Watch this video to learn more about Deloitte LLP
Job Details
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
Recruiting for this role ends on May 31, 2026.
Work You'll Do
Endpoint Detection & Response (EDR) Administrator - CrowdStrike Falcon
The EDR Administrator ensures the continuous, secure operation of the agency's endpoint security capabilities, with primary responsibility for CrowdStrike Falcon (EDR) and associated Falcon modules. This role owns day-to-day platform administration, configuration governance, production testing, and integration support to enable rapid detection, investigation, and response across the enterprise endpoint environment.
In today's evolving threat landscape, the agency must proactively safeguard endpoints and respond quickly to incidents. The EDR Administrator is critical to operational resilience-maintaining platform health, improving detection fidelity, supporting troubleshooting and investigations, and adapting configurations and workflows as threats, technologies, and requirements evolve.
Key Responsibilities
The Team
Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.
Our Cyber Defense & Resilience offering assists clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response, ensuring clients can be ready for, respond to, and recover from business disruptions.
The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery-focused professionals.
Qualifications
Required:
Preferred Certifications:
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $88,600 to $163,100.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Information for applicants with a need for accommodation: https://www2.deloitte.com/us/en/pages/careers/articles/join-deloitte-assistance-for-disabled-applicants.html
Recruiting for this role ends on May 31, 2026.
Work You'll Do
Endpoint Detection & Response (EDR) Administrator - CrowdStrike Falcon
The EDR Administrator ensures the continuous, secure operation of the agency's endpoint security capabilities, with primary responsibility for CrowdStrike Falcon (EDR) and associated Falcon modules. This role owns day-to-day platform administration, configuration governance, production testing, and integration support to enable rapid detection, investigation, and response across the enterprise endpoint environment.
In today's evolving threat landscape, the agency must proactively safeguard endpoints and respond quickly to incidents. The EDR Administrator is critical to operational resilience-maintaining platform health, improving detection fidelity, supporting troubleshooting and investigations, and adapting configurations and workflows as threats, technologies, and requirements evolve.
Key Responsibilities
- Platform Administration & Health
- Administer CrowdStrike Falcon (tenant configuration, sensor health, policy sets, exclusions, groups/tags).
- Monitor service performance and endpoint coverage; remediate gaps and recurring agent issues.
- Configuration, Policy & Workflow Management
- Implement and maintain policies, prevention settings, and workflows aligned to federal guidelines and industry best practices.
- Manage change control for configuration updates, including approvals, communications, and rollback readiness.
- Testing & Release Enablement
- Develop and execute development and production test plans for Falcon components and configuration changes.
- Validate new features/modules and conduct controlled rollouts (pilot rings, phased deployment, success criteria).
- Module & Capability Support
- Support Falcon components such as Identity Protection, Forensics, Cloud Workload Protection, Threat Intelligence, and workflow implementation as applicable.
- Integration & Automation Support
- Integrate EDR telemetry, alerts, and case workflows with enterprise security services (e.g., SIEM, SOAR, ticketing, identity, vulnerability management).
- Troubleshoot data pipelines, alert routing, and enrichment to improve investigation speed and accuracy.
- Incident Support & Troubleshooting
- Provide expert triage support for endpoint detections, containment actions, and investigative needs in coordination with SOC and endpoint teams.
- Resolve complex platform issues (policy conflicts, performance impacts, false positives/negatives) and drive root-cause fixes.
- Documentation & Operational Excellence
- Produce and maintain baselines, runbooks, SOPs, and knowledge articles; contribute to continuous improvement and lessons learned
The Team
Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.
Our Cyber Defense & Resilience offering assists clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response, ensuring clients can be ready for, respond to, and recover from business disruptions.
The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery-focused professionals.
Qualifications
Required:
- 4+ years of direct experience administering EDR platforms (CrowdStrike preferred).
- Bachelor's degree
- Ability to obtain Public Trust clearance
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future
- Ability to travel 25%, on average, based on the work you do and the clients and industries/sectors you serve
- 4+ years of hands-on experience in the following areas:
- Development and production testing of EDR platform components, including (as applicable):
Identity Protection, Forensics, Cloud Workload Protection, policy/workflow implementation, Threat Intelligence. - Demonstrated experience integrating EDR components with other security systems and services.
- Ability to configure EDR solutions to align with federal guidelines and industry best practices.
- Strong experience developing security baselines, operational troubleshooting, and technical documentation.
- Development and production testing of EDR platform components, including (as applicable):
Preferred Certifications:
- CompTIA Advanced Security Practitioner (CASP+)
- ISACA Certified Information Security Manager (CISM)
- (ISC)² Certified Information Systems Security Professional (CISSP)
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $88,600 to $163,100.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Information for applicants with a need for accommodation: https://www2.deloitte.com/us/en/pages/careers/articles/join-deloitte-assistance-for-disabled-applicants.html
Company Details
Deloitte LLP
New York City, NY, United States
Don't imagine what's next. Discover it. We provide industry-leading audit & assurance services, consulting, tax and advisory services to many of... Read more