1

Crowdstrike Falcon Administrator Jobs (NOW HIRING)

Cloud Architect

Des Moines, IA · Remote

$63.50 - $80.75/hr

CrowdStrike Certified Falcon Administrator (CCFA) * CrowdStrike Certified Falcon Responder (CCFR) * CrowdStrike Certified Falcon Hunter (CCFH) * Industry Certifications: * CISSP, GCFA, GCIH, GSEC ...

$108K - $143K/yr

... and administrators experiences that are in the flow of work, easy to use and ideally completely transparent, operating in the background. * Leverage the power of the CrowdStrike Falcon platform:

next page

Showing results 1-20

Crowdstrike Falcon Administrator information

What is a CrowdStrike Falcon administrator?

Crowdstrike Falcon Administrators are IT professionals responsible for managing, configuring, and maintaining the Crowdstrike Falcon cybersecurity platform within an organization. They handle tasks such as deploying endpoint protection agents, monitoring security alerts, responding to incidents, and ensuring that security policies are properly enforced. Administrators also work to optimize the platform’s settings, manage user permissions, and generate security reports to keep the organization’s systems secure. Their expertise helps protect against cyber threats and ensures compliance with security standards.

What are some common challenges faced by CrowdStrike Falcon administrators when managing endpoint security across large organizations?

Crowdstrike Falcon Administrators often encounter challenges related to scaling the platform across numerous endpoints and ensuring consistent policy enforcement. Managing frequent updates, handling false positives, and integrating Falcon with other security tools can also be complex. Additionally, collaborating with IT and incident response teams is crucial to quickly address threats and maintain compliance. Staying updated on the latest threats and Crowdstrike features helps administrators proactively protect their organization's digital assets.

What are the key skills and qualifications needed to thrive as a CrowdStrike Falcon administrator, and why are they important?

To thrive as a Crowdstrike Falcon Administrator, you need a strong background in cybersecurity, endpoint protection, and enterprise IT systems, often supported by relevant degrees or certifications like CompTIA Security+ or CISSP. Familiarity with Crowdstrike Falcon's cloud-based console, EDR tools, and scripting languages such as PowerShell is typically required. Analytical thinking, effective communication, and problem-solving skills help administrators respond swiftly to threats and collaborate with IT teams. These competencies ensure the effective deployment, management, and optimization of Crowdstrike solutions to protect organizational assets from cyber threats.

What is the difference between Crowdstrike Falcon Administrator vs Crowdstrike Falcon Engineer?

AspectCrowdstrike Falcon AdministratorCrowdstrike Falcon Engineer
CertificationsTypically requires Crowdstrike certifications and cybersecurity fundamentalsOften requires advanced certifications like CISSP, CEH, or vendor-specific engineering credentials
Work EnvironmentFocuses on managing and maintaining Falcon platform, troubleshooting, and user supportInvolves designing, implementing, and optimizing Falcon security solutions, often in a technical engineering capacity
Employer & Industry UsageUsed across cybersecurity teams in various industries for endpoint security managementUsed by security engineering teams for deployment and integration of Falcon in complex environments

The Crowdstrike Falcon Administrator primarily manages and supports the Falcon platform, ensuring endpoint security and user support. In contrast, the Crowdstrike Falcon Engineer focuses on deploying, customizing, and optimizing Falcon solutions within an organization's security infrastructure. Both roles require cybersecurity knowledge, but the engineer role typically demands more technical and engineering expertise.

What are popular job titles related to Crowdstrike Falcon Administrator jobs?

For Crowdstrike Falcon Administrator jobs, the most frequently searched job titles are:

Infographic showing various Crowdstrike Falcon Administrator job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 83% Full Time, 11% Part Time, 1% Temporary, 3% Contract, and 1% Nights. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution.

Remote CrowdStrike Falcon Engineer

Des Moines, IA • On-site

Mahantech Corporation
IT Services • 1 - 10 employees

Other

Posted 25 days ago


Key responsibilities

  • Architect, implement, and maintain the state-wide CrowdStrike Falcon platform architecture across multi-tenant environments.

  • Act as the final technical escalation point for complex endpoint threats, perform advanced containment, remediation, and live forensics during critical incidents.

  • Design, support, and develop telemetry integrations between CrowdStrike Falcon, SIEM/SOAR platforms, network defenses, and threat intelligence feeds.


Job description

Engagement Type
Contract Short Description
This position acts as the highest
level of technical escalation (Tier 3) for endpoint incidents, advanced threat
hunting, platform troubleshooting, and complex integrations (such as Next-Gen
SIEM, threat intelligence, and automated orchestration).
Complete Description
The Senior Tier 3 CrowdStrike
Architect serves as the primary technical authority for the State of Iowa s
Enterprise Endpoint Detection and Response (EDR / XDR) platform. Operating
within the Information Security Services (ISS) Bureau, this role is responsible
for the overall architecture, administration, multi-tenant federation,
fine-tuning, and escalation engineering of the CrowdStrike Falcon ecosystem
across state agencies.
This position acts as the highest level of technical escalation (Tier 3) for
endpoint incidents, advanced threat hunting, platform troubleshooting, and
complex integrations (such as Next-Gen SIEM, threat intelligence, and automated
orchestration).
1. Platform Architecture &
Multi-Tenant Administration
Architect,
implement, and maintain the state-wide CrowdStrike Falcon platform architecture
across multi-tenant environments (CID hierarchy, RBAC, policy groups).
Oversee
sensor deployment strategies, policy prevention/detection tuning, custom rule creation
(IOAs/IOCs), and feature rollout schedules across diverse agency environments.
Manage
CrowdStrike platform health, agent updates, host group management, and agent
troubleshooting across Windows, macOS, Linux, and virtualized workloads.
2. Tier 3 Incident Escalation
& Response Engineering
Act
as the final technical escalation point for complex endpoint threats, zero-day
vulnerabilities, and persistent malware identified by Tier 1/2 SOC analysts.
Execute
advanced containment, remediation, and live forensics using Real-Time Response
(RTR) and custom scripts during critical incidents.
Partner
with SOC Analysts and Incident Response teams to refine playbooks, minimize
Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk
reduction.
3. Integration, Automation &
Data Pipeline
Design
and support telemetry integration between CrowdStrike Falcon, central SIEM/SOAR
platforms, network defenses, and threat intelligence feeds.
Introduce
new integration ideas to better levergage existing security tools.
Leverage
CrowdStrike Fusion SOAR workflows to automate routine containment,
notifications, and response actions.
Align
endpoint security strategies with Identity Threat Detection and Response (ITDR)
and Cloud Security Posture Management (CSPM) modules as platform needs evolve.
4. Stakeholder Enablement,
Training & Vendor Management
Translate
complex technical threat data into actionable guidance for agency IT administrators
and executive leadership.
Develop
dashboards using the CrowdStrike API to collect daily vulnerability data, and
other key metrics, providing clear and actionable visibility into the
enterprise environment.
Develop
standardized operating procedures (SOPs), deployment guides, and platform
hardening specifications for state agency IT partners.
Serve
as the primary technical point of contact with CrowdStrike engineering and technical
account managers (TAMs) to drive feature requests and resolve critical bugs.
Provide
formal and informal technical mentoring and training to Tier 1/2 SOC staff.
Required Technical Experience
Platform
Mastery: 4+ years of hands-on experience engineering, deploying, and
maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).
Tier
3 IR Capabilities: Demonstrated proficiency using CrowdStrike Real-Time
Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat
hunting.
OS
& Scripting: Strong knowledge of Windows, Linux, and macOS internals, along
with scripting capabilities (PowerShell, Python, Bash) for automated
remediation and API integration.
Security
Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity
& Access Management (AD/Entra ID), patch management, vulnerability
assessments, and MITRE ATT&CK framework mapping.
Required Certifications (Must
hold at least one active certification)
CrowdStrike
Specific (Highly Preferred):
CrowdStrike Certified Falcon
Administrator (CCFA)
CrowdStrike Certified Falcon
Responder (CCFR)
CrowdStrike Certified Falcon Hunter
(CCFH)
Industry
Certifications:
CISSP, GCFA, GCIH, GSEC, CISA, or
equivalent advanced security credential.
Professional & Soft Skills
Integrity
& Ethics: Unwavering commitment to confidentiality, integrity, and compliance
standards necessary for state government operations.
Communication
& Translation: Proven ability to explain technical risk to non-technical
stakeholders and state agency leaders clearly.
Complex
Problem Solving: High analytical capability to navigate complex multi-tenant
environments, agency-specific constraints, and conflicting operational
priorities.
Collaboration
& Inclusion: Strong interpersonal skills with a commitment to fostering a diverse,
supportive, and team-oriented working environment.
Preferred Qualifications
Prior
experience in state/local government (SLTT), higher education, or large-scale
multi-tenant enterprise environments.
Experience
integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs
(e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).
Familiarity
with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub
1075).
).
Required/Desired Skills
Skill Required/Desired Amount of Experience Industry Certifications: CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential. Required 4.0 Years Required Certifications (must hold at least one active CrowdStrike specific certification): Required 4.0 Years CrowdStrike Certified Falcon Administrator (CCFA); CrowdStrike Certified Falcon Responder (CCFR); CrowdStrike Certified Falcon Hunter (CCFH) Required Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints). Required 4.0 Years Tier 3 IR Capabilities: Proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting Required 4.0 Years OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated... Required automated remediation and API integration. Required 4.0 Years Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, Required vulnerability assessments, and MITRE ATT&CK framework mapping. Required 4.0 Years Integrity & Ethics: Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations. Required 7.0 Years Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly. Required 7.0 Years Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments, agency-specific constraints, and conflicting... Required operational policies Required 7.0 Years Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team-oriented working environment. Required 7.0 Years Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments. Highly desired Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex). Highly desired Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075). Highly desired