Haystack
← Back to Jobs
Other
PT

Senior Tier 3 CroudStrike Architect

PROCYON TechnostructureUnited States🇺🇸United StatesPosted 18 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Position Summary

The Senior Tier 3 CrowdStrike Architect serves as the technical authority for the State of Iowa’s enterprise CrowdStrike Falcon EDR/XDR platform. This role is responsible for platform architecture, multi-tenant administration, advanced threat hunting, Tier 3 incident response, security integrations, automation, and technical escalation across state agencies.

Key Responsibilities

  • Architect and administer CrowdStrike Falcon across large-scale, multi-tenant environments.

  • Manage CID hierarchy, RBAC, policies, host groups, sensors, IOAs/IOCs, and prevention/detection tuning.

  • Serve as the Tier 3 escalation point for complex endpoint incidents, malware, zero-day threats, and advanced attacks.

  • Perform advanced threat hunting, containment, remediation, and live response using CrowdStrike RTR.

  • Develop automation and remediation scripts using PowerShell, Python, and Bash.

  • Integrate CrowdStrike with SIEM/SOAR, threat intelligence, network security, IAM, and vulnerability management platforms.

  • Leverage CrowdStrike APIs and Fusion SOAR for automation, reporting, dashboards, and response workflows.

  • Develop SOPs, security standards, dashboards, and operational documentation.

  • Mentor Tier 1/2 SOC analysts and collaborate with agency IT/security teams.

  • Serve as the technical liaison with CrowdStrike Engineering and TAMs.

Required Qualifications

  • 4+ years of hands-on CrowdStrike Falcon experience in enterprise environments, preferably 10,000+ endpoints.

  • Strong experience with EDR/XDR, RTR, threat hunting, IOAs/IOCs, incident response, and detection engineering.

  • Strong knowledge of Windows, Linux, and macOS.

  • Scripting experience with PowerShell, Python, or Bash.

  • Knowledge of SIEM/SOAR, IAM/Entra ID, vulnerability management, network security, and MITRE ATT&CK.

  • Experience with CrowdStrike API integrations and security automation preferred.

  • Must hold at least one active certification: CCFA, CCFR, CCFH, CISSP, GCFA, GCIH, GSEC, CISA, or equivalent.

Preferred Qualifications

  • Experience in State/Local Government (SLTT), higher education, or large multi-tenant environments.

  • Experience with Splunk, Microsoft Sentinel, Palo Alto Cortex, or similar platforms.

  • Familiarity with NIST SP 800-53, CJIS, HIPAA, or IRS Publication 1075.

Skills

Splunk
Bash
HIPAA
PowerShell
Python

Similar jobs