Seeking an experienced CrowdStrike Architect to serve as the primary technical authority for an enterprise Endpoint Detection and Response (EDR/XDR) environment. This role will be responsible for the architecture, administration, multi-tenant federation, optimization, and advanced troubleshooting of the CrowdStrike Falcon platform across a large-scale enterprise environment.
Key Responsibilities:
Architect, implement, administer, and maintain the enterprise CrowdStrike Falcon platform across multi-tenant environments.
Develop and maintain enterprise sensor deployment and upgrade strategies.
Configure and tune prevention and detection policies and develop custom Indicators of Attack (IOAs) and Indicators of Compromise (IOCs).
Monitor platform health and troubleshoot Falcon sensors across Windows, Linux, macOS, and virtualized environments.
Serve as the Tier 3 escalation point for complex endpoint threats, zero-day vulnerabilities, persistent malware, and advanced security incidents.
Perform advanced endpoint investigation, containment, remediation, and live forensic activities using CrowdStrike Real-Time Response (RTR).
Conduct advanced threat hunting using CrowdStrike telemetry and endpoint data.
Design and support CrowdStrike integrations with enterprise SIEM, SOAR, network security, and threat intelligence platforms.
Develop integrations and automation using CrowdStrike Falcon APIs.
Develop and maintain CrowdStrike Fusion SOAR workflows to automate containment, notifications, and response activities.
Support integration and alignment with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) capabilities.
Develop scripts using PowerShell, Python, and/or Bash for automated remediation, platform administration, and API integrations.
Develop dashboards using CrowdStrike APIs to provide visibility into vulnerabilities, endpoint health, security incidents, and other enterprise security metrics.
Develop and maintain SOPs, deployment guides, troubleshooting documentation, and platform hardening standards.
Provide technical mentoring and training to Tier 1 and Tier 2 SOC analysts.
Work directly with CrowdStrike engineering teams and Technical Account Managers (TAMs) to troubleshoot critical platform issues and support feature enhancements.
Communicate complex security risks, findings, and recommendations to both technical teams and executive stakeholders.
Required Qualifications:
4+ years of hands-on experience engineering, deploying, administering, and maintaining CrowdStrike Falcon in enterprise environments.
Experience supporting CrowdStrike environments at significant scale, preferably 10,000+ endpoints.
Strong experience with CrowdStrike platform architecture and multi-tenant administration.
Hands-on experience with CrowdStrike Real-Time Response (RTR).
Experience creating and tuning custom IOAs and IOCs.
Strong experience performing advanced endpoint threat hunting and incident response.
Strong knowledge of Windows, Linux, and macOS internals.
Scripting experience using PowerShell, Python, and/or Bash.
Experience with automated endpoint remediation and security API integrations.
Strong understanding of network security, firewalls, IDS/IPS, IAM, Active Directory/Entra ID, patch management, and vulnerability management.
Knowledge of the MITRE ATT&CK framework and its application to threat detection and response.
Strong troubleshooting, analytical, and complex problem-solving skills.
Ability to communicate technical security risks and recommendations clearly to technical and non-technical stakeholders.
Experience collaborating across SOC, Incident Response, infrastructure, networking, IAM, and other security teams.
Numbers & Facts
Location
Des Moines, IA (Remote)
Skills
Analysis Skillsunmatched
Application Programming Interface (API)unmatched
Applications Securityunmatched
Automationunmatched
Bash Scriptingunmatched
Cloud Computingunmatched
Communication Skillsunmatched
Computer Securityunmatched
Documentationunmatched
Endpoint Securityunmatched
Enterprise Endpointunmatched
Enterprise Protectionunmatched
Firewallsunmatched
Huntingunmatched
Identify Issuesunmatched
Incident Responseunmatched
Intrusion Detection Systemsunmatched
Intrusion Prevention Systemsunmatched
Linux Operating Systemunmatched
Mac Operating Systemunmatched
Malwareunmatched
Mentoringunmatched
Metricsunmatched
Microsoft Active Directoryunmatched
Microsoft Windows Operating Systemunmatched
Network Securityunmatched
Problem Solving Skillsunmatched
Python Programming/Scripting Languageunmatched
Reporting Dashboardsunmatched
Sales Managementunmatched
Scripting (Scripting Languages)unmatched
Security Attacksunmatched
Security Information and Event Management (SIEM)unmatched
Software Patchesunmatched
Standard Operating Procedures (SOP)unmatched
Systems Administration/Managementunmatched
Technical Leadershipunmatched
Technical Trainingunmatched
Telemetryunmatched
Virtualizationunmatched
Windows PowerShellunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.