IA-DOM-DOIT-TS4-Senior Tier 3 CroudStrike Architect

Varmoda Tech

$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years of hands-on experience with CrowdStrike Falcon at enterprise scale.
  • Experience supporting environments with 10,000+ endpoints.
  • Deep expertise in CrowdStrike Falcon Administration, EDR, XDR, threat hunting, and incident response.
  • Proficient in custom Development of IOAs and IOCs.
  • Strong knowledge of Windows, Linux, and macOS administration.
  • Experience scripting and automating tasks using PowerShell, Python, and Bash.
  • Excellent troubleshooting, analytical, and communication skills.

Responsibilities

  • Architect, implement, and maintain the enterprise CrowdStrike Falcon platform.
  • Design and manage CID hierarchy structures and role-based access controls.
  • Develop sensor deployment strategies tailored for agency environments.
  • Configure and optimize prevention and detection policies, including custom IOAs and IOCs.
  • Serve as the highest escalation point for advanced endpoint threats.
  • Investigate and respond to zero-day vulnerabilities and persistent threats.
  • Design and support integration with SIEM, SOAR, and threat intelligence platforms.

Benefits

  • Develop executive dashboards and security metrics using CrowdStrike APIs.
  • Track vulnerabilities and platform utilization.
  • Act as liaison with CrowdStrike engineering teams.
  • Mentor and guide Tier 1 and Tier 2 SOC personnel.
Full Job Description
The Senior Tier 3 CrowdStrike Architect serves as the primary technical authority for the State of Iowa's Enterprise Endpoint Detection and Response (EDR/XDR) environment. Operating within the Information Security Services (ISS) Bureau, this role is responsible for the architecture, administration, optimization, governance, and advanced engineering of the CrowdStrike Falcon platform across multiple state agencies.
This position functions as the highest level of technical escalation for endpoint security incidents, advanced threat hunting, security integrations, automation, and platform operations. The ideal candidate will possess deep expertise with CrowdStrike Falcon, endpoint security, incident response, automation, and enterprise-scale cybersecurity operations.

Key Responsibilities
Platform Architecture & Multi-Tenant Administration
  • Architect, implement, and maintain the enterprise CrowdStrike Falcon platform across multi-tenant environments.
  • Design and manage CID hierarchy structures, role-based access controls (RBAC), policy groups, and platform governance.
  • Develop and maintain sensor deployment strategies across diverse agency environments.
  • Configure and optimize prevention policies, detection policies, custom Indicators of Attack (IOAs), and Indicators of Compromise (IOCs).
  • Manage platform health, agent updates, host groups, and Falcon feature deployments.
  • Support CrowdStrike Falcon environments across:
    • Windows
    • Linux
    • macOS
    • Virtualized workloads
Tier 3 Incident Escalation & Response Engineering
  • Serve as the highest escalation point for advanced endpoint threats and security incidents.
  • Investigate zero-day vulnerabilities, advanced malware, ransomware, and persistent threats.
  • Leverage CrowdStrike Real-Time Response (RTR) capabilities for containment, remediation, and forensic investigations.
  • Develop automation scripts and remediation procedures.
  • Partner with SOC and Incident Response teams to improve response effectiveness.
  • Drive improvements in:
    • Mean Time to Detect (MTTD)
    • Mean Time to Respond (MTTR)
    • Risk Reduction Metrics
Integration, Automation & Data Pipeline Engineering
  • Design and support integrations between CrowdStrike Falcon and enterprise security ecosystems.
  • Integrate security telemetry with:
    • SIEM Platforms
    • SOAR Solutions
    • Threat Intelligence Platforms
    • Network Security Tools
  • Implement and maintain CrowdStrike Fusion SOAR workflows.
  • Automate security response, containment, notifications, and remediation actions.
  • Align endpoint security strategies with:
    • Identity Threat Detection & Response (ITDR)
    • Cloud Security Posture Management (CSPM)
  • Identify and implement new integration opportunities to enhance overall security visibility and effectiveness.
Stakeholder Enablement, Reporting & Vendor Management
  • Develop executive dashboards and security metrics using CrowdStrike APIs.
  • Track vulnerabilities, endpoint coverage, threat activity, and platform utilization.
  • Translate technical security findings into actionable business recommendations.
  • Develop:
    • Standard Operating Procedures (SOPs)
    • Deployment Guides
    • Security Hardening Standards
    • Operational Documentation
  • Act as primary technical liaison with CrowdStrike engineering teams and Technical Account Managers (TAMs).
  • Deliver mentoring, technical guidance, and training to Tier 1 and Tier 2 SOC personnel.


Required Qualifications
  • 4+ years of hands-on experience engineering, deploying, administering, and maintaining CrowdStrike Falcon at enterprise scale.
  • Experience supporting environments with 10,000+ endpoints.
  • Deep expertise in:
    • CrowdStrike Falcon Administration
    • Endpoint Detection & Response (EDR)
    • Extended Detection & Response (XDR)
    • Threat Hunting
    • Incident Response
  • Demonstrated experience utilizing:
    • CrowdStrike Real-Time Response (RTR)
    • Custom IOA Development
    • Custom IOC Development
  • Strong knowledge of:
    • Windows Internals
    • Linux Administration
    • macOS Security
  • Experience with scripting and automation using:
    • PowerShell
    • Python
    • Bash
  • Strong understanding of:
    • Network Security
    • Firewalls
    • IDS/IPS Technologies
    • Active Directory
    • Microsoft Entra ID
    • Vulnerability Management
    • Patch Management
    • MITRE Telecommunication&CK Framework
  • Experience integrating endpoint security solutions with SIEM and SOAR platforms.
  • Excellent troubleshooting, analytical, and incident response capabilities.
  • Strong communication and stakeholder management skills.


Preferred Qualifications
  • Experience in State, Local, Tribal, and Territorial (SLTT) government environments.
  • Experience supporting higher education or large-scale multi-tenant enterprise organizations.
  • Experience integrating CrowdStrike APIs with:
    • Splunk
    • Microsoft Sentinel
    • Palo Alto Cortex
    • Other SIEM/SOAR Platforms
  • Experience with:
    • Threat Intelligence Platforms
    • Security Automation
    • Security Orchestration
    • Cloud Security Platforms
  • Knowledge of regulatory and compliance frameworks including:
    • NIST SP 800-53
    • CJIS
    • HIPAA
    • IRS Publication 1075
  • Experience developing executive security reporting and operational metrics dashboards.


Certifications & Clearance
Required Certification (Must Hold at Least One Active Certification)
CrowdStrike Certifications (Highly Preferred)
  • CrowdStrike Certified Falcon Administrator (CCFA)
  • CrowdStrike Certified Falcon Responder (CCFR)
  • CrowdStrike Certified Falcon Hunter (CCFH)
Industry Certifications
  • CISSP (Certified Information Systems Security Professional)
  • GCIH (GIAC Certified Incident Handler)
  • GCFA (GIAC Certified Forensic Analyst)
  • GSEC (GIAC Security Essentials)
  • CISA (Certified Information Systems Auditor)
  • Equivalent advanced cybersecurity certification


Similar Jobs

More Jobs at Varmoda Tech

More Information Technology Jobs

Find similar IA-DOM-DOIT-TS4-Senior Tier 3 CroudStrike Architect jobs: