12+ Months of Contract with Possible Extension
About the Role
We're looking for a Senior CrowdStrike Architect to serve as the primary technical authority for our enterprise Endpoint Detection and Response (EDR/XDR) platform. This role owns the architecture, administration, multi-tenant federation, fine-tuning, and escalation engineering of the CrowdStrike Falcon ecosystem across a large, multi-agency enterprise environment.
You’ll act as the highest level of technical escalation (Tier 3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations including Next-Gen SIEM, threat intelligence, and automated orchestration.
What You’ll Do
- Architect, implement, and maintain a state-wide CrowdStrike Falcon platform across multi-tenant environments (CID hierarchy, RBAC, policy groups)
- Oversee sensor deployment strategies, policy prevention/detection tuning, custom rule creation (IOAs/IOCs), and feature rollout schedules across diverse environments
- Manage platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads
- Act as the final technical escalation point for complex endpoint threats, zero-day vulnerabilities, and persistent malware identified by Tier 1/2 SOC analysts
- Execute advanced containment, remediation, and live forensics using Real-Time Response (RTR) and custom scripts during critical incidents
- Partner with SOC Analysts and Incident Response teams to refine playbooks, minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk reduction
- Design and support telemetry integration between CrowdStrike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds
- Introduce new integration ideas to better leverage existing security tools
- Leverage CrowdStrike Fusion SOAR workflows to automate routine containment, notifications, and response actions
- Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules as platform needs evolve
- Translate complex technical threat data into actionable guidance for IT administrators and executive leadership
- Develop dashboards using the CrowdStrike API to track daily vulnerability data and other key metrics, providing clear visibility into the enterprise environment
- Develop standardized operating procedures (SOPs), deployment guides, and platform hardening specifications for IT partners
- Serve as the primary technical point of contact with CrowdStrike engineering and technical account managers (TAMs) to drive feature requests and resolve critical bugs
- Provide formal and informal technical mentoring and training to Tier 1/2 SOC staff
Required Experience
- 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints)
- Demonstrated proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting
- Strong knowledge of Windows, Linux, and macOS internals, plus scripting capabilities (PowerShell, Python, Bash) for automated remediation and API integration
- Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping
Required Certifications (at least one active)
CrowdStrike-specific (highly preferred):
Industry certifications:
- CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential
Professional & Soft Skills
- Unwavering commitment to confidentiality, integrity, and compliance standards
- Proven ability to explain technical risk clearly to non-technical stakeholders and leadership
- High analytical capability to navigate complex multi-tenant environments and conflicting operational priorities
- Strong interpersonal skills with a commitment to fostering a diverse, supportive, team-oriented environment
Preferred Qualifications
- Prior experience in government (SLTT), higher education, or large-scale multi-tenant enterprise environments
- Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex)
- Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075)