×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Senior Croud Strike Architect

Job in Des Moines, Polk County, Iowa, 50301, USA
Listing for: Coventek Inc
Full Time position
Listed on 2026-08-21
Job specializations:
  • IT/Tech
    Cybersecurity
Job Description & How to Apply Below

Senior Tier 3 Crowd Strike Architect

This position acts as the highest level of technical escalation (Tier
3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations (such as Next-Gen SIEM, threat intelligence, and automated orchestration).

The Senior Tier 3 Crowd Strike Architect serves as the primary technical authority for the State of Iowa's Enterprise Endpoint Detection and Response (EDR / XDR) platform. Operating within the Information Security Services (ISS) Bureau, this role is responsible for the overall architecture, administration, multi-tenant federation, fine-tuning, and escalation engineering of the Crowd Strike Falcon ecosystem across state agencies.

Platform Architecture & Multi-Tenant Administration
  • Architect, implement, and maintain the state-wide Crowd Strike Falcon platform architecture across multi-tenant environments (CID hierarchy, RBAC, policy groups).
  • Oversee sensor deployment strategies, policy prevention/detection tuning, custom rule creation (IOAs/IOCs), and feature rollout schedules across diverse agency environments.
  • Manage Crowd Strike platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads.
Tier 3 Incident Escalation & Response Engineering
  • Act as the final technical escalation point for complex endpoint threats, zero-day vulnerabilities, and persistent malware identified by Tier 1/2 SOC analysts.
  • Execute advanced containment, remediation, and live forensics using Real-Time Response (RTR) and custom scripts during critical incidents.
  • Partner with SOC Analysts and Incident Response teams to refine playbooks, minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk reduction.
Integration, Automation & Data Pipeline
  • Design and support telemetry integration between Crowd Strike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds.
  • Introduce new integration ideas to better leverage existing security tools.
  • Leverage Crowd Strike Fusion SOAR workflows to automate routine containment, notifications, and response actions.
  • Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules as platform needs evolve.
Stakeholder Enablement, Training & Vendor Management
  • Translate complex technical threat data into actionable guidance for agency IT administrators and executive leadership.
  • Develop dashboards using the Crowd Strike API to collect daily vulnerability data, and other key metrics, providing clear and actionable visibility into the enterprise environment.
  • Develop standardized operating procedures (SOPs), deployment guides, and platform hardening specifications for state agency IT partners.
  • Serve as the primary technical point of contact with Crowd Strike engineering and technical account managers (TAMs) to drive feature requests and resolve critical bugs.
  • Provide formal and informal technical mentoring and training to Tier 1/2 SOC staff.
Required Technical Experience
  • Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining Crowd Strike Falcon at enterprise scale (10,000+ endpoints).
  • Tier 3 IR Capabilities:
    Demonstrated proficiency using Crowd Strike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting.
  • OS & Scripting:
    Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (Power Shell, Python, Bash) for automated remediation and API integration.
  • Security Ecosystems:
    Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping.
Required Certifications (Must hold at least one active certification)
  • Crowd Strike Specific (Highly Preferred)
  • Crowd Strike Certified Falcon Administrator (CCFA)
  • Crowd Strike Certified Falcon Responder (CCFR)
  • Crowd Strike Certified Falcon Hunter (CCFH)
Industry Certifications
  • CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.
Professional & Soft Skills
  • Integrity & Ethics:
    Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations.
  • Communication & Translation:
    Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly.
  • Complex Problem Solving:
    High analytical capability to navigate complex multi-tenant environments, agency-specific constraints, and conflicting operational priorities.
  • Collaboration & Inclusion:
    Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team-oriented working environment.
Preferred Qualifications
  • Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.
  • Experience integrating Crowd Strike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel,…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary