Senior CrowdStrike Architect

ACL Digital

United States

On-site

USD 180,000 - 230,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ACL Digital seeks a Senior CrowdStrike Architect to own the Falcon ecosystem across a large enterprise. You will lead architecture, deployment, multi-tenant federation, and escalation engineering for EDR/XDR capabilities.

You will act as Tier 3 escalation for complex incidents, threat hunting, and platform troubleshooting while coordinating with SOC and IT leadership to reduce risk and improve detection and response.

Qualifications

  • Hands-on CrowdStrike Falcon at enterprise scale (10,000+ endpoints).
  • Experience with RTR, IOAs/IOCs, and threat hunting.
  • Strong Windows/Linux/macOS internals knowledge and scripting skills.
  • Familiarity with SIEM integrations and MITRE ATT&CK mapping.

Responsibilities

  • Architect, implement, and maintain a CrowdStrike Falcon platform across multi-tenant environments.
  • Serve as Tier 3 escalation for endpoint incidents and advanced threat hunting.
  • Configure policy tuning, IOAs/IOCs, and feature rollout schedules.
  • Lead integration with SIEM/SOAR and threat intelligence feeds.
  • Mentor SOC staff and coordinate with IT leadership on risk reduction.

Skills

Threat hunting
Scripting
Incident response
Communication

Tools

CrowdStrike Falcon
Real-Time Response
Splunk
Microsoft Sentinel
Palo Alto Cortex

Job description

12+ Months of Contract with Possible Extension
About the Role

We're looking for a Senior CrowdStrike Architect to serve as the primary technical authority for our enterprise Endpoint Detection and Response (EDR/XDR) platform. This role owns the architecture, administration, multi-tenant federation, fine-tuning, and escalation engineering of the CrowdStrike Falcon ecosystem across a large, multi-agency enterprise environment.

You’ll act as the highest level of technical escalation (Tier 3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations including Next-Gen SIEM, threat intelligence, and automated orchestration.

What You’ll Do
  • Architect, implement, and maintain a state-wide CrowdStrike Falcon platform across multi-tenant environments (CID hierarchy, RBAC, policy groups)
  • Oversee sensor deployment strategies, policy prevention/detection tuning, custom rule creation (IOAs/IOCs), and feature rollout schedules across diverse environments
  • Manage platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads
  • Act as the final technical escalation point for complex endpoint threats, zero-day vulnerabilities, and persistent malware identified by Tier 1/2 SOC analysts
  • Execute advanced containment, remediation, and live forensics using Real-Time Response (RTR) and custom scripts during critical incidents
  • Partner with SOC Analysts and Incident Response teams to refine playbooks, minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk reduction
  • Design and support telemetry integration between CrowdStrike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds
  • Introduce new integration ideas to better leverage existing security tools
  • Leverage CrowdStrike Fusion SOAR workflows to automate routine containment, notifications, and response actions
  • Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules as platform needs evolve
  • Translate complex technical threat data into actionable guidance for IT administrators and executive leadership
  • Develop dashboards using the CrowdStrike API to track daily vulnerability data and other key metrics, providing clear visibility into the enterprise environment
  • Develop standardized operating procedures (SOPs), deployment guides, and platform hardening specifications for IT partners
  • Serve as the primary technical point of contact with CrowdStrike engineering and technical account managers (TAMs) to drive feature requests and resolve critical bugs
  • Provide formal and informal technical mentoring and training to Tier 1/2 SOC staff
Required Experience
  • 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints)
  • Demonstrated proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting
  • Strong knowledge of Windows, Linux, and macOS internals, plus scripting capabilities (PowerShell, Python, Bash) for automated remediation and API integration
  • Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping
Required Certifications (at least one active)
CrowdStrike-specific (highly preferred):
Industry certifications:
  • CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential
Professional & Soft Skills
  • Unwavering commitment to confidentiality, integrity, and compliance standards
  • Proven ability to explain technical risk clearly to non-technical stakeholders and leadership
  • High analytical capability to navigate complex multi-tenant environments and conflicting operational priorities
  • Strong interpersonal skills with a commitment to fostering a diverse, supportive, team-oriented environment
Preferred Qualifications
  • Prior experience in government (SLTT), higher education, or large-scale multi-tenant enterprise environments
  • Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex)
  • Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Tier 3 CroudStrike Architect
Senior Tier 3 CroudStrike Architect

JPS Tech Solutions • Iowa (LA)

On-site
USD 120,000 - 180,000
Senior Tier 3 CroudStrike Architect
Senior Tier 3 CroudStrike Architect

Novisync Solutions Inc. • Iowa (LA)

On-site
USD 120,000 - 180,000
Senior Tier 3 CroudStrike Architect
Senior Tier 3 CroudStrike Architect

Mbi Llc • Des Moines (IA), Northern (KY)

Hybrid
USD 120,000 - 160,000
Senior Endpoint Protection Engineer
Senior Endpoint Protection Engineer

Jobtailor • California (MO)

On-site
USD 120,000 - 160,000
CrowdStrike Platform Associate Resident Consultant (Remote)
CrowdStrike Platform Associate Resident Consultant (Remote)

CrowdStrike • Town of Texas (WI)

On-site
USD 70,000 - 95,000
Market compensation and equity
Wellness programs
Generous vacation and holidays
+5
CrowdStrike Platform Associate Resident Consultant (Remote)
CrowdStrike Platform Associate Resident Consultant (Remote)

CrowdStrike • United States

On-site
USD 70,000 - 95,000
Equity awards
Wellness programs
Paid time off
+1
Platform Professional Services Sr. Consultant- Cloud (Remote)
Platform Professional Services Sr. Consultant- Cloud (Remote)

CrowdStrike, Inc. • Town of Texas (WI)

Remote
USD 95,000 - 140,000
Health insurance
Equity awards
Professional development
+1
Principal Software Engineer – Sensor, Telemetry & Observability (Hybrid)
Principal Software Engineer – Sensor, Telemetry & Observability (Hybrid)

CrowdStrike • Oregon (WI)

On-site
USD 195,000 - 290,000
Equity awards
Health insurance
Paid time off
+1
Manager, Platform Professional Services (Remote)
Manager, Platform Professional Services (Remote)

CrowdStrike • California (MO)

On-site
USD 140,000 - 195,000
Market-leading compensation
Comprehensive wellness programs
Paid parental leaves
+2
Engineer 3, Sensor - SSP (Hybrid)
Engineer 3, Sensor - SSP (Hybrid)

CrowdStrike • Sunnyvale (CA)

Hybrid
USD 120,000 - 180,000
Market leading compensation
Equity awards
Comprehensive wellness programs
+6