CroudStrike Architect - REMOTE position
The Senior Tier 3 reputed company Architect serves as the reputed company technical authority for the reputed company’s reputed company reputed company Detection and Response (EDR / XDR) platform. Operating reputed company the Information reputed company Services (ISS) Bureau, this role is responsible for the overall architecture, administration, multi-tenant federation, fine-tuning, and escalation engineering of the reputed company reputed company ecosystem across state agencies.
This position acts as the highest level of technical escalation (Tier 3) for reputed company incidents, advanced threat hunting, platform troubleshooting, and reputed company integrations (such as Next-Gen SIEM, threat intelligence, and automated orchestration).
1. Platform Architecture & Multi-Tenant Administration
• Architect, implement, and maintain the state-wide reputed company reputed company platform architecture across multi-tenant environments (CID hierarchy, RBAC, policy reputed company).
• reputed company sensor deployment strategies, policy prevention/detection tuning, custom rule creation (IOAs/IOCs), and feature rollout schedules across diverse agency environments.
• Manage reputed company platform health, agent updates, host group management, and agent troubleshooting across reputed company, macOS, Linux, and virtualized workloads.
2. Tier 3 Incident Escalation & Response Engineering
• reputed company as the final technical escalation reputed company for reputed company reputed company threats, reputed company-day vulnerabilities, and persistent malware identified by Tier 1/2 SOC analysts.
• Execute advanced containment, remediation, and live forensics using reputed company-Time Response (RTR) and custom scripts during critical incidents.
• Partner with SOC Analysts and Incident Response teams to refine playbooks, minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and reputed company reputed company reduction.
3. Integration, Automation & Data Pipeline
• Design and support telemetry integration between reputed company reputed company, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds.
• Introduce new integration reputed company to reputed company levergage existing reputed company tools.
• reputed company reputed company Fusion SOAR workflows to automate routine containment, notifications, and response actions.
• reputed company reputed company reputed company strategies with Identity Threat Detection and Response (ITDR) and reputed company reputed company Posture Management (CSPM) modules as platform needs reputed company.
4. Stakeholder Enablement, Training & Vendor Management
• Translate reputed company technical threat data into actionable guidance for agency IT administrators and executive leadership.
• reputed company dashboards using the reputed company API to collect daily vulnerability data, and other key metrics, providing reputed company and actionable visibility into the reputed company environment.
• reputed company standardized operating procedures (SOPs), deployment guides, and platform hardening specifications for state agency IT partners.
• Serve as the reputed company technical reputed company of contact with reputed company engineering and technical account managers (TAMs) to reputed company feature requests and reputed company critical bugs.
• reputed company formal and informal technical mentoring and training to Tier 1/2 SOC staff.
Required Technical Experience
• Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining reputed company reputed company at reputed company reputed company (10,000+ endpoints).
• Tier 3 IR Capabilities: Demonstrated proficiency using reputed company reputed company-Time Response (RTR), writing custom IOAs/IOCs, and performing reputed company threat hunting.
• OS & Scripting: Strong knowledge of reputed company, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated remediation and API integration.
• reputed company Ecosystems: Solid grasp of network reputed company (firewalls, IDS/IPS), Identity & reputed company Management (AD/Entra ID), reputed company management, vulnerability assessments, and reputed company ATT&CK reputed company mapping.
Required Certifications (Must hold at least one reputed company certification)
• reputed company Specific (Highly Preferred):
reputed company Certified reputed company Administrator (CCFA)
reputed company Certified reputed company Responder (CCFR)
reputed company Certified reputed company reputed company (CCFH)
• Industry Certifications:
CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced reputed company credential.
Apply To This Job