What are the responsibilities and job description for the CrowdStrike Architect position at Ubertal Inc?
Position Title: Senior CrowdStrike Architect
Location: Des Moines, IA
Engagement Type: Contract
Work Mode: Remote
Duration: ~9.5 Months (09/14/2026 – 06/30/2027)
Interview Type: Webcam or In-Person
Role OverviewServes as the primary technical authority for an enterprise-wide Endpoint Detection and Response (EDR / XDR) platform. Responsible for platform architecture, multi-tenant federation, administration, fine-tuning, and Tier 3 technical escalation engineering across enterprise environments. Acts as the highest escalation point for complex endpoint threats, threat hunting, platform troubleshooting, and security integrations.
Key ResponsibilitiesArchitect, implement, and maintain the enterprise CrowdStrike Falcon platform architecture across multi-tenant environments, managing CID hierarchy, RBAC, and policy groups.
Oversee sensor deployment strategies, policy tuning, custom IOA/IOC rule creation, and feature rollout schedules across diverse environments.
Maintain platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads.
Serve as the final Tier 3 technical escalation point for zero-day vulnerabilities, complex endpoint threats, and persistent malware.
Execute live forensics, advanced containment, and remediation using Real-Time Response (RTR) and custom scripts.
Partner with SOC Analysts and Incident Response teams to refine playbooks and improve MTTD and MTTR metrics.
Design telemetry integrations between CrowdStrike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds.
Automate routine containment, notifications, and response actions using CrowdStrike Fusion SOAR workflows.
Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules.
Develop custom dashboards using CrowdStrike APIs to report daily vulnerability metrics and enterprise security visibility.
Standardize operating procedures, deployment guides, and platform hardening specifications.
Provide technical mentoring and training to Tier 1 and Tier 2 SOC personnel while liaising with vendor technical teams.
4 years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000 endpoints).
4 years of Tier 3 Incident Response experience, including CrowdStrike RTR, writing custom IOAs/IOCs, and endpoint threat hunting.
4 years of experience with Windows, Linux, and macOS internals, alongside scripting capabilities in PowerShell, Python, or Bash for API integration and automated remediation.
4 years of experience in network security (firewalls, IDS/IPS), IAM (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping.
Must hold at least one active CrowdStrike certification (CCFA, CCFR, CCFH) or an advanced industry security credential (CISSP, GCFA, GCIH, GSEC, CISA, or equivalent).
7 years of experience demonstrating high ethics/integrity, clear technical communication to non-technical leaders, and complex problem-solving capabilities.
Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.
Hands-on experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).
Familiarity with federal and state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).
Work Schedule: Monday through Friday, 8:00 AM – 4:30 PM CST.
Work Arrangement: Fully remote position based out of Des Moines, IA.