CroudStrike Architect

JPS Tech Solutions

Des Moines (IA)

On-site

USD 150,000 - 190,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

JPS Tech Solutions is seeking a Senior Tier 3 CrowdStrike Architect to lead enterprise EDR/XDR across state agencies. You will own architecture, multi-tenant administration, and advanced threat hunting, working with SOC, IT admins, and executive leadership.

You will design integrations between Falcon, SIEM/SOAR, and threat feeds, refine playbooks, and mentor junior staff while aligning security with ITDR and CSPM modules as needs evolve.

Qualifications

  • Demonstrated expertise with CrowdStrike Falcon at enterprise scale (10,000+ endpoints).
  • Experience writing IOAs/IOCs and performing endpoint threat hunting.
  • Strong scripting capabilities (PowerShell, Python, Bash) for automation and integration.

Responsibilities

  • Act as final Tier 3 escalation point for complex endpoint threats and incidents.
  • Design telemetry integrations between CrowdStrike Falcon and SIEM/SOAR platforms.
  • Develop SOPs, deployment guides, and platform hardening specifications for state agencies.
  • Mentor Tier 1/2 SOC staff and coordinate with CrowdStrike TAMs for feature requests.

Skills

CrowdStrike Falcon
RTR
IOAs/IOCs
PowerShell
Python
Bash

Tools

Splunk
Microsoft Sentinel
Palo Alto Cortex
CrowdStrike API

Job description

Short Description

This position acts as the highest level of technical escalation (Tier 3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations (such as Next-Gen SIEM, threat intelligence, and automated orchestration).

Description

The Senior Tier 3 CrowdStrike Architect serves as the primary technical authority for the State of Iowa’s Enterprise Endpoint Detection and Response (EDR / XDR) platform. Operating within the Information Security Services (ISS) Bureau, this role is responsible for the overall architecture, administration, multi‑tenant federation, fine‑tuning, and escalation engineering of the CrowdStrike Falcon ecosystem across state agencies. This position acts as the highest level of technical escalation (Tier 3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations (such as Next-Gen SIEM, threat intelligence, and automated orchestration).

Platform Architecture & Multi‑Tenant Administration
  • Architect, implement, and maintain the state‑wide CrowdStrike Falcon platform architecture across multi‑tenant environments (CID hierarchy, RBAC, policy groups).
  • Oversee sensor deployment strategies, policy prevention/detection tuning, custom rule creation (IOAs/IOCs), and feature rollout schedules across diverse agency environments.
  • Manage CrowdStrike platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads.
Tier 3 Incident Escalation & Response Engineering
  • Act as the final technical escalation point for complex endpoint threats, zero‑day vulnerabilities, and persistent malware identified by Tier 1/2 SOC analysts.
  • Execute advanced containment, remediation, and live forensics using Real‑Time Response (RTR) and custom scripts during critical incidents.
  • Partner with SOC Analysts and Incident Response teams to refine playbooks, minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk reduction.
Integration, Automation & Data Pipeline
  • Design and support telemetry integration between CrowdStrike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds.
  • Introduce new integration ideas to better leverage existing security tools.
  • Leverage CrowdStrike Fusion SOAR workflows to automate routine containment, notifications, and response actions.
  • Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules as platform needs evolve.
Stakeholder Enablement, Training & Vendor Management
  • Translate complex technical threat data into actionable guidance for agency IT administrators and executive leadership.
  • Develop dashboards using the CrowdStrike API to collect daily vulnerability data, and other key metrics, providing clear and actionable visibility into the enterprise environment.
  • Develop standardized operating procedures (SOPs), deployment guides, and platform hardening specifications for state agency IT partners.
  • Serve as the primary technical point of contact with CrowdStrike engineering and technical account managers (TAMs) to drive feature requests and resolve critical bugs.
  • Provide formal and informal technical mentoring and training to Tier 1/2 SOC staff.
Required Technical Experience
  • Platform Mastery: 4+ years of hands‑on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).
  • Tier 3 IR Capabilities: Demonstrated proficiency using CrowdStrike Real‑Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting.
  • OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated remediation and API integration.
  • Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping.
Required Certifications (Must hold at least one active certification)
  • CrowdStrike Certified Falcon Administrator (CCFA)
  • CrowdStrike Certified Falcon Responder (CCFR)
  • CrowdStrike Certified Falcon Hunter (CCFH)
  • CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.
Professional & Soft Skills
  • Integrity & Ethics: Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations.
  • Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly.
  • Complex Problem Solving: High analytical capability to navigate complex multi‑tenant environments, agency‑specific constraints, and conflicting operational priorities.
  • Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team‑oriented working environment.
Preferred Qualifications
  • Prior experience in state/local government (SLTT), higher education, or large‑scale multi‑tenant enterprise environments.
  • Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).
  • Familiarity with federal/state compliance frameworks (NIST SP 800‑53, CJIS, HIPAA, IRS Pub 1075).
Skill Matrix
  • Industry Certifications: CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential. Required. Years.
  • Required Certifications (must hold at least one active CrowdStrike specific certification): CrowdStrike Certified Falcon Administrator (CCFA); CrowdStrike Certified Falcon Responder (CCFR); CrowdStrike Certified Falcon Hunter (CCFH). Required. Years.
  • Platform Mastery: 4+ years of hands‑on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints). Required. Years.
  • Tier 3 IR Capabilities: Proficiency using CrowdStrike Real‑Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting. Required. Years.
  • OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated remediation and API integration. Required.
  • Automated remediation and API integration. Required. Years.
  • Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping. Required. Years.
  • Integrity & Ethics: Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations. Required. Years.
  • Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly. Required. Years.
  • Complex Problem Solving: High analytical capability to navigate complex multi‑tenant environments, agency‑specific constraints, and conflicting… Required.
  • Operational policies. Required. Years.
  • Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team‑oriented working environment. Required. Years.
  • Prior experience in state/local government (SLTT), higher education, or large‑scale multi‑tenant enterprise environments. Highly desired.
  • Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex). Highly desired.
  • Familiarity with federal/state compliance frameworks (NIST SP 800‑53, CJIS, HIPAA, IRS Pub 1075). Highly desired.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Tier 3 CroudStrike Architect
Senior Tier 3 CroudStrike Architect

Mbi Llc • Des Moines (IA), Northern (KY)

Hybrid
USD 120,000 - 160,000
Senior Tier 3 CroudStrike Architect
Senior Tier 3 CroudStrike Architect

Novisync Solutions Inc. • Iowa (LA)

On-site
USD 120,000 - 180,000
CrowdStrike Architect
CrowdStrike Architect

Skywalk Global Pvt. Ltd. • Des Moines (IA)

On-site
USD 130,000 - 180,000
CrowdStrike Platform Associate Resident Consultant (Remote)
CrowdStrike Platform Associate Resident Consultant (Remote)

CrowdStrike • Town of Texas (WI)

On-site
USD 70,000 - 95,000
Market compensation and equity
Wellness programs
Generous vacation and holidays
+5
CrowdStrike Platform Associate Resident Consultant (Remote)
CrowdStrike Platform Associate Resident Consultant (Remote)

CrowdStrike • United States

On-site
USD 70,000 - 95,000
Equity awards
Wellness programs
Paid time off
+1
Manager, Platform Professional Services (Remote)
Manager, Platform Professional Services (Remote)

CrowdStrike • United States

On-site
USD 140,000 - 195,000
Market-leading compensation
Wellness programs
Generous vacation and holidays
+4
Manager, Platform Professional Services (Remote)
Manager, Platform Professional Services (Remote)

CrowdStrike • California (MO)

On-site
USD 140,000 - 195,000
Market-leading compensation
Comprehensive wellness programs
Paid parental leaves
+2
Senior Endpoint Protection Engineer
Senior Endpoint Protection Engineer

Jobtailor • California (MO)

On-site
USD 120,000 - 160,000
Platform Professional Services Sr. Consultant- Cloud (Remote)
Platform Professional Services Sr. Consultant- Cloud (Remote)

CrowdStrike • Town of Texas (WI)

On-site
USD 110,000 - 190,000
Equity awards
Wellness programs
Paid time off
+4
Platform Professional Services Sr. Consultant- Cloud (Remote)
Platform Professional Services Sr. Consultant- Cloud (Remote)

CrowdStrike, Inc. • Town of Texas (WI)

Remote
USD 95,000 - 140,000
Health insurance
Equity awards
Professional development
+1