Title: CroudStrike Architect
Location: Des Moines, IA 50309- Remote
Duration: 12+ Months
Short Description
- This position acts as the highest level of technical escalation (Tier 3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations (such as Next-Gen SIEM, threat intelligence, and automated orchestration).
Complete Description
- The Senior Tier 3 CrowdStrike Architect serves as the primary technical authority for the State of Iowa’s Enterprise Endpoint Detection and Response (EDR / XDR) platform. Operating within the Information Security Services (ISS) Bureau, this role is responsible for the overall architecture, administration, multi-tenant federation, fine-tuning, and escalation engineering of the CrowdStrike Falcon ecosystem across state agencies.
- This position acts as the highest level of technical escalation (Tier 3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations (such as Next-Gen SIEM, threat intelligence, and automated orchestration).
- Platform Architecture & Multi-Tenant Administration
- Architect, implement, and maintain the state-wide CrowdStrike Falcon platform architecture across multi-tenant environments (CID hierarchy, RBAC, policy groups).
- Oversee sensor deployment strategies, policy prevention/detection tuning, custom rule creation (IOAs/IOCs), and feature rollout schedules across diverse agency environments.
- Manage CrowdStrike platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads.
- Tier 3 Incident Escalation & Response Engineering
- Act as the final technical escalation point for complex endpoint threats, zero-day vulnerabilities, and persistent malware identified by Tier 1/2 SOC analysts.
- Execute advanced containment, remediation, and live forensics using Real-Time Response (RTR) and custom scripts during critical incidents.
- Partner with SOC Analysts and Incident Response teams to refine playbooks, minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk reduction.
- Integration, Automation & Data Pipeline
- Design and support telemetry integration between CrowdStrike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds.
- Introduce new integration ideas to better levergage existing security tools.
- Leverage CrowdStrike Fusion SOAR workflows to automate routine containment, notifications, and response actions.
- Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules as platform needs evolve.
Required Technical Experience
- Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).
- Tier 3 IR Capabilities: Demonstrated proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting.
- OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated remediation and API integration.
- Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping.
Required Certifications (Must hold at least one active certification)
- CrowdStrike Specific (Highly Preferred):
- CrowdStrike Certified Falcon Administrator (CCFA)
- CrowdStrike Certified Falcon Responder (CCFR)
- CrowdStrike Certified Falcon Hunter (CCFH)
Industry Certifications
- CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.
Preferred Qualifications
- Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.
- Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).
- Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).
"TA01”
Pay: $60.00 - $75.00 per hour
Benefits
Work Location: Remote