CrowdStrike Architect
Indianapolis, IN - USA
Job Summary
1. Platform Architecture & Multi-Tenant Administration
- Architect implement and maintain the state-wide CrowdStrike Falcon platform architecture across multi-tenant environments (CID hierarchy RBAC policy groups).
- Oversee sensor deployment strategies policy prevention/detection tuning custom rule creation (IOAs/IOCs) and feature rollout schedules across diverse agency environments.
- Manage CrowdStrike platform health agent updates host group management and agent troubleshooting across Windows macOS Linux and virtualized workloads.
2. Tier 3 Incident Escalation & Response Engineering
- Act as the final technical escalation point for complex endpoint threats zero-day vulnerabilities and persistent malware identified by Tier 1/2 SOC analysts.
- Execute advanced containment remediation and live forensics using Real-Time Response (RTR) and custom scripts during critical incidents.
- Partner with SOC Analysts and Incident Response teams to refine playbooks minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) and drive risk reduction.
3. Integration Automation & Data Pipeline
- Design and support telemetry integration between CrowdStrike Falcon central SIEM/SOAR platforms network defenses and threat intelligence feeds.
- Introduce new integration ideas to better levergage existing security tools.
- Leverage CrowdStrike Fusion SOAR workflows to automate routine containment notifications and response actions.
- Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules as platform needs evolve.
- 4. Stakeholder Enablement Training & Vendor Management
- Translate complex technical threat data into actionable guidance for agency IT administrators and executive leadership.
- Develop dashboards using the CrowdStrike API to collect daily vulnerability data and other key metrics providing clear and actionable visibility into the enterprise environment.
- Develop standardized operating procedures (SOPs) deployment guides and platform hardening specifications for state agency IT partners.
- Serve as the primary technical point of contact with CrowdStrike engineering and technical account managers (TAMs) to drive feature requests and resolve critical bugs.
- Provide formal and informal technical mentoring and training to Tier 1/2 SOC staff.
Required Technical Experience
- Platform Mastery: 4 years of hands-on experience engineering deploying and maintaining CrowdStrike Falcon at enterprise scale (10000 endpoints).
- Tier 3 IR Capabilities: Demonstrated proficiency using CrowdStrike Real-Time Response (RTR) writing custom IOAs/IOCs and performing endpoint threat hunting.
- OS & Scripting: Strong knowledge of Windows Linux and macOS internals along with scripting capabilities (PowerShell Python Bash) for automated remediation and API integration.
- Security Ecosystems: Solid grasp of network security (firewalls IDS/IPS) Identity & Access Management (AD/Entra ID) patch management vulnerability assessments and MITRE ATT&CK framework mapping.
Required Certifications (Must hold at least one active certification)
- CrowdStrike Specific (Highly Preferred):
- CrowdStrike Certified Falcon Administrator (CCFA)
- CrowdStrike Certified Falcon Responder (CCFR)
- CrowdStrike Certified Falcon Hunter (CCFH)
- Industry Certifications:
- CISSP GCFA GCIH GSEC CISA or equivalent advanced security credential.
Professional & Soft Skills
- Integrity & Ethics: Unwavering commitment to confidentiality integrity and compliance standards necessary for state government operations.
- Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly.
- Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments agency-specific constraints and conflicting operational priorities.
- Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse supportive and team-oriented working environment.
Preferred Qualifications
- Prior experience in state/local government (SLTT) higher education or large-scale multi-tenant enterprise environments.
- Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g. Splunk Microsoft Sentinel Palo Alto Cortex).
- Familiarity with federal/state compliance frameworks (NIST SP 800-53 CJIS HIPAA IRS Pub 1075).
| Required / Desired |
|
|
| Industry Certifications: CISSP GCFA GCIH GSEC CISA or equivalent advanced security credential. | Required |
|
|
| Required Certifications (must hold at least one active CrowdStrike specific certification): | Required |
|
|
| CrowdStrike Certified Falcon Administrator (CCFA); CrowdStrike Certified Falcon Responder (CCFR); CrowdStrike Certified Falcon Hunter (CCFH) | Required |
|
|
| Platform Mastery: 4 years of hands-on experience engineering deploying and maintaining CrowdStrike Falcon at enterprise scale (10000 endpoints). | Required |
|
|
| Tier 3 IR Capabilities: Proficiency using CrowdStrike Real-Time Response (RTR) writing custom IOAs/IOCs and performing endpoint threat hunting | Required |
|
|
| OS & Scripting: Strong knowledge of Windows Linux and macOS internals along with scripting capabilities (PowerShell Python Bash) for automated... | Required |
|
|
| automated remediation and API integration. | Required |
|
|
| Security Ecosystems: Solid grasp of network security (firewalls IDS/IPS) Identity & Access Management (AD/Entra ID) patch management | Required |
|
|
| vulnerability assessments and MITRE ATT&CK framework mapping. | Required |
|
|
| Integrity & Ethics: Unwavering commitment to confidentiality integrity and compliance standards necessary for state government operations. | Required |
|
|
| Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly. | Required |
|
|
| Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments agency-specific constraints and conflicting... | Required |
|
|
| operational policies | Required |
|
|
| Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse supportive and team-oriented working environment. | Required |
|
|
| Prior experience in state/local government (SLTT) higher education or large-scale multi-tenant enterprise environments. | Highly desired |
|
|
| Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g. Splunk Microsoft Sentinel Palo Alto Cortex). | Highly desired |
|
|
| Familiarity with federal/state compliance frameworks (NIST SP 800-53 CJIS HIPAA IRS Pub 1075). | Highly desired |
|
|