Haystack
← Back to Jobs
Remote
Other
BI

Senior Tier 3 CrowdStrike Architect @ Remote

BURGEON IT SERVICES LLCUnited States🇺🇸United StatesPosted 19 Aug 2026

Why This Role Stands Out

Leverage your extensive CrowdStrike expertise as a Senior Tier 3 Architect in this fully remote role, where you'll be the technical authority for a large-scale EDR/XDR environment. This opportunity is ideal for a seasoned professional with a passion for threat hunting, incident response, and platform automation, offering significant impact and continuous learning. Apply today to shape the future of enterprise security from anywhere!

Quick Overview

Work Type
Remote
Level
Mid Senior

Job Description

Senior Tier 3 CrowdStrike Architect

Location: Des Moines, IA Remote
Job Type: Long-Term Contract
Experince: 10+ Years

Job Summary

We are seeking a Senior Tier 3 CrowdStrike Architect to serve as the technical authority for an enterprise CrowdStrike Falcon EDR/XDR environment supporting 10,000+ endpoints. The role will focus on Falcon architecture, Tier 3 incident response, threat hunting, automation, integrations, and platform administration.

Mandatory Skills & Experience

  • 4+ years of hands-on CrowdStrike Falcon experience in an enterprise environment with 10,000+ endpoints.
  • Strong experience with CrowdStrike Falcon architecture, administration, RBAC, policies, host groups, sensor deployment, and platform tuning.
  • Hands-on experience with CrowdStrike Real-Time Response (RTR).
  • Strong Tier 3 Incident Response, endpoint threat hunting, malware investigation, containment, and remediation experience.
  • Experience creating and managing custom IOCs and IOAs.
  • Strong knowledge of Windows, Linux, and macOS internals.
  • Strong scripting experience with PowerShell, Python, and/or Bash.
  • Experience with CrowdStrike Falcon APIs and security automation.
  • Experience integrating CrowdStrike with SIEM/SOAR platforms, such as Splunk, Microsoft Sentinel, or Palo Alto Cortex.
  • Knowledge of network security, firewalls, IDS/IPS, Active Directory, Microsoft Entra ID/IAM, patch management, and vulnerability management.
  • Strong understanding of the MITRE ATT&CK framework.
  • Experience with CrowdStrike Fusion SOAR and automated response workflows is highly valuable.
  • Strong communication, troubleshooting, stakeholder management, and mentoring skills.

Mandatory Certification

Candidate must hold at least one active certification:

  • CrowdStrike Certified Falcon Administrator (CCFA)
  • CrowdStrike Certified Falcon Responder (CCFR)
  • CrowdStrike Certified Falcon Hunter (CCFH)
  • OR CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security certification.

Preferred

  • State/local government, higher education, or large multi-tenant enterprise experience.
  • Knowledge of NIST SP 800-53, CJIS, HIPAA, or IRS Pub 1075.
  • Experience with ITDR/CSPM security technologies.

Skills

Splunk
Active Directory
Bash
HIPAA
PowerShell
Python
Stakeholder Management

Similar jobs