CrowdStrike Architect
Ubertal Inc. · Des Moines, IA · 1 wk ago
DesignFull-time
Location: Des Moines, IA | Engagement Type: Contract | Work Mode: Remote | Duration: ~9.5 Months (09/14/2026 – 06/30/2027)
About the Role
Serves as the primary technical authority for an enterprise-wide Endpoint Detection and Response (EDR / XDR) platform. Responsible for platform architecture, multi-tenant federation, administration, fine-tuning, and Tier 3 technical escalation engineering across enterprise environments. Acts as the highest escalation point for complex endpoint threats, threat hunting, platform troubleshooting, and security integrations.
Responsibilities
- Architect, implement, and maintain the enterprise CrowdStrike Falcon platform architecture across multi-tenant environments, managing CID hierarchy, RBAC, and policy groups.
- Oversee sensor deployment strategies, policy tuning, custom IOA/IOC rule creation, and feature rollout schedules across diverse environments.
- Maintain platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads.
- Serve as the final Tier 3 technical escalation point for zero-day vulnerabilities, complex endpoint threats, and persistent malware.
- Execute live forensics, advanced containment, and remediation using Real-Time Response (RTR) and custom scripts.
- Partner with SOC Analysts and Incident Response teams to refine playbooks and improve MTTD and MTTR metrics.
- Design telemetry integrations between CrowdStrike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds.
- Automate routine containment, notifications, and response actions using CrowdStrike Fusion SOAR workflows.
- Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules.
- Develop custom dashboards using CrowdStrike APIs to report daily vulnerability metrics and enterprise security visibility.
- Standardize operating procedures, deployment guides, and platform hardening specifications.
- Provide technical mentoring and training to Tier 1 and Tier 2 SOC personnel while liaising with vendor technical teams.
Requirements
- 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).
- 4+ years of Tier 3 Incident Response experience, including CrowdStrike RTR, writing custom IOAs/IOCs, and endpoint threat hunting.
- 4+ years of experience with Windows, Linux, and macOS internals, alongside scripting capabilities in PowerShell, Python, or Bash for API integration and automated remediation.
- 4+ years of experience in network security (firewalls, IDS/IPS), IAM (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping.
- Must hold at least one active CrowdStrike certification (CCFA, CCFR, CCFH) or an advanced industry security credential (CISSP, GCFA, GCIH, GSEC, CISA, or equivalent).
- 7+ years of experience demonstrating high ethics/integrity, clear technical communication to non-technical leaders, and complex problem-solving capabilities.
Preferred Skills
- Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.
- Hands-on experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).
- Familiarity with federal and state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).
Schedule
Monday through Friday, 8:00 AM – 4:30 PM CST.