Role: CrowdStrike Architect
Location: Remote
Duration: 9 Months Contract with possibility of extensions
Job Overview
IRG Clients is seeking a Senior Tier 3 CrowdStrike Architect to serve as the technical authority for an enterprise-wide CrowdStrike Falcon EDR/XDR platform. This role will lead platform architecture, administration, threat hunting, advanced incident response, troubleshooting, automation, and security integrations across a large multi-tenant environment.
Key Responsibilities
- Design, implement, and maintain CrowdStrike Falcon architecture across multiple tenants, agencies, and environments.
- Manage CrowdStrike policies, RBAC, host groups, sensors, prevention/detection rules, and platform updates.
- Provide Tier 3 technical support for complex endpoint security incidents, malware, zero-day threats, and advanced vulnerabilities.
- Perform advanced threat hunting, endpoint investigation, containment, and remediation using CrowdStrike Real-Time Response (RTR).
- Develop and manage custom IOCs/IOAs and security detection rules.
- Integrate CrowdStrike with SIEM, SOAR, threat intelligence, network security, and other security platforms.
- Develop automation using CrowdStrike Fusion, APIs, PowerShell, Python, and Bash to improve incident response and remediation.
- Create dashboards and reports using CrowdStrike APIs to provide visibility into vulnerabilities, endpoint health, and security metrics.
- Support endpoint environments across Windows, Linux, macOS, and virtualized systems.
- Develop SOPs, deployment guides, security standards, and platform hardening procedures.
- Provide technical guidance and training to Tier 1/Tier 2 SOC teams and agency IT staff.
- Work with CrowdStrike engineering and technical account teams to resolve complex issues and improve platform capabilities.
- Translate complex security risks and technical findings into clear recommendations for technical and executive stakeholders.
Required Qualifications
- 4+ years of hands-on enterprise experience with CrowdStrike Falcon, preferably supporting 10,000+ endpoints.
- 4+ years of experience with Tier 3 incident response, threat hunting, RTR, and custom IOA/IOC development.
- Strong knowledge of Windows, Linux, and macOS security and internals.
- Strong scripting experience with PowerShell, Python, and/or Bash.
- Experience with CrowdStrike APIs, SIEM/SOAR integrations, and security automation.
- Strong understanding of firewalls, IDS/IPS, Active Directory/Entra ID, vulnerability management, patch management, and MITRE ATT&CK.
- Strong communication, analytical, troubleshooting, and problem-solving skills.
- Ability to explain complex cybersecurity risks to both technical and non-technical stakeholders.
Required Certifications
Candidates must hold at least one active CrowdStrike certification, such as:
- CrowdStrike Certified Falcon Administrator (CCFA)
- CrowdStrike Certified Falcon Responder (CCFR)
- CrowdStrike Certified Falcon Hunter (CCFH)
Additionally, candidates must have an active advanced security certification such as CISSP, GCFA, GCIH, GSEC, CISA, or equivalent.
Preferred Qualifications
- Experience in state/local government, higher education, or large multi-tenant enterprise environments.
- Experience integrating CrowdStrike with Splunk, Microsoft Sentinel, Palo Alto Cortex, or similar security platforms.
- Knowledge of NIST SP 800-53, CJIS, HIPAA, IRS Publication 1075, or other government security frameworks.
- Experience with ITDR, CSPM, SOAR, and advanced security automation.