1

Cortex Xdr Jobs in Iowa (NOW HIRING)

... Response (EDR / XDR) platform. Responsible for platform architecture, multi-tenant federation ... Alto Cortex). * Familiarity with federal and state compliance frameworks (NIST SP 800-53, CJIS ...

Cortex Xdr information

See Iowa salary details

$69K

$114.6K

$154K

How much do cortex xdr jobs pay per year?

As of Sep 5, 2026, the average yearly pay for cortex xdr in Iowa is $114,597.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,700.00 and $132,400.00 per year, depending on experience, location, and employer.

What is a Cortex XDR?

A Cortex XDR job typically involves working with Palo Alto Networks' Cortex XDR platform to detect, investigate, and respond to cybersecurity threats. Professionals in this role analyze security events, manage endpoint protection, and configure security policies to prevent breaches. They may also work with automation tools, threat intelligence, and forensic analysis to enhance an organization's security posture. Strong knowledge of SIEM, EDR, and incident response methodologies is often required.

What does a Cortex XDR specialist do?

A typical day for a Cortex XDR Specialist involves proactively monitoring security alerts, investigating suspicious activities, and responding to potential incidents using the Cortex XDR platform. Collaboration is frequent, as you’ll work closely with incident response teams, IT staff, and sometimes end users to gather insights and implement mitigation strategies. You may also spend time tuning security policies, preparing threat reports, or participating in tabletop exercises to ensure ongoing readiness. The role is dynamic and requires a balance of technical investigation and clear communication to help protect the organization’s digital assets.

What are the key skills and qualifications needed to thrive in the Cortex XDR position?

To excel as a Cortex XDR Specialist, you need a deep understanding of cybersecurity principles, threat detection, and incident response, often backed by a degree in information security or computer science. Familiarity with Palo Alto Networks Cortex XDR platform, SIEM tools, and certifications such as CISSP or PCNSE are highly valued. Strong analytical thinking, attention to detail, and effective communication skills are essential for interpreting data and collaborating with IT teams. These competencies ensure prompt identification and remediation of security threats, maintaining the organization's cyber resilience.

What are popular job titles related to Cortex Xdr jobs in Iowa?

For Cortex Xdr jobs in Iowa, the most frequently searched job titles are:

What job categories do people searching Cortex Xdr jobs in Iowa look for?

The top searched job categories for Cortex Xdr jobs in Iowa are:

Infographic showing various Cortex Xdr job openings in Iowa as of August 2026, with employment types broken down into 44% Full Time, and 56% Contract. Highlights an 100% In-person job distribution, with an average salary of $114,597 per year, or $55.1 per hour.

CrowdStrike Architect

Ubertal Inc

Des Moines, IA • On-site

Contractor

Posted 17 days ago


Job description

Position Title: Senior CrowdStrike Architect

Location: Des Moines, IA

Engagement Type: Contract

Work Mode: Remote

Duration: ~9.5 Months (09/14/2026 – 06/30/2027)

Interview Type: Webcam or In-Person

Role Overview

Serves as the primary technical authority for an enterprise-wide Endpoint Detection and Response (EDR / XDR) platform. Responsible for platform architecture, multi-tenant federation, administration, fine-tuning, and Tier 3 technical escalation engineering across enterprise environments. Acts as the highest escalation point for complex endpoint threats, threat hunting, platform troubleshooting, and security integrations.

Key Responsibilities
  • Architect, implement, and maintain the enterprise CrowdStrike Falcon platform architecture across multi-tenant environments, managing CID hierarchy, RBAC, and policy groups.

  • Oversee sensor deployment strategies, policy tuning, custom IOA/IOC rule creation, and feature rollout schedules across diverse environments.

  • Maintain platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads.

  • Serve as the final Tier 3 technical escalation point for zero-day vulnerabilities, complex endpoint threats, and persistent malware.

  • Execute live forensics, advanced containment, and remediation using Real-Time Response (RTR) and custom scripts.

  • Partner with SOC Analysts and Incident Response teams to refine playbooks and improve MTTD and MTTR metrics.

  • Design telemetry integrations between CrowdStrike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds.

  • Automate routine containment, notifications, and response actions using CrowdStrike Fusion SOAR workflows.

  • Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules.

  • Develop custom dashboards using CrowdStrike APIs to report daily vulnerability metrics and enterprise security visibility.

  • Standardize operating procedures, deployment guides, and platform hardening specifications.

  • Provide technical mentoring and training to Tier 1 and Tier 2 SOC personnel while liaising with vendor technical teams.

Required Skills & Experience
  • 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).

  • 4+ years of Tier 3 Incident Response experience, including CrowdStrike RTR, writing custom IOAs/IOCs, and endpoint threat hunting.

  • 4+ years of experience with Windows, Linux, and macOS internals, alongside scripting capabilities in PowerShell, Python, or Bash for API integration and automated remediation.

  • 4+ years of experience in network security (firewalls, IDS/IPS), IAM (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping.

  • Must hold at least one active CrowdStrike certification (CCFA, CCFR, CCFH) or an advanced industry security credential (CISSP, GCFA, GCIH, GSEC, CISA, or equivalent).

  • 7+ years of experience demonstrating high ethics/integrity, clear technical communication to non-technical leaders, and complex problem-solving capabilities.

Preferred Skills
  • Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.

  • Hands-on experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).

  • Familiarity with federal and state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).

Additional Details
  • Work Schedule: Monday through Friday, 8:00 AM – 4:30 PM CST.

  • Work Arrangement: Fully remote position based out of Des Moines, IA.