Senior Tier 3 CroudStrike Architect Remote

Des Moines, IA, US • Posted 1 hour ago • Updated 1 hour ago
Contract W2
Contract Corp To Corp
Contract Independent
9 Months
On-site
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

👾 Reticulating splines...

Job Details

Skills

  • CCFA
  • CCFR
  • CCFH
  • CROWDSTRIKE CERTIFIED
  • CERTIFIED CROWDSTRIKE
  • MITRE
  • ATTACK
  • THREAT
  • PYTHON
  • BASH
  • POWERSHELL

Summary

Additional Job Information:
Title:Senior Tier 3 CroudStrike Architect
Start & End Date: 09/14/2026 to 06/30/2027
Position Type: contract
Location:  Des Moines, IA 50309 
Work Arrangement: Remote

Agency Interview Type: Either Web Cam or In Person Interview
Working hours: 8am - 4:30pm CST; M-F


Complete Description:
The Senior Tier 3 CrowdStrike
Architect serves as the primary technical authority for the State of Iowa’s
Enterprise Endpoint Detection and Response (EDR / XDR) platform. Operating
within the Information Security Services (ISS) Bureau, this role is responsible
for the overall architecture, administration, multi-tenant federation,
fine-tuning, and escalation engineering of the CrowdStrike Falcon ecosystem
across state agencies.

This position acts as the highest level of technical escalation (Tier 3) for
endpoint incidents, advanced threat hunting, platform troubleshooting, and
complex integrations (such as Next-Gen SIEM, threat intelligence, and automated
orchestration).


1. Platform Architecture & Multi-Tenant Administration

• Architect, implement, and maintain the state-wide CrowdStrike Falcon platform architecture across multi-tenant environments (CID hierarchy, RBAC, policy groups).
• Oversee sensor deployment strategies, policy prevention/detection tuning, custom rule creation (IOAs/IOCs), and feature rollout schedules across diverse agency environments.
• Manage CrowdStrike platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads.


2. Tier 3 Incident Escalation & Response Engineering

• Act as the final technical escalation point for complex endpoint threats, zero-day vulnerabilities, and persistent malware identified by Tier 1/2 SOC analysts.
• Execute advanced containment, remediation, and live forensics using Real-Time Response (RTR) and custom scripts during critical incidents.
• Partner with SOC Analysts and Incident Response teams to refine playbooks, minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk reduction.


3. Integration, Automation & Data Pipeline
• Design and support telemetry integration between CrowdStrike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds.
• Introduce new integration ideas to better levergage existing security tools.
• Leverage CrowdStrike Fusion SOAR workflows to automate routine containment, notifications, and response actions.
• Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules as platform needs evolve.


4. Stakeholder Enablement, Training & Vendor Management
• Translate complex technical threat data into actionable guidance for agency IT administrators and executive leadership.
• Develop dashboards using the CrowdStrike API to collect daily vulnerability data, and other key metrics, providing clear and actionable visibility into the enterprise environment.
• Develop standardized operating procedures (SOPs), deployment guides, and platform hardening specifications for state agency IT partners.
• Serve as the primary technical point of contact with CrowdStrike engineering and technical account managers (TAMs) to drive feature requests and resolve critical bugs.
• Provide formal and informal technical mentoring and training to Tier 1/2 SOC staff.



Required Technical Experience
• Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).
• Tier 3 IR Capabilities: Demonstrated proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting.
• OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated remediation and API integration.
• Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, vulnerability assessments, and MITRE Telecommunication&CK framework mapping.


Required Certifications (Must hold at least one active certification)


• CrowdStrike Specific (Highly Preferred):

CrowdStrike Certified Falcon Administrator (CCFA)
CrowdStrike Certified Falcon Responder (CCFR)
CrowdStrike Certified Falcon Hunter (CCFH)


• Industry Certifications:

CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.


Professional & Soft Skills

• Integrity & Ethics: Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations.
• Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly.
• Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments, agency-specific constraints, and conflicting operational priorities.
• Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team-oriented working environment.


Preferred Qualifications


• Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.
• Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).
• Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).
).

Skills:
 SkillRequired / DesiredAmountof ExperienceExpertise RatingMove
Industry Certifications: CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.Required Years  
Required Certifications (must hold at least one active CrowdStrike specific certification):Required Years  
CrowdStrike Certified Falcon Administrator (CCFA); CrowdStrike Certified Falcon Responder (CCFR); CrowdStrike Certified Falcon Hunter (CCFH)Required    
Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).Required Years  
Tier 3 IR Capabilities: Proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting Required Years  
OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated...Required    
automated remediation and API integration.Required Years  
Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, Required    
vulnerability assessments, and MITRE Telecommunication&CK framework mapping.Required Years  
Integrity & Ethics: Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations.Required Years  
Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly.Required Years  
Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments, agency-specific constraints, and conflicting...Required    
operational policiesRequired Years  
Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team-oriented working environment.Required Years  
Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.Highly desired    
Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).Highly desired    
Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).Highly desired    


Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91142014
  • Position Id: 26-02632
  • Posted 1 hour ago

Company Info

About Syntricate

We are here to analyze and resolve the most intricate processes and deliver market’s best solution and services to your business problems.

Syntricate Technologies is an Information Technology and Business Consulting company that offers comprehensive solutions to our clients for Quality Assurance, Validation, Regulatory, Business Analysis and Project Management services. Our core values are integrity, delivering value and making positive impact on society. We are committed to our client success and work on high standards to provide the best professional services.

We believe in effective integration of technology to improve business processes. We provide solutions that address the current and long-tern needs of our clients nationwide which range from various industries such as Healthcare, Pharmaceutical, Life Sciences, Finance and Insurance.

Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs