TELECOMMUTE CroudStrike Architect
Stellar Professionals
United States
15 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source
Tech stack
Microsoft Windows
Active Directory
Application Programming Interfaces (APIs)
Apple Mac Systems
Computing Platforms
ARM Architecture
Bash Shell
Linux
Python (Programming Language)
Network Security
Windows PowerShell
Role-Based Access Control
+6 more
Security Information and Event Management
Systems Integration
Scripting
Cybercrime
3-tier Architectures
Splunk
Job description
Serve as the primary technical authority and highest escalation tier (Tier 3) for an enterprise CrowdStrike Falcon (EDR/XDR) ecosystem. This role focuses on platform architecture, advanced threat hunting, incident containment, and complex security tool integrations., * Platform Architecture: Architect and manage multi-tenant CrowdStrike environments (CID hierarchy, RBAC, policy groups, host health) across Windows, Linux, and macOS.
- Tier 3 Incident Escalation: Lead containment, forensics, and live response via Real-Time Response (RTR); create custom IOAs/IOCs.
- Integrations & Automation: Connect Falcon telemetry with SIEM/SOAR platforms (Splunk, Sentinel, Cortex) and automate playbooks via CrowdStrike Fusion SOAR.
- Dashboards & APIs: Build custom dashboards using CrowdStrike APIs to report vulnerability data and critical operational metrics.
Requirements
- CrowdStrike Platform Mastery: 4+ years engineering and managing Falcon at scale (10,000+ endpoints).
- Incident Response & Forensics: Real-Time Response (RTR), threat hunting, and custom rule creation (IOAs/IOCs).
- Scripting: PowerShell, Python, or Bash for remediation and API integration.
- Ecosystems & Frameworks: Active Directory / Entra ID, Network Security, and MITRE ATT&CK mapping.
Required Certifications:
- Must hold at least ONE active CrowdStrike Certification: CCFA, CCFR, or CCFH.
- Must hold an active Industry Certification: CISSP, GCFA, GCIH, GSEC, or CISA.
Preferred Experience:
- State/Local Government (SLTT) or enterprise multi-tenant environments.
- Compliance frameworks: NIST SP 800-53, CJIS, HIPAA, or IRS Pub 1075.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
CH
Chris Heilmann
almost 2 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
7 months ago
CS
Christina Schaireiter
Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence
3 months ago
CH
Chris Heilmann
Dev Digest 138 - Are you secure about this?
almost 2 years ago
CS
Christina Schaireiter
Why Attend a Developer Event in 2026?
7 months ago