CroudStrike Architect
Quick Overview
Job Description
This position acts as the highest level of technical escalation (Tier 3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations (such as Next-Gen SIEM, threat intelligence, and automated orchestration).
1. Platform Architecture & Multi-Tenant Administration
Architect, implement, and maintain the state-wide CrowdStrike Falcon platform architecture across multi-tenant environments (CID hierarchy, RBAC, policy groups).
Oversee sensor deployment strategies, policy prevention/detection tuning, custom rule creation (IOAs/IOCs), and feature rollout schedules across diverse agency environments.
Manage CrowdStrike platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads.
2. Tier 3 Incident Escalation & Response Engineering
Act as the final technical escalation point for complex endpoint threats, zero-day vulnerabilities, and persistent malware identified by Tier 1/2 SOC analysts.
Execute advanced containment, remediation, and live forensics using Real-Time Response (RTR) and custom scripts during critical incidents.
Partner with SOC Analysts and Incident Response teams to refine playbooks, minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk reduction.
3. Integration, Automation & Data Pipeline
Design and support telemetry integration between CrowdStrike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds.
Introduce new integration ideas to better levergage existing security tools.
Leverage CrowdStrike Fusion SOAR workflows to automate routine containment, notifications, and response actions.
Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules as platform needs evolve.
4. Stakeholder Enablement, Training & Vendor Management
Translate complex technical threat data into actionable guidance for agency IT administrators and executive leadership.
Develop dashboards using the CrowdStrike API to collect daily vulnerability data, and other key metrics, providing clear and actionable visibility into the enterprise environment.
Develop standardized operating procedures (SOPs), deployment guides, and platform hardening specifications for state agency IT partners.
Serve as the primary technical point of contact with CrowdStrike engineering and technical account managers (TAMs) to drive feature requests and resolve critical bugs.
Provide formal and informal technical mentoring and training to Tier 1/2 SOC staff.
Skills
Similar jobs
Low Voltage Cabling Design Engineer, Network Infrastructure Desi with Security Clearance
Amazon · San Antonio, United States
2 minutes ago$111.3k - $186.1k/yrSenior Supervisor, Configuration Management with Security Clearance
L3Harris Technologies · Palm Bay, United States
2 minutes agoNetwork Development Engineer, ADC Network Design, Engineering, a with Security Clearance
Amazon · Arlington, United States
2 minutes ago$136k - $184k/yrNetwork Development Engineer, AWS ADC Networking with Security Clearance
Amazon · Seattle, United States
2 minutes ago$136k - $184k/yrReactJS Lead
Photon · Las Vegas, United States
25 minutes ago.NET Technical Lead
QUANTUM TECHNOLOGIES LLC · United States
25 minutes ago$85/hr