Senior Tier 3 CroudStrike Architect

Mbi Llc

Des Moines, Northern (IA, KY)

Hybrid

USD 120,000 - 160,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

The Senior Tier 3 CrowdStrike Architect will serve as the primary technical authority for the State of Iowa’s Enterprise EDR/XDR platform. Operating within the ISS Bureau, you will oversee architecture, multi-tenant federation, tuning, and escalation engineering of the CrowdStrike Falcon ecosystem across state agencies.

You will act as the highest level of escalation for endpoint incidents, threat hunting, platform troubleshooting, and complex integrations, while mentoring Tier 1/2 SOC staff and

Qualifications

  • Platform Mastery with hands-on CrowdStrike Falcon at enterprise scale.
  • Experience with Real-Time Response for endpoint threat hunting and containment.
  • Scripting skills for automated remediation and API integration.
  • Understanding of MITRE ATT&CK and patch management practices.
  • Active certifications such as CISSP, GCFA, GCIH, GSEC, CISA or equivalent.

Responsibilities

  • Serve as primary technical authority for the CrowdStrike Falcon platform across state agencies.
  • Architect, implement, and maintain multi-tenant CrowdStrike Falcon architecture and governance.
  • Lead complex endpoint investigations, containment, and live forensics with RTR.
  • Integrate CrowdStrike with SIEM/SOAR and threat intel feeds; mentor SOC staff.
  • Develop dashboards and SOPs; collaborate with IT leadership and engineers.

Skills

Platform Mastery
Tier 3 IR Capabilities
OS & Scripting
Security Ecosystems
Integrity & Ethics
Communication & Translation
Complex Problem Solving
Collaboration & Inclusion

Education

Industry Certifications: CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential
CrowdStrike Specific Certification (Highly Preferred)

Tools

CrowdStrike Falcon
RTR (Real-Time Response)

Job description

- The Senior Tier 3 CrowdStrike Architect serves as the primary technical authority for the State of Iowa’s Enterprise Endpoint Detection and Response (EDR / XDR) platform.

- Operating within the Information Security Services (ISS) Bureau, this role is responsible for the overall architecture, administration, multi-tenant federation, fine-tuning, and escalation engineering of the CrowdStrike Falcon ecosystem across state agencies.

- This position acts as the highest level of technical escalation (Tier 3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations (such as Next-Gen SIEM, threat intelligence, and automated orchestration).

- Architect, implement, and maintain the state-wide CrowdStrike Falcon platform architecture across multi-tenant environments (CID hierarchy, RBAC, policy groups).

- Oversee sensor deployment strategies, policy prevention/detection tuning, custom rule creation (IOAs/IOCs), and feature rollout schedules across diverse agency environments.

- Manage CrowdStrike platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads.

- Act as the final technical escalation point for complex endpoint threats, zero-day vulnerabilities, and persistent malware identified by Tier 1/2 SOC analysts.

- Execute advanced containment, remediation, and live forensics using Real-Time Response (RTR) and custom scripts during critical incidents.

- Partner with SOC Analysts and Incident Response teams to refine playbooks, minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk reduction.

- Design and support telemetry integration between CrowdStrike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds.

- Introduce new integration ideas to better levergage existing security tools.

- Leverage CrowdStrike Fusion SOAR workflows to automate routine containment, notifications, and response actions.

- Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules as platform needs evolve.

- Translate complex technical threat data into actionable guidance for agency IT administrators and executive leadership.

- Develop dashboards using the CrowdStrike API to collect daily vulnerability data, and other key metrics, providing clear and actionable visibility into the enterprise environment.

- Develop standardized operating procedures (SOPs), deployment guides, and platform hardening specifications for state agency IT partners.

- Serve as the primary technical point of contact with CrowdStrike engineering and technical account managers (TAMs) to drive feature requests and resolve critical bugs.

- Provide formal and informal technical mentoring and training to Tier 1/2 SOC staff.

Required Technical Experience

- Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).

- Tier 3 IR Capabilities: Demonstrated proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting.

- OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated remediation and API integration.

- Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping.

Required Certifications (Must hold at least one active certification)

- CrowdStrike Specific (Highly Preferred):

Industry Certifications:

- CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.

Professional & Soft Skills

- Integrity & Ethics: Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations.

- Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly.

- Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments, agency-specific constraints, and conflicting operational priorities.

- Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team-oriented working environment.

Preferred Qualifications

- Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.

- Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).

- Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).

Fill the skill matrix below:

Skill

Amount

Candidate's No. of years of experience

Industry Certifications: CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.

Required

4

Required Certifications (must hold at least one active CrowdStrike specific certification):

Required

4

Required

Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).

Required

4

Tier 3 IR Capabilities: Proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting

Required

4

OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated...

Required

automated remediation and API integration.

Required

4

Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management,

Required

vulnerability assessments, and MITRE ATT&CK framework mapping.

Required

4

Integrity & Ethics: Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations.

Required

7

Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly.

Required

7

Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments, agency-specific constraints, and conflicting...

Required

operational policies

Required

7

Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team-oriented working environment.

Required

7

Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.

Highly desired

Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).

Highly desired

Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).

Highly desired

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CrowdStrike Platform Associate Resident Consultant (Remote)
CrowdStrike Platform Associate Resident Consultant (Remote)

CrowdStrike • Town of Texas (WI)

On-site
USD 70,000 - 95,000
Market compensation and equity
Wellness programs
Generous vacation and holidays
+5
CrowdStrike Platform Associate Resident Consultant (Remote)
CrowdStrike Platform Associate Resident Consultant (Remote)

CrowdStrike • United States

On-site
USD 70,000 - 95,000
Equity awards
Wellness programs
Paid time off
+1
Manager, Platform Professional Services (Remote)
Manager, Platform Professional Services (Remote)

CrowdStrike • United States

On-site
USD 140,000 - 195,000
Competitive compensation & equity
Wellness programs
Parental leave
+3
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)

CrowdStrike • United States

On-site
USD 85,000 - 120,000
Equity awards
Wellness programs
Vacation & holidays
+5
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)

CrowdStrike • St. Louis (MO)

On-site
USD 85,000 - 120,000
Equity awards
Wellness programs
Vacation and holidays
+4
CrowdStrike Next-Gen SIEM Resident Consultant (Remote)
CrowdStrike Next-Gen SIEM Resident Consultant (Remote)

CrowdStrike • Arizona

On-site
USD 85,000 - 120,000
Market-leading compensation
Wellness programs
Generous vacation and holidays
+5
Manager, Platform Professional Resident Services (Remote)
Manager, Platform Professional Resident Services (Remote)

CrowdStrike • California (MO)

On-site
USD 140,000 - 195,000
Market compensation
Wellness programs
Paid time off
+3
Manager, Platform Professional Resident Services (Remote)
Manager, Platform Professional Resident Services (Remote)

CrowdStrike • United States

On-site
USD 140,000 - 195,000
Market-leading compensation
Wellness programs
Paid time off
+4
Technical Support Engineer - GovCloud (Remote)
Technical Support Engineer - GovCloud (Remote)

CrowdStrike Holdings, Inc. • Northern (KY)

Hybrid
USD 70,000 - 110,000
Health insurance
401k
Paid time off
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000