Haystack
← Back to Jobs
Other
DK

Senior CrowdStrike Falcon Architect

DKMRBH Inc.United States🇺🇸United StatesPosted 18 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Senior CrowdStrike Falcon Engineer / Architect

We are looking for a senior CrowdStrike Falcon engineer / architect to serve as the Tier 3 technical authority for a large enterprise CrowdStrike Falcon EDR/XDR environment.

This is a hands-on CrowdStrike engineering and architecture position, not a general SOC analyst role. The person in this role will own advanced Falcon administration, enterprise architecture, endpoint security policy, detection tuning, threat hunting, incident response, Real-Time Response (RTR), IOA/IOC development, Falcon API integrations, automation, and complex Tier 3 troubleshooting.

The environment includes 10,000+ endpoints across multiple agency environments, so experience managing CrowdStrike Falcon at enterprise scale is critical.

What You Will Work On

CrowdStrike Falcon Architecture & Engineering

  • Architect, administer, and maintain the enterprise CrowdStrike Falcon platform across multiple environments.
  • Manage Falcon CID hierarchy, RBAC, host groups, security policies, sensor deployment, and prevention and detection controls.
  • Develop and tune CrowdStrike prevention, detection, and response policies.
  • Create and maintain custom IOAs and IOCs.
  • Manage CrowdStrike sensor deployment, upgrades, agent health, and troubleshooting.
  • Support Falcon across Windows, Linux, macOS, and virtualized workloads.
  • Evaluate new CrowdStrike capabilities and determine how they should be deployed across the enterprise.

Tier 3 Incident Response & Threat Hunting

  • Act as the highest-level technical escalation point for complex endpoint security incidents.
  • Investigate advanced malware, persistent threats, zero-day vulnerabilities, and sophisticated endpoint activity.
  • Perform advanced threat hunting and endpoint investigation using CrowdStrike Falcon.
  • Use CrowdStrike Real-Time Response (RTR) for live investigation, containment, remediation, and forensic activities.
  • Develop scripts and response actions for complex endpoint incidents.
  • Analyze endpoint activity and map adversary behavior to MITRE ATT&CK.
  • Partner with SOC and Incident Response teams to improve detection and response processes.

Integration, API & Security Automation

  • Integrate CrowdStrike Falcon with enterprise SIEM, SOAR, threat intelligence, network security, and identity security platforms.
  • Develop and support CrowdStrike Falcon API integrations.
  • Build security automation using PowerShell, Python, and Bash.
  • Develop automated response workflows using CrowdStrike Fusion.
  • Support integrations with platforms such as Splunk, Microsoft Sentinel, Palo Alto Cortex, and other security technologies.
  • Identify opportunities to automate endpoint investigation, containment, remediation, reporting, and operational tasks.

Enterprise Platform Management

  • Monitor overall CrowdStrike platform health, endpoint coverage, sensor status, and policy effectiveness.
  • Develop dashboards and reporting through the CrowdStrike API for vulnerabilities, detections, endpoint status, and security metrics.
  • Create technical standards, deployment procedures, SOPs, and platform hardening documentation.
  • Work directly with CrowdStrike Engineering and Technical Account Managers on complex product issues, bugs, and technical escalations.
  • Provide technical guidance and mentoring to Tier 1/Tier 2 security teams.

Required Experience

CrowdStrike Falcon – Required

  • 4+ years of hands-on CrowdStrike Falcon engineering and administration experience.
  • Experience designing, deploying, maintaining, and troubleshooting CrowdStrike Falcon EDR/XDR in a large enterprise environment.
  • Experience supporting 10,000+ endpoints or a comparable enterprise-scale environment.
  • Strong hands-on experience with:
    • CrowdStrike Falcon administration
    • Falcon EDR/XDR
    • Real-Time Response (RTR)
    • IOA / IOC development
    • Detection and prevention policy tuning
    • Host groups
    • RBAC
    • Sensor deployment
    • Endpoint troubleshooting
    • Threat hunting

Tier 3 Security / Incident Response

  • 4+ years of experience in advanced endpoint security, incident response, threat hunting, detection engineering, or Tier 3 security operations.
  • Demonstrated ability to investigate and remediate complex endpoint threats.
  • Strong understanding of MITRE ATT&CK and modern endpoint attack techniques.

Operating Systems & Automation

Strong working knowledge of:

  • Windows
  • Linux
  • macOS

Hands-on scripting experience with PowerShell, Python, and/or Bash, particularly for endpoint remediation, security automation, and API integration.

Enterprise Security Technologies

Experience working with several of the following:

  • SIEM / SOAR
  • Network security
  • Firewalls
  • IDS/IPS
  • Identity and Access Management
  • Active Directory
  • Microsoft Entra ID
  • Vulnerability management
  • Patch management
  • Threat intelligence
  • Endpoint security

Certification Requirement

At least one active CrowdStrike certification is required:

  • CCFA – CrowdStrike Certified Falcon Administrator
  • CCFR – CrowdStrike Certified Falcon Responder
  • CCFH – CrowdStrike Certified Falcon Hunter

Additional security certifications such as CISSP, GCFA, GCIH, GSEC, or CISA are highly desirable.

Preferred Experience

  • CrowdStrike experience in a state/local government, higher education, or large enterprise environment.
  • Multi-tenant CrowdStrike Falcon architecture and administration.
  • CrowdStrike Falcon API development/integration.
  • CrowdStrike Fusion automation.
  • SIEM/SOAR integrations with Splunk, Microsoft Sentinel, Palo Alto Cortex, or similar platforms.
  • Familiarity with NIST SP 800-53, CJIS, HIPAA, or IRS Publication 1075.
  • Experience with ITDR or CSPM technologies.

Skills

Splunk
Active Directory
Bash
HIPAA
PowerShell
Python

Similar jobs