
Senior Crowd Strike Architect
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Iowa.
• Design, implement, and sustain the statewide CrowdStrike Falcon architecture within multi-tenant settings.
• Manage sensor deployment, fine-tuning of prevention/detection, custom IOA/IOC rules, feature rollouts, platform health, agent updates, host groups, and troubleshooting.
• Act as the final Tier 3 escalation contact for intricate endpoint threats, zero-day vulnerabilities, and persistent malware.
• Conduct advanced containment, remediation, and live forensics utilizing Real-Time Response and tailored scripts.
• Collaborate with SOC Analysts and Incident Response teams to enhance playbooks and minimize MTTD and MTTR.
• Design and facilitate telemetry integrations between CrowdStrike Falcon, SIEM/SOAR platforms, network defenses, and threat intelligence feeds.
• Utilize CrowdStrike Fusion SOAR workflows to automate containment, notifications, and response measures.
• Align endpoint security initiatives with ITDR and CSPM modules.
• Convert technical threat information into actionable insights for agency IT administrators and executive leadership.
• Create CrowdStrike API dashboards for daily vulnerability data and enterprise metrics.
• Develop SOPs, deployment guides, and platform hardening specifications.
• Serve as the technical liaison with CrowdStrike engineering and Technical Account Managers (TAMs).
• Mentor and train Tier 1/2 SOC personnel.
• Minimum of 4 years of practical experience in engineering, deploying, and maintaining CrowdStrike Falcon at an enterprise scale (10,000+ endpoints).
• Proven expertise with CrowdStrike Real-Time Response (RTR), custom IOAs/IOCs, and endpoint threat hunting.
• Strong understanding of Windows, Linux, and macOS internals.
• Proficiency in scripting with PowerShell, Python, and Bash for automated remediation and API integration.
• Familiarity with network security, including firewalls and IDS/IPS.
• Knowledge of Identity & Access Management, particularly AD/Entra ID.
• Awareness of patch management, vulnerability assessments, and MITRE ATT&CK mapping.
• Must possess at least one active certification: CCFA, CCFR, CCFH, CISSP, GCFA, GCIH, GSEC, CISA, or an equivalent advanced security credential.
• Capability to articulate technical risks clearly to non-technical stakeholders and state agency leaders.
• High analytical skills for managing complex multi-tenant environments and balancing conflicting priorities.
• Strong interpersonal skills and a commitment to fostering a diverse, supportive, team-oriented atmosphere.
• Must reside in Des Moines, IA.
• Availability for interviews on August 24, 25, and 26 is required.
• Preferred: experience within state/local government, higher education, or large-scale multi-tenant enterprise settings.
• Preferred: experience integrating CrowdStrike Falcon APIs with automation platforms or SIEMs such as Splunk, Microsoft Sentinel, or Palo Alto Cortex.
• Preferred: familiarity with NIST SP 800-53, CJIS, HIPAA, or IRS Pub 1075.
• Comprehensive health, dental, and vision insurance.
• Retirement savings plans with employer matching.
• Generous paid time off and holiday schedule.
• Opportunities for professional development and continuing education.
• Flexible work arrangements and support for work-life balance.
Get handpicked remote jobs straight to your inbox weekly.