Senior Tier 3 CrowdStrike Architect

 Posted 2 days ago
     
5-10 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

The Senior Tier 3 CrowdStrike Architect serves as the primary technical authority for the enterprise endpoint detection and response platform, overseeing architecture, administration, and multi-tenant federation. They are responsible for fine-tuning security policies, managing platform health, and acting as the final escalation point for complex endpoint threats and critical incidents.

This is a remote position.

Seeking a Senior Tier 3 CrowdStrike Architect who will serve as the primary technical authority for the SOI Enterprise Endpoint Detection and Response platform. The resource will be response for the overall architecture, administration, multi-tenant federation, fine-tuning, and escalation engineering of the CrowdStrike Falcon ecosystem across state agencies. Additionally:
  • Architect, implement, and maintain the state-wide CrowdStrike Falcon platform architecture across multi-tenant environments (CID hierarchy, RBAC, policy groups).
  • Oversee sensor deployment strategies, policy prevention/detection tuning, custom rule creation (IOAs/IOCs), and feature rollout schedules across diverse agency environments.
  • Manage CrowdStrike platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads. 
  • Act as the final technical escalation point for complex endpoint threats, zero-day vulnerabilities, and persistent malware identified by Tier 1/2 SOC analysts.
  • Execute advanced containment, remediation, and live forensics using Real-Time Response (RTR) and custom scripts during critical incidents.
  • Partner with SOC Analysts and Incident Response teams to refine playbooks, minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk reduction.
  • Design and support telemetry integration between CrowdStrike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds.
  • Introduce new integration ideas to better leverage existing security tools.
  • Leverage CrowdStrike Fusion SOAR workflows to automate routine containment, notifications, and response actions.
  • Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules as platform needs evolve.
  • Translate complex technical threat data into actionable guidance for agency IT administrators and executive leadership.
  • Develop dashboards using the CrowdStrike API to collect daily vulnerability data, and other key metrics, providing clear and actionable visibility into the enterprise environment.
  • Develop standardized operating procedures (SOPs), deployment guides, and platform hardening specifications for state agency IT partners.
  • Serve as the primary technical point of contact with CrowdStrike engineering and technical account managers (TAMs) to drive feature requests and resolve critical bugs.
  • Provide formal and informal technical mentoring and training to Tier 1/2 SOC staff.

Requirements

Skills
Required/Preferred
Years
Candidate Experience
Industry Certifications: CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.
Required
4

Required Certifications (must hold at least one active CrowdStrike specific certification): CrowdStrike Certified Falcon Administrator (CCFA); CrowdStrike Certified Falcon Responder (CCFR); CrowdStrike Certified Falcon Hunter (CCFH)
Required
4

Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).
Required
4

Proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting?
Required
4

Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated remediation and API integration.
Required
4

Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping.
Required
4

Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations.
Required
7

Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly.
Required
7

High analytical capability to navigate complex multi-tenant environments, agency-specific constraints, and conflicting operational policies
Required
4

Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team-oriented working environment.
Required
7

Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.
Highly desired
 
 
Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).
Highly desired
 
 
Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).
Highly desired
 
 


Benefits

Benefit Package includes: 
  • Paid Sick Time
  • Insurance for Medical, Dental, Vision and Life Available
  • 401(k) including Employer Match 
  • HSA, Short-term & Long-term Disability Available 
  • We are an EEO/Veterans/Disabled employer


Similar Jobs

See all Remote Software Development jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Architect

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified