Certified Woman & Minority Owned

Apply for this job

CrowdStrike Architect

100% Remote (Within US) 9.5 Months
Contract $65.16/hour - $70.16/hour






Accepted: .doc, .docx, .pdf, - max 20MB
Posted: Aug 18, 2026
Ref: NPILIT656

Position Overview


Remote

This position acts as the highest level of technical escalation (Tier 3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations (such as Next-Gen SIEM, threat intelligence, and automated orchestration).


The Senior Tier 3 CrowdStrike Architect serves as the primary technical authority for the client Enterprise Endpoint Detection and Response (EDR / XDR) platform. Operating within the Information Security Services (ISS) Bureau, this role is responsible for the overall architecture, administration, multi-tenant federation, fine-tuning, and escalation engineering of the CrowdStrike Falcon ecosystem across client.


1. Platform Architecture & Multi-Tenant Administration

Architect, implement, and maintain the state-wide CrowdStrike Falcon platform architecture across multi-tenant environments (CID hierarchy, RBAC, policy groups).
Oversee sensor deployment strategies, policy prevention/detection tuning, custom rule creation (IOAs/IOCs), and feature rollout schedules across diverse client environments.
Manage CrowdStrike platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads.

2. Tier 3 Incident Escalation & Response Engineering

Act as the final technical escalation point for complex endpoint threats, zero-day vulnerabilities, and persistent malware identified by Tier 1/2 client analysts.
Execute advanced containment, remediation, and live forensics using Real-Time Response (RTR) and custom scripts during critical incidents.
Partner with client Analysts and Incident Response teams to refine playbooks, minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk reduction.

3. Integration, Automation & Data Pipeline

Design and support telemetry integration between CrowdStrike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds.
Introduce new integration ideas to better levergage existing security tools.
Leverage CrowdStrike Fusion SOAR workflows to automate routine containment, notifications, and response actions.
Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules as platform needs evolve.

4. Stakeholder Enablement, Training & Vendor Management

Translate complex technical threat data into actionable guidance for agency IT administrators and executive leadership.
Develop dashboards using the CrowdStrike API to collect daily vulnerability data, and other key metrics, providing clear and actionable visibility into the enterprise environment.
Develop standardized operating procedures (SOPs), deployment guides, and platform hardening specifications for client  IT partners.
Serve as the primary technical point of contact with CrowdStrike engineering and technical account managers (TAMs) to drive feature requests and resolve critical bugs.
Provide formal and informal technical mentoring and training to Tier 1/2 client staff.

Required Technical Experience

Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).
Tier 3 IR Capabilities: Demonstrated proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting.
OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated remediation and API integration.
Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping.

Required Certifications (Must hold at least one active certification)
CrowdStrike Specific (Highly Preferred):
CrowdStrike Certified Falcon Administrator (CCFA)
CrowdStrike Certified Falcon Responder (CCFR)
CrowdStrike Certified Falcon Hunter (CCFH)

Industry Certifications:
CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.

Professional & Soft Skills

Integrity & Ethics: Unwavering commitment to confidentiality, integrity, and compliance standards necessary for client government operations.
Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and client  leaders clearly.
Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments, client -specific constraints, and conflicting operational priorities.
Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team-oriented working environment.

Preferred Qualifications

Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.
Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).
Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).


Notes:
Remote


VIVA is an equal opportunity employer. All qualified applicants have an equal opportunity for placement, and all employees have an equal opportunity to develop on the job. This means that VIVA will not discriminate against any employee or qualified applicant on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status

Trusted by 100+ Fortune 500 Companies

Competitive Benefits


Your well-being Matters

Health & Future Fully Covered

At VIVA, employee well-being is paramount. Our comprehensive benefits package ensures your health, financial security, and quality of life are always prioritized.

Health Insurance

VIVA provides employees access to a comprehensive group health insurance plan (Medical, Dental, Vision, Basic Life, Term Life, and Accidental Death) through our flexible PPO plan-allowing you the freedom to choose healthcare providers.

401(k) Retirement Planning

Plan securely for your future with automatic payroll deductions into a tax-advantaged 401(k) retirement plan, including employer-matching contributions for eligible employees.

Performance Bonuses & Referrals

Earn performance-based bonuses and generous referral incentives of up to $500 when recommending talented candidates who become part of the VIVA family.

Biweekly Direct Deposit

Enjoy timely and convenient payroll with biweekly direct deposit to your chosen financial institution. Biweekly Direct Deposit

VIVA Perks Program

Access exclusive employee discounts and savings on electronics, travel, groceries, apparel, and more through our dedicated VIVA Perks Program.

Join VIVA and Grow
VIVA is faster, easier and you still have complete control

CrowdStrike Architect


Reference Number: NPILIT656
Empty
Click + to add content