TELECOMMUTE CroudStrike Architect

Super Technology Solutions, Inc.
United States
14 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Application Programming Interfaces (APIs) Apple Mac Systems Computing Platforms Bash Shell Cloud Computing Security Cyber Security Linux Identity and Access Management Intrusion Detection and Prevention Intrusion Detection Systems Python (Programming Language)
+16 more
Network Security Windows PowerShell Role-Based Access Control Security Information and Event Management Scripting Mitre Att&ck Mttr Cyber Threat Analysis Firewalls (Computer Science) Falcon Platform Deployment Automation Cybercrime Patch Management 3-tier Architectures Data Pipelines Vulnerability Analysis

Job description

The Senior Tier 3 CrowdStrike Architect serves as the primary technical authority for the State of Iowa’s Enterprise Endpoint Detection and Response (EDR / XDR) platform. Operating within the Information Security Services (ISS) Bureau, this role is responsible for the overall architecture, administration, multi-tenant federation, fine-tuning, and escalation engineering of the CrowdStrike Falcon ecosystem across state agencies. This position acts as the highest level of technical escalation (Tier 3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations (such as Next-Gen SIEM, threat intelligence, and automated orchestration).

  1. Platform Architecture & Multi-Tenant Administration
  • Architect, implement, and maintain the state-wide CrowdStrike Falcon platform architecture across multi-tenant environments (CID hierarchy, RBAC, policy groups).

  • Oversee sensor deployment strategies, policy prevention/detection tuning, custom rule creation (IOAs/IOCs), and feature rollout schedules across diverse agency environments.

  • Manage CrowdStrike platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads.

  1. Tier 3 Incident Escalation & Response Engineering
  • Act as the final technical escalation point for complex endpoint threats, zero-day vulnerabilities, and persistent malware identified by Tier 1/2 SOC analysts.

  • Execute advanced containment, remediation, and live forensics using Real-Time Response (RTR) and custom scripts during critical incidents.

  • Partner with SOC Analysts and Incident Response teams to refine playbooks, minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk reduction.

  1. Integration, Automation & Data Pipeline
  • Design and support telemetry integration between CrowdStrike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds.

  • Introduce new integration ideas to better levergage existing security tools.

  • Leverage CrowdStrike Fusion SOAR workflows to automate routine containment, notifications, and response actions.

  • Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules as platform needs evolve.

  1. Stakeholder Enablement, Training & Vendor Management
  • Translate complex technical threat data into actionable guidance for agency IT administrators and executive leadership.

  • Develop dashboards using the CrowdStrike API to collect daily vulnerability data, and other key metrics, providing clear and actionable visibility into the enterprise environment.

  • Develop standardized operating procedures (SOPs), deployment guides, and platform hardening specifications for state agency IT partners.

  • Serve as the primary technical point of contact with CrowdStrike engineering and technical account managers (TAMs) to drive feature requests and resolve critical bugs.

Requirements

  • Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).

  • Tier 3 IR Capabilities: Demonstrated proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting.

  • OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated remediation and API integration.

  • Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping.

Required Certifications (Must hold at least one active certification)

  • CrowdStrike Specific (Highly Preferred):

CrowdStrike Certified Falcon Administrator (CCFA)

CrowdStrike Certified Falcon Responder (CCFR), CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:08 min

Aligning engineering processes with core business impact metrics

Chris Riley · World Congress 2021

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all