1

Crowdstrike Falcon Administrator Jobs (NOW HIRING)

Sr. CrowdStrike Engineer

Washington, DC · On-site

$118K - $162K/yr

CrowdStrike Certified Falcon Administrator (CCFA) * CrowdStrike Certified SIEM Engineer (CCSE) * CrowdStrike Certified Cloud Specialist (CCCS) * Equivalent cybersecurity or endpoint security ...

Lead CrowdStrike Falcon operations and SIEM strategy, including threat detection and response * Oversee SOC strategy and vendor partnerships Collaboration & Productivity Platforms * Administer Slack ...

CrowdStrike Falcon deployment across all endpoints * Implementation of a next-generation SIEM ... Administer Slack Enterprise Grid , including workspace structure, integrations, and retention ...

next page

Showing results 1-20

Crowdstrike Falcon Administrator information

What is the difference between Crowdstrike Falcon Administrator vs Crowdstrike Falcon Engineer?

AspectCrowdstrike Falcon AdministratorCrowdstrike Falcon Engineer
CertificationsTypically requires Crowdstrike certifications and cybersecurity fundamentalsOften requires advanced certifications like CISSP, CEH, or vendor-specific engineering credentials
Work EnvironmentFocuses on managing and maintaining Falcon platform, troubleshooting, and user supportInvolves designing, implementing, and optimizing Falcon security solutions, often in a technical engineering capacity
Employer & Industry UsageUsed across cybersecurity teams in various industries for endpoint security managementUsed by security engineering teams for deployment and integration of Falcon in complex environments

The Crowdstrike Falcon Administrator primarily manages and supports the Falcon platform, ensuring endpoint security and user support. In contrast, the Crowdstrike Falcon Engineer focuses on deploying, customizing, and optimizing Falcon solutions within an organization's security infrastructure. Both roles require cybersecurity knowledge, but the engineer role typically demands more technical and engineering expertise.

What are some common challenges faced by Crowdstrike Falcon Administrators when managing endpoint security across large organizations?

Crowdstrike Falcon Administrators often encounter challenges related to scaling the platform across numerous endpoints and ensuring consistent policy enforcement. Managing frequent updates, handling false positives, and integrating Falcon with other security tools can also be complex. Additionally, collaborating with IT and incident response teams is crucial to quickly address threats and maintain compliance. Staying updated on the latest threats and Crowdstrike features helps administrators proactively protect their organization's digital assets.

What is the 1 10 60 rule in CrowdStrike?

The 1-10-60 rule in CrowdStrike refers to the recommended response times for security incidents: 1 minute to detect, 10 minutes to investigate, and 60 minutes to contain or remediate. As a CrowdStrike Falcon Administrator, understanding this rule helps ensure timely threat response and effective endpoint security management.

Do crowdstrikes pay well?

CrowdStrike Falcon Administrators typically earn competitive salaries that vary based on experience, location, and certifications. Entry-level roles may start around $70,000 annually, while experienced professionals can earn over $120,000, especially with specialized skills in endpoint security and threat detection.

What is the salary of admin in CrowdStrike?

The salary of a CrowdStrike Falcon Administrator typically ranges from $70,000 to $120,000 annually, depending on experience, location, and certifications. Entry-level positions may start lower, while experienced administrators with specialized skills can earn higher salaries. Compensation also varies based on the complexity of the environment and organizational size.

What are Crowdstrike Falcon Administrators?

Crowdstrike Falcon Administrators are IT professionals responsible for managing, configuring, and maintaining the Crowdstrike Falcon cybersecurity platform within an organization. They handle tasks such as deploying endpoint protection agents, monitoring security alerts, responding to incidents, and ensuring that security policies are properly enforced. Administrators also work to optimize the platform’s settings, manage user permissions, and generate security reports to keep the organization’s systems secure. Their expertise helps protect against cyber threats and ensures compliance with security standards.

How hard is it to get hired at CrowdStrike?

Getting hired as a CrowdStrike Falcon Administrator typically requires relevant experience with endpoint security, familiarity with the Falcon platform, and often certifications such as CompTIA Security+ or CISSP. The hiring process involves technical interviews and assessments to evaluate cybersecurity knowledge and troubleshooting skills, making it competitive for qualified candidates.

What are the key skills and qualifications needed to thrive as a Crowdstrike Falcon Administrator, and why are they important?

To thrive as a Crowdstrike Falcon Administrator, you need a strong background in cybersecurity, endpoint protection, and enterprise IT systems, often supported by relevant degrees or certifications like CompTIA Security+ or CISSP. Familiarity with Crowdstrike Falcon's cloud-based console, EDR tools, and scripting languages such as PowerShell is typically required. Analytical thinking, effective communication, and problem-solving skills help administrators respond swiftly to threats and collaborate with IT teams. These competencies ensure the effective deployment, management, and optimization of Crowdstrike solutions to protect organizational assets from cyber threats.
Infographic showing various Crowdstrike Falcon Administrator job openings in the United States as of June 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution.

Full-time

Posted 12 days ago


Job description

Position: CrowdStrike Engineer
Location: Remote
Position Type: Fulltime
Key Roles and Responsibilities
Identity Threat Monitoring: Monitor and analyze user behaviour, Active Directory (AD) activity, and authentication logs to detect anomalies, such as credential theft or lateral movement.
Implementation & Configuration: Deploy and configure CrowdStrike Falcon Identity Protection modules across hybrid and cloud environments (Entra ID, Okta).
Incident Response: Investigate identity-based attacks (e.g., Kerb roasting, Pass-the-Hash, Golden Ticket) and execute containment actions.
Policy & Posture Management: Establish and maintain security policies, strengthen identity security posture, and remove unnecessary standing privileges.
Automation: Develop and build Falcon Fusion SOAR playbooks to automate responses to identity threats.
Collaboration: Work with security operations (SOC), IAM teams, and stakeholders to improve overall security, often acting as a bridge between IT and security teams.
CrowdStrike
Required Skills and Expertise
CrowdStrike Platform: Strong hands-on experience with CrowdStrike Falcon Identity Protection (or similar ITDR tools).
Identity Infrastructure: Deep understanding of Active Directory (AD) and cloud identity providers (Entra ID/Azure AD, Okta).
Threat Intelligence: Knowledge of adversary tactics, techniques, and procedures (TTPs) related to identity attacks.
Security Frameworks: Familiarity with MITRE ATT&CK framework, particularly techniques covering lateral movement and credential access.
Scripting & Automation: Experience with Python or PowerShell to streamline detection and remediation processes.
Analytical Skills: Ability to analyze large sets of data, logs, and telemetry to identify indicators of compromise (IoCs).
CrowdStrike
Experience and Qualifications
  1. Years of Experience: Typically, 6+ years of experience in cybersecurity operations, specializing in identity, EDR, or threat hunting.
  2. Education: Bachelor's degree in computer science, Information Security, or a related field.
  3. Certifications (Preferred): CrowdStrike Certified Falcon Administrator (CCFA), CISSP, or relevant SIEM/Identity certifications.