What are the responsibilities and job description for the Senior Tier 3 CroudStrike Architect position at JPS Tech Solutions?
Short Description:
This position acts as the highest level of technical escalation (Tier 3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations (such as Next-Gen SIEM, threat intelligence, and automated orchestration).
Description:
The Senior Tier 3 CrowdStrike Architect serves as the primary technical authority for the State of Iowa's Enterprise Endpoint Detection and Response (EDR / XDR) platform. Operating within the Information Security Services (ISS) Bureau, this role is responsible for the overall architecture, administration, multi-tenant federation, fine-tuning, and escalation engineering of the CrowdStrike Falcon ecosystem across state agencies.
This position acts as the highest level of technical escalation (Tier 3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations (such as Next-Gen SIEM, threat intelligence, and automated orchestration).
Oversee sensor deployment strategies, policy prevention/detection tuning, custom rule creation (IOAs/IOCs), and feature rollout schedules across diverse agency environments.
Manage CrowdStrike platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads.
Execute advanced containment, remediation, and live forensics using Real-Time Response (RTR) and custom scripts during critical incidents.
Partner with SOC Analysts and Incident Response teams to refine playbooks, minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk reduction.
Introduce new integration ideas to better levergage existing security tools.
Leverage CrowdStrike Fusion SOAR workflows to automate routine containment, notifications, and response actions.
Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules as platform needs evolve.
Develop dashboards using the CrowdStrike API to collect daily vulnerability data, and other key metrics, providing clear and actionable visibility into the enterprise environment.
Develop standardized operating procedures (SOPs), deployment guides, and platform hardening specifications for state agency IT partners.
Serve as the primary technical point of contact with CrowdStrike engineering and technical account managers (TAMs) to drive feature requests and resolve critical bugs.
Provide formal and informal technical mentoring and training to Tier 1/2 SOC staff.
Required Technical Experience:
Platform Mastery: 4 years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000 endpoints).
Tier 3 IR Capabilities: Demonstrated proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting.
OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated remediation and API integration.
Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping.
Required Certifications (Must hold at least one active certification)
CrowdStrike Specific (Highly Preferred):
CrowdStrike Certified Falcon Administrator (CCFA)
CrowdStrike Certified Falcon Responder (CCFR)
CrowdStrike Certified Falcon Hunter (CCFH)
Industry Certifications:
CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.
Professional & Soft Skills:
Integrity & Ethics: Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations.
Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly.
Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments, agency-specific constraints, and conflicting operational priorities.
Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team-oriented working environment.
Preferred Qualifications:
Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.
Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).
Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).
Skill Matrix:
Skill
Required / Desired
Amount
of Experience
Industry Certifications: CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.
Required
Years
Required Certifications (must hold at least one active CrowdStrike specific certification):
Required
Years
CrowdStrike Certified Falcon Administrator (CCFA); CrowdStrike Certified Falcon Responder (CCFR); CrowdStrike Certified Falcon Hunter (CCFH)
Required
Platform Mastery: 4 years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000 endpoints).
Required
Years
Tier 3 IR Capabilities: Proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting
Required
Years
OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated...
Required
automated remediation and API integration.
This position acts as the highest level of technical escalation (Tier 3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations (such as Next-Gen SIEM, threat intelligence, and automated orchestration).
Description:
The Senior Tier 3 CrowdStrike Architect serves as the primary technical authority for the State of Iowa's Enterprise Endpoint Detection and Response (EDR / XDR) platform. Operating within the Information Security Services (ISS) Bureau, this role is responsible for the overall architecture, administration, multi-tenant federation, fine-tuning, and escalation engineering of the CrowdStrike Falcon ecosystem across state agencies.
This position acts as the highest level of technical escalation (Tier 3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations (such as Next-Gen SIEM, threat intelligence, and automated orchestration).
- Platform Architecture & Multi-Tenant Administration
Oversee sensor deployment strategies, policy prevention/detection tuning, custom rule creation (IOAs/IOCs), and feature rollout schedules across diverse agency environments.
Manage CrowdStrike platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads.
- Tier 3 Incident Escalation & Response Engineering
Execute advanced containment, remediation, and live forensics using Real-Time Response (RTR) and custom scripts during critical incidents.
Partner with SOC Analysts and Incident Response teams to refine playbooks, minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk reduction.
- Integration, Automation & Data Pipeline
Introduce new integration ideas to better levergage existing security tools.
Leverage CrowdStrike Fusion SOAR workflows to automate routine containment, notifications, and response actions.
Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules as platform needs evolve.
- Stakeholder Enablement, Training & Vendor Management
Develop dashboards using the CrowdStrike API to collect daily vulnerability data, and other key metrics, providing clear and actionable visibility into the enterprise environment.
Develop standardized operating procedures (SOPs), deployment guides, and platform hardening specifications for state agency IT partners.
Serve as the primary technical point of contact with CrowdStrike engineering and technical account managers (TAMs) to drive feature requests and resolve critical bugs.
Provide formal and informal technical mentoring and training to Tier 1/2 SOC staff.
Required Technical Experience:
Platform Mastery: 4 years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000 endpoints).
Tier 3 IR Capabilities: Demonstrated proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting.
OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated remediation and API integration.
Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping.
Required Certifications (Must hold at least one active certification)
CrowdStrike Specific (Highly Preferred):
CrowdStrike Certified Falcon Administrator (CCFA)
CrowdStrike Certified Falcon Responder (CCFR)
CrowdStrike Certified Falcon Hunter (CCFH)
Industry Certifications:
CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.
Professional & Soft Skills:
Integrity & Ethics: Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations.
Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly.
Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments, agency-specific constraints, and conflicting operational priorities.
Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team-oriented working environment.
Preferred Qualifications:
Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.
Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).
Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).
Skill Matrix:
Skill
Required / Desired
Amount
of Experience
Industry Certifications: CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.
Required
Years
Required Certifications (must hold at least one active CrowdStrike specific certification):
Required
Years
CrowdStrike Certified Falcon Administrator (CCFA); CrowdStrike Certified Falcon Responder (CCFR); CrowdStrike Certified Falcon Hunter (CCFH)
Required
Platform Mastery: 4 years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000 endpoints).
Required
Years
Tier 3 IR Capabilities: Proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting
Required
Years
OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated...
Required
automated remediation and API integration.