Remote CrowdStrike Falcon Engineer

Moines, IA, US • Posted 1 hour ago • Updated 1 hour ago
Full Time
Part Time
On-site
Company Branding Image
Fitment

Dice Job Match Score™

🫥 Flibbertigibetting...

Job Details

Skills

  • Industry Certifications: CISSP
  • GCFA
  • GCIH
  • GSEC
  • CISA
  • or equivalent advanced security credential.
  • Required Certifications (must hold at least one active CrowdStrike specific certification):
  • CrowdStrike Certified Falcon Administrator (CCFA); CrowdStrike Certified Falcon Responder (CCFR); CrowdStrike Certified Falcon Hunter (CCFH)
  • Platform Mastery: 4+ years of hands-on experience engineering
  • deploying
  • and maintaining CrowdStrike Falcon at enterprise scale (10
  • 000+ endpoints).
  • Tier 3 IR Capabilities: Proficiency using CrowdStrike Real-Time Response (RTR)
  • writing custom IOAs/IOCs
  • and performing endpoint threat hunting
  • OS & Scripting: Strong knowledge of Windows
  • Linux
  • and macOS internals
  • along with scripting capabilities (PowerShell
  • Python
  • Bash) for automated...
  • automated remediation and API integration.
  • Security Ecosystems: Solid grasp of network security (firewalls
  • IDS/IPS)
  • Identity & Access Management (AD/Entra ID)
  • patch management
  • vulnerability assessments
  • and MITRE ATT&CK framework mapping.
  • Integrity & Ethics: Unwavering commitment to confidentiality
  • integrity
  • and compliance standards necessary for state government operations.
  • Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly.
  • Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments
  • agency-specific constraints
  • and conflicting...
  • operational policies
  • Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse
  • supportive
  • and team-oriented working environment.
  • Prior experience in state/local government (SLTT)
  • higher education
  • or large-scale multi-tenant enterprise environments.
  • Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g.
  • Splunk
  • Microsoft Sentinel
  • Palo Alto Cortex).
  • Familiarity with federal/state compliance frameworks (NIST SP 800-53
  • CJIS
  • HIPAA
  • IRS Pub 1075).

Summary

Engagement Type

Contract
Short Description

This position acts as the highest

level of technical escalation (Tier 3) for endpoint incidents, advanced threat

hunting, platform troubleshooting, and complex integrations (such as Next-Gen

SIEM, threat intelligence, and automated orchestration).
Complete Description

The Senior Tier 3 CrowdStrike

Architect serves as the primary technical authority for the State of Iowa s

Enterprise Endpoint Detection and Response (EDR / XDR) platform. Operating

within the Information Security Services (ISS) Bureau, this role is responsible

for the overall architecture, administration, multi-tenant federation,

fine-tuning, and escalation engineering of the CrowdStrike Falcon ecosystem

across state agencies.



This position acts as the highest level of technical escalation (Tier 3) for

endpoint incidents, advanced threat hunting, platform troubleshooting, and

complex integrations (such as Next-Gen SIEM, threat intelligence, and automated

orchestration).





1. Platform Architecture &

Multi-Tenant Administration





Architect,

implement, and maintain the state-wide CrowdStrike Falcon platform architecture

across multi-tenant environments (CID hierarchy, RBAC, policy groups).





Oversee

sensor deployment strategies, policy prevention/detection tuning, custom rule creation

(IOAs/IOCs), and feature rollout schedules across diverse agency environments.





Manage

CrowdStrike platform health, agent updates, host group management, and agent

troubleshooting across Windows, macOS, Linux, and virtualized workloads.





2. Tier 3 Incident Escalation

& Response Engineering





Act

as the final technical escalation point for complex endpoint threats, zero-day

vulnerabilities, and persistent malware identified by Tier 1/2 SOC analysts.





Execute

advanced containment, remediation, and live forensics using Real-Time Response

(RTR) and custom scripts during critical incidents.





Partner

with SOC Analysts and Incident Response teams to refine playbooks, minimize

Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk

reduction.





3. Integration, Automation &

Data Pipeline





Design

and support telemetry integration between CrowdStrike Falcon, central SIEM/SOAR

platforms, network defenses, and threat intelligence feeds.





Introduce

new integration ideas to better levergage existing security tools.





Leverage

CrowdStrike Fusion SOAR workflows to automate routine containment,

notifications, and response actions.





Align

endpoint security strategies with Identity Threat Detection and Response (ITDR)

and Cloud Security Posture Management (CSPM) modules as platform needs evolve.





4. Stakeholder Enablement,

Training & Vendor Management





Translate

complex technical threat data into actionable guidance for agency IT administrators

and executive leadership.





Develop

dashboards using the CrowdStrike API to collect daily vulnerability data, and

other key metrics, providing clear and actionable visibility into the

enterprise environment.





Develop

standardized operating procedures (SOPs), deployment guides, and platform

hardening specifications for state agency IT partners.





Serve

as the primary technical point of contact with CrowdStrike engineering and technical

account managers (TAMs) to drive feature requests and resolve critical bugs.





Provide

formal and informal technical mentoring and training to Tier 1/2 SOC staff.

















Required Technical Experience





Platform

Mastery: 4+ years of hands-on experience engineering, deploying, and

maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).





Tier

3 IR Capabilities: Demonstrated proficiency using CrowdStrike Real-Time

Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat

hunting.





OS

& Scripting: Strong knowledge of Windows, Linux, and macOS internals, along

with scripting capabilities (PowerShell, Python, Bash) for automated

remediation and API integration.





Security

Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity

& Access Management (AD/Entra ID), patch management, vulnerability

assessments, and MITRE ATT&CK framework mapping.





Required Certifications (Must

hold at least one active certification)





CrowdStrike

Specific (Highly Preferred):





CrowdStrike Certified Falcon

Administrator (CCFA)





CrowdStrike Certified Falcon

Responder (CCFR)





CrowdStrike Certified Falcon Hunter

(CCFH)





Industry

Certifications:





CISSP, GCFA, GCIH, GSEC, CISA, or

equivalent advanced security credential.





Professional & Soft Skills





Integrity

& Ethics: Unwavering commitment to confidentiality, integrity, and compliance

standards necessary for state government operations.





Communication

& Translation: Proven ability to explain technical risk to non-technical

stakeholders and state agency leaders clearly.





Complex

Problem Solving: High analytical capability to navigate complex multi-tenant

environments, agency-specific constraints, and conflicting operational

priorities.





Collaboration

& Inclusion: Strong interpersonal skills with a commitment to fostering a diverse,

supportive, and team-oriented working environment.





Preferred Qualifications





Prior

experience in state/local government (SLTT), higher education, or large-scale

multi-tenant enterprise environments.





Experience

integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs

(e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).





Familiarity

with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub

1075).





).
Required/Desired Skills

Skill Required/Desired Amount of Experience
Industry Certifications: CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential. Required 4.0 Years
Required Certifications (must hold at least one active CrowdStrike specific certification): Required 4.0 Years
CrowdStrike Certified Falcon Administrator (CCFA); CrowdStrike Certified Falcon Responder (CCFR); CrowdStrike Certified Falcon Hunter (CCFH) Required
Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints). Required 4.0 Years
Tier 3 IR Capabilities: Proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting Required 4.0 Years
OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated... Required
automated remediation and API integration. Required 4.0 Years
Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, Required
vulnerability assessments, and MITRE ATT&CK framework mapping. Required 4.0 Years
Integrity & Ethics: Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations. Required 7.0 Years
Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly. Required 7.0 Years
Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments, agency-specific constraints, and conflicting... Required
operational policies Required 7.0 Years
Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team-oriented working environment. Required 7.0 Years
Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments. Highly desired
Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex). Highly desired
Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075). Highly desired
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10195834
  • Position Id: OOJ - 6387-6160-1787059727
  • Posted 1 hour ago

Company Info

About Mahantech Corporation

For over twenty years, major corporations and organizations across the U.S. have relied upon Mahantech Corp. to supply top I.T. consultants to both the private and public sectors with a focus on efficiency, quality, and service.

The modern world runs on Information Technology. As a new graduate in the field of Information Technology, you possess the most up-to-date knowledge and skills; traits that are in high demand for companies looking to give themselves an edge in the ever-more-competitive world of business.

Now is the time to turn your degree into a career. Mahantech Corp. can provide the job opportunities you need to set you on the path to lifelong career success.

Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs