> Markdown version of [/jobs/ext/2413166-telecommute-senior-tier-3-croudstrike-architect](https://www.wearedevelopers.com/jobs/ext/2413166-telecommute-senior-tier-3-croudstrike-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # TELECOMMUTE Senior Tier 3 CroudStrike Architect - **Company:** KONNECTINGTREE INC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Apple Mac Systems, ARM Architecture, Bash Shell, Cloud Computing Security, Linux, Identity and Access Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Network Security, Automation of Marketing, Windows PowerShell, Role-Based Access Control, Security Information and Event Management, Systems Integration, Scripting, Mitre Att&ck, Mttr, Firewalls (Computer Science), Falcon Platform, Deployment Automation, Cybercrime, Palo Alto Networks, Patch Management, Microsoft Sentinel, 3-tier Architectures, Splunk, Data Pipelines, Vulnerability Analysis - **Published:** August 18, 2026 - **Apply:** https://www.dice.com/job-detail/0e093b63-cfd3-4c23-88e5-f962460bd1f8 ## About the Role Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints). Tier 3 IR Capabilities: Demonstrated proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting. OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated remediation and API integration. Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping. Required Certifications (Must hold at least one active certification) CrowdStrike Specific (Highly Preferred): CrowdStrike Certified Falcon Administrator (CCFA) CrowdStrike Certified Falcon Responder (CCFR) CrowdStrike Certified Falcon Hunter (CCFH) Industry Certifications: CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential. Professional & Soft Skills Integrity & Ethics: Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations. Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly. Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments, agency-specific constraints, and conflicting operational priorities. Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team-oriented working environment. Preferred Qualifications Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments. Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex). Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075). ## Description Architect, implement, and maintain the state-wide CrowdStrike Falcon platform architecture across multi-tenant environments (CID hierarchy, RBAC, policy groups). Oversee sensor deployment strategies, policy prevention/detection tuning, custom rule creation (IOAs/IOCs), and feature rollout schedules across diverse agency environments. Manage CrowdStrike platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads. 2. Tier 3 Incident Escalation & Response Engineering Act as the final technical escalation point for complex endpoint threats, zero-day vulnerabilities, and persistent malware identified by Tier 1/2 SOC analysts. Execute advanced containment, remediation, and live forensics using Real-Time Response (RTR) and custom scripts during critical incidents. Partner with SOC Analysts and Incident Response teams to refine playbooks, minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk reduction. 3. Integration, Automation & Data Pipeline Design and support telemetry integration between CrowdStrike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds. Introduce new integration ideas to better levergage existing security tools. Leverage CrowdStrike Fusion SOAR workflows to automate routine containment, notifications, and response actions. Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules as platform needs evolve. 4. Stakeholder Enablement, Training & Vendor Management Translate complex technical threat data into actionable guidance for agency IT administrators and executive leadership. Develop dashboards using the CrowdStrike API to collect daily vulnerability data, and other key metrics, providing clear and actionable visibility into the enterprise environment. Develop standardized operating procedures (SOPs), deployment guides, and platform hardening specifications for state agency IT partners. Serve as the primary technical point of contact with CrowdStrike engineering and technical account managers (TAMs) to drive feature requests and resolve critical bugs. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)