Senior CrowdStrike Falcon Architect

Remote • Posted 1 hour ago • Updated 1 hour ago
Contract W2
Contract Independent
Contract Corp To Corp
12 Months
No Travel Required
Remote
Depends on Experience
Fitment

Dice Job Match Score™

📊 Calculating match score...

Job Details

Skills

  • Falcon Engineer
  • RTR
  • CrowdStrike
  • Splunk
  • Palo Alto

Summary

Senior CrowdStrike Falcon Engineer / Architect

We are looking for a senior CrowdStrike Falcon engineer / architect to serve as the Tier 3 technical authority for a large enterprise CrowdStrike Falcon EDR/XDR environment.

This is a hands-on CrowdStrike engineering and architecture position, not a general SOC analyst role. The person in this role will own advanced Falcon administration, enterprise architecture, endpoint security policy, detection tuning, threat hunting, incident response, Real-Time Response (RTR), IOA/IOC development, Falcon API integrations, automation, and complex Tier 3 troubleshooting.

The environment includes 10,000+ endpoints across multiple agency environments, so experience managing CrowdStrike Falcon at enterprise scale is critical.

What You Will Work On

CrowdStrike Falcon Architecture & Engineering

  • Architect, administer, and maintain the enterprise CrowdStrike Falcon platform across multiple environments.
  • Manage Falcon CID hierarchy, RBAC, host groups, security policies, sensor deployment, and prevention and detection controls.
  • Develop and tune CrowdStrike prevention, detection, and response policies.
  • Create and maintain custom IOAs and IOCs.
  • Manage CrowdStrike sensor deployment, upgrades, agent health, and troubleshooting.
  • Support Falcon across Windows, Linux, macOS, and virtualized workloads.
  • Evaluate new CrowdStrike capabilities and determine how they should be deployed across the enterprise.

Tier 3 Incident Response & Threat Hunting

  • Act as the highest-level technical escalation point for complex endpoint security incidents.
  • Investigate advanced malware, persistent threats, zero-day vulnerabilities, and sophisticated endpoint activity.
  • Perform advanced threat hunting and endpoint investigation using CrowdStrike Falcon.
  • Use CrowdStrike Real-Time Response (RTR) for live investigation, containment, remediation, and forensic activities.
  • Develop scripts and response actions for complex endpoint incidents.
  • Analyze endpoint activity and map adversary behavior to MITRE ATT&CK.
  • Partner with SOC and Incident Response teams to improve detection and response processes.

Integration, API & Security Automation

  • Integrate CrowdStrike Falcon with enterprise SIEM, SOAR, threat intelligence, network security, and identity security platforms.
  • Develop and support CrowdStrike Falcon API integrations.
  • Build security automation using PowerShell, Python, and Bash.
  • Develop automated response workflows using CrowdStrike Fusion.
  • Support integrations with platforms such as Splunk, Microsoft Sentinel, Palo Alto Cortex, and other security technologies.
  • Identify opportunities to automate endpoint investigation, containment, remediation, reporting, and operational tasks.

Enterprise Platform Management

  • Monitor overall CrowdStrike platform health, endpoint coverage, sensor status, and policy effectiveness.
  • Develop dashboards and reporting through the CrowdStrike API for vulnerabilities, detections, endpoint status, and security metrics.
  • Create technical standards, deployment procedures, SOPs, and platform hardening documentation.
  • Work directly with CrowdStrike Engineering and Technical Account Managers on complex product issues, bugs, and technical escalations.
  • Provide technical guidance and mentoring to Tier 1/Tier 2 security teams.

Required Experience

CrowdStrike Falcon – Required

  • 4+ years of hands-on CrowdStrike Falcon engineering and administration experience.
  • Experience designing, deploying, maintaining, and troubleshooting CrowdStrike Falcon EDR/XDR in a large enterprise environment.
  • Experience supporting 10,000+ endpoints or a comparable enterprise-scale environment.
  • Strong hands-on experience with:
    • CrowdStrike Falcon administration
    • Falcon EDR/XDR
    • Real-Time Response (RTR)
    • IOA / IOC development
    • Detection and prevention policy tuning
    • Host groups
    • RBAC
    • Sensor deployment
    • Endpoint troubleshooting
    • Threat hunting

Tier 3 Security / Incident Response

  • 4+ years of experience in advanced endpoint security, incident response, threat hunting, detection engineering, or Tier 3 security operations.
  • Demonstrated ability to investigate and remediate complex endpoint threats.
  • Strong understanding of MITRE ATT&CK and modern endpoint attack techniques.

Operating Systems & Automation

Strong working knowledge of:

  • Windows
  • Linux
  • macOS

Hands-on scripting experience with PowerShell, Python, and/or Bash, particularly for endpoint remediation, security automation, and API integration.

Enterprise Security Technologies

Experience working with several of the following:

  • SIEM / SOAR
  • Network security
  • Firewalls
  • IDS/IPS
  • Identity and Access Management
  • Active Directory
  • Microsoft Entra ID
  • Vulnerability management
  • Patch management
  • Threat intelligence
  • Endpoint security

Certification Requirement

At least one active CrowdStrike certification is required:

  • CCFA – CrowdStrike Certified Falcon Administrator
  • CCFR – CrowdStrike Certified Falcon Responder
  • CCFH – CrowdStrike Certified Falcon Hunter

Additional security certifications such as CISSP, GCFA, GCIH, GSEC, or CISA are highly desirable.

Preferred Experience

  • CrowdStrike experience in a state/local government, higher education, or large enterprise environment.
  • Multi-tenant CrowdStrike Falcon architecture and administration.
  • CrowdStrike Falcon API development/integration.
  • CrowdStrike Fusion automation.
  • SIEM/SOAR integrations with Splunk, Microsoft Sentinel, Palo Alto Cortex, or similar platforms.
  • Familiarity with NIST SP 800-53, CJIS, HIPAA, or IRS Publication 1075.
  • Experience with ITDR or CSPM technologies.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10504943
  • Position Id: 4138-12901-1787073194
  • Posted 1 hour ago

Company Info

About DKMRBH Inc.

Do Know Me Right Before Hiring knows the value of transparency & constant communication between the client & the project resources to build a trustworthy foundation of our name. A commitment made is a commitment honored. Our clients experience the commitment during our intensive project delivery engagements. We believe in building a reputation that will serve as a positive reflection on our clients & candidates. We measure our success by the strength of the relationships we cultivate.



At DKMRBH Inc. we understand the importance of work to our clients & aspire to honor all of our commitments to them. Deep technical & functional expertise in every aspect of the Enterprise management: Our senior management team brings a wealth of experience in leading companies, delivering a consistent record of positive results. This stems directly from our devotion to sustain, mutually benefit & build long-term relationships with our clients,

Contact the job poster
BK

Bisma Kahn

Recruiter @ DKMRBH Inc.
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs