Bluebix
All jobs
B

Senior Tier 3 CroudStrike Architect

Bluebix Solutions

Des Moines, IowaSeniorAug 18, 2026

About the role

Role: Senior Tier 3 Croud Strike Architect

Location: Des Moines, IA (Remote)

Agency Interview Type: Either Web Cam or In Person Interview

Visa- USC


Job description:

Key Responsibilities:

Architect and manage CrowdStrike Falcon across 10,000+ endpoints and multiple agency environments.

Manage CID hierarchy, RBAC, policies, sensors, IOAs/IOCs, and platform health.

Handle complex Tier 3 incidents using Real-Time Response (RTR), threat hunting, and forensic techniques.

Integrate CrowdStrike with SIEM/SOAR, threat intelligence, and security tools.

Develop Fusion SOAR workflows, APIs, dashboards, and automation.

Support Windows, Linux, and macOS environments using PowerShell, Python, and Bash.

Develop SOPs, security standards, dashboards, and provide technical mentoring.

Serve as the primary technical contact with CrowdStrike engineering/TAMs.


Required Skills:

4+ years CrowdStrike Falcon enterprise experience.

Strong RTR, IOA/IOC, threat hunting, and Tier 3 incident response experience.

Windows/Linux/macOS and PowerShell, Python, Bash.

Knowledge of AD/Entra ID, network security, vulnerability management, and MITRE ATT&CK.

Experience with SIEM/SOAR and CrowdStrike APIs preferred.

10,000+ endpoint enterprise-scale experience required.


Certification – At Least One Required:

CCFA, CCFR, CCFH, CISSP, GCFA, GCIH, GSEC, or CISA.

Preferred: State/local government or large multi-tenant enterprise experience and familiarity with NIST, CJIS, HIPAA, or IRS 1075.


Skills:

Industry Certifications: CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.

Required Certifications (must hold at least one active CrowdStrike specific certification):

CrowdStrike Certified Falcon Administrator (CCFA); CrowdStrike Certified Falcon Responder (CCFR); CrowdStrike Certified Falcon Hunter (CCFH)

Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).

Tier 3 IR Capabilities: Proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting

OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated.

Automated remediation and API integration.

Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management

vulnerability assessments, and MITRE ATT&CK framework mapping.

Integrity & Ethics: Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations.

Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly.

Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments, agency-specific constraints, and conflicting.

operational policies

Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team-oriented working environment.

Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.

Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).

Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).