity providers force organizations to represent agents as service accounts, API keys, and workload identities, static models never meant for identities that take autonomous action on behalf of users and delegate to sub-agents. Agentic IdP is the authority for AI agents. * Automatic Registration: Falcon Guardian discovers every AI agent across the enterprise, and Agentic IdP registers each one the moment it comes online under a single authoritative directory. * Cryptographically Verifiable Agent Identity: Every agent is issued a cryptographically verifiable identity that cannot be spoofed or shared. Only agents with a trusted identity are eligible for authorization. Every access decision is then made by Continuous Identity. * Short-Lived, Tightly-Scoped Tokens: Agents are never given standing credentials of their own. Agentic IdP brokers access through tokens scoped to the minimum access, for the minimum time, required for each task. * Attribution at Every Step: Every action an agent takes is bound to the human or workload it acts on behalf of, so every step is traceable and accountable. The AI Agent Security Platform With Falcon, every agent is discovered, established as a trusted identity, authorized in real time, and secured at runtime. The full lifecycle, on one platform. To learn more, read our blog and visit here. About CrowdStrike CrowdStrike (NASDAQ: CRWD), a global cybersecurity leader, has redefined modern security with the world's most advanced cloud-native platform for protecting critical areas of enterprise risk - endpoints and cloud workloads, identity and data. Powered by the CrowdStrike Security Cloud and world-class AI, the CrowdStrike Falcon(R) platform leverages real-time indicators of attack, threat intelligence, evolving adversary tradecraft and enriched telemetry from across the enterprise to deliver hyper-accurate detections, automated protection and remediation, elite threat hunting and prioritized observability of vulnerabilities. Purpose-built in the cloud with a single lightweight-agent architecture, the Falcon platform delivers rapid and scalable deployment, superior protection and performance, reduced complexity and immediate time-to-value. CrowdStrike: We stop breaches. Learn more: https://www.crowdstrike.com/ Follow us: Blog | X | LinkedIn | Instagram Start a free trial today: https://www.crowdstrike.com/trial (C) 2026 CrowdStrike, Inc. All rights reserved. CrowdStrike and CrowdStrike Falcon are marks owned by CrowdStrike, Inc. and are registered in the United States and other countries. CrowdStrike owns other trademarks and service marks and may use the brands of third parties to identify their products and services. Forward-Looking Statements This release includes discussion of unreleased services or features. Any unreleased services or features referenced here are still in development and subject to change. Customers should make their purchase decisions based upon features that are currently available. Media Contact Jake Schuster CrowdStrike Corporate Communications [email protected]