Jobs · Design

CrowdStrike Architect

Ubertal Inc. · Des Moines, IA · 1 wk ago
DesignFull-time

Location: Des Moines, IA | Engagement Type: Contract | Work Mode: Remote | Duration: ~9.5 Months (09/14/2026 – 06/30/2027)

About the Role

Serves as the primary technical authority for an enterprise-wide Endpoint Detection and Response (EDR / XDR) platform. Responsible for platform architecture, multi-tenant federation, administration, fine-tuning, and Tier 3 technical escalation engineering across enterprise environments. Acts as the highest escalation point for complex endpoint threats, threat hunting, platform troubleshooting, and security integrations.

Responsibilities

  • Architect, implement, and maintain the enterprise CrowdStrike Falcon platform architecture across multi-tenant environments, managing CID hierarchy, RBAC, and policy groups.
  • Oversee sensor deployment strategies, policy tuning, custom IOA/IOC rule creation, and feature rollout schedules across diverse environments.
  • Maintain platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads.
  • Serve as the final Tier 3 technical escalation point for zero-day vulnerabilities, complex endpoint threats, and persistent malware.
  • Execute live forensics, advanced containment, and remediation using Real-Time Response (RTR) and custom scripts.
  • Partner with SOC Analysts and Incident Response teams to refine playbooks and improve MTTD and MTTR metrics.
  • Design telemetry integrations between CrowdStrike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds.
  • Automate routine containment, notifications, and response actions using CrowdStrike Fusion SOAR workflows.
  • Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules.
  • Develop custom dashboards using CrowdStrike APIs to report daily vulnerability metrics and enterprise security visibility.
  • Standardize operating procedures, deployment guides, and platform hardening specifications.
  • Provide technical mentoring and training to Tier 1 and Tier 2 SOC personnel while liaising with vendor technical teams.

Requirements

  • 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).
  • 4+ years of Tier 3 Incident Response experience, including CrowdStrike RTR, writing custom IOAs/IOCs, and endpoint threat hunting.
  • 4+ years of experience with Windows, Linux, and macOS internals, alongside scripting capabilities in PowerShell, Python, or Bash for API integration and automated remediation.
  • 4+ years of experience in network security (firewalls, IDS/IPS), IAM (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping.
  • Must hold at least one active CrowdStrike certification (CCFA, CCFR, CCFH) or an advanced industry security credential (CISSP, GCFA, GCIH, GSEC, CISA, or equivalent).
  • 7+ years of experience demonstrating high ethics/integrity, clear technical communication to non-technical leaders, and complex problem-solving capabilities.

Preferred Skills

  • Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.
  • Hands-on experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).
  • Familiarity with federal and state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).

Schedule

Monday through Friday, 8:00 AM – 4:30 PM CST.

Similar jobs