Haystack
← Back to Jobs
Other
KB

CrowdStrike Architect /(809272)

Key Business Solutions, Inc.Des Moines, IA🇺🇸United StatesPosted 20 Aug 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Des Moines, IA, United States
Posted
21 hours ago
SplunkBashComplianceData PipelineHIPAAPowerShellPythonSchedulingVendor Management

Job Description

CrowdStrike Architect /(809272)

Des Moines, IA

Duration: Long term

 

Description:

The Senior Tier 3 CrowdStrike Architect serves as the primary technical authority for the State of Iowa’s Enterprise Endpoint Detection and Response (EDR / XDR) platform. Operating within the Information Security Services (ISS) Bureau, this role is responsible for the overall architecture, administration, multi-tenant federation, fine-tuning, and escalation engineering of the CrowdStrike Falcon ecosystem across state agencies.

This position acts as the highest level of technical escalation (Tier 3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations (such as Next-Gen SIEM, threat intelligence, and automated orchestration).

 

1. Platform Architecture & Multi-Tenant Administration

 

             Architect, implement, and maintain the state-wide CrowdStrike Falcon platform architecture across multi-tenant environments (CID hierarchy, RBAC, policy groups).

 

             Oversee sensor deployment strategies, policy prevention/detection tuning, custom rule creation (IOAs/IOCs), and feature rollout schedules across diverse agency environments.

 

             Manage CrowdStrike platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads.

 

2. Tier 3 Incident Escalation & Response Engineering

 

             Act as the final technical escalation point for complex endpoint threats, zero-day vulnerabilities, and persistent malware identified by Tier 1/2 SOC analysts.

 

             Execute advanced containment, remediation, and live forensics using Real-Time Response (RTR) and custom scripts during critical incidents.

 

             Partner with SOC Analysts and Incident Response teams to refine playbooks, minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk reduction.

 

3. Integration, Automation & Data Pipeline

 

             Design and support telemetry integration between CrowdStrike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds.

 

             Introduce new integration ideas to better levergage existing security tools.

 

             Leverage CrowdStrike Fusion SOAR workflows to automate routine containment, notifications, and response actions.

 

             Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules as platform needs evolve.

 

4. Stakeholder Enablement, Training & Vendor Management

 

             Translate complex technical threat data into actionable guidance for agency IT administrators and executive leadership.

 

             Develop dashboards using the CrowdStrike API to collect daily vulnerability data, and other key metrics, providing clear and actionable visibility into the enterprise environment.

 

             Develop standardized operating procedures (SOPs), deployment guides, and platform hardening specifications for state agency IT partners.

 

             Serve as the primary technical point of contact with CrowdStrike engineering and technical account managers (TAMs) to drive feature requests and resolve critical bugs.

 

             Provide formal and informal technical mentoring and training to Tier 1/2 SOC staff.

 

 

 

 

 

Required Technical Experience

 

             Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).

 

             Tier 3 IR Capabilities: Demonstrated proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting.

 

             OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated remediation and API integration.

 

             Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping.

 

Required Certifications (Must hold at least one active certification)

 

             CrowdStrike Specific (Highly Preferred):

 

           CrowdStrike Certified Falcon Administrator (CCFA)

 

           CrowdStrike Certified Falcon Responder (CCFR)

 

           CrowdStrike Certified Falcon Hunter (CCFH)

 

             Industry Certifications:

 

           CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.

 

Professional & Soft Skills

 

             Integrity & Ethics: Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations.

 

             Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly.

 

             Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments, agency-specific constraints, and conflicting operational priorities.

 

             Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team-oriented working environment.

 

Preferred Qualifications

 

             Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.

 

             Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).

 

             Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).

 

Required:

Skill

Required / Desired

Amount

of Experience

Industry Certifications: CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.

Required

4

Years

Required Certifications (must hold at least one active CrowdStrike specific certification):

Required

4

Years

CrowdStrike Certified Falcon Administrator (CCFA); CrowdStrike Certified Falcon Responder (CCFR); CrowdStrike Certified Falcon Hunter (CCFH)

Required

 

 

Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).

Required

4

Years

Tier 3 IR Capabilities: Proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting

Required

4

Years

OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated...

Required

 

 

automated remediation and API integration.

Required

4

Years

Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management,

Required

 

 

vulnerability assessments, and MITRE ATT&CK framework mapping.

Required

4

Years

Integrity & Ethics: Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations.

Required

7

Years

Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly.

Required

7

Years

Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments, agency-specific constraints, and conflicting...

Required

 

 

operational policies

Required

7

Years

Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team-oriented working environment.

Required

7

Years

Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.

Highly desired

 

 

Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).

Highly desired

 

 

Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).

Highly desired

 

 

Questions

Description

Question 1

The Contractor must report any disciplinary action, misdemeanor or felony convictions to the State for any temporary IT staff provided. Do you agree to this requirement?

Question 2

Absences greater than two weeks MUST be approved by CAI Management in advance, and contact information must be provided to CAI so that a resource can be reached during his or her absence. The client has the right to dismiss the resource if she or he does not return to work by the agreed upon date. Do you accept this requirement?

Question 3

Please list candidate''s email address.

Question 5

PROVIDE CANDIDIDATES CURRENT LOCATION (CITY/STATE) HERE:

Question 6

SHOW YOUR WORK - In the summary of qualifications field under the details tab of the candidate''s profile, you should explain why your candidate is the best fit for this position.

Question 7

Use of AI is Strictly Prohibited: Please be advised that the use of AI-generated responses during screenings and interviews is strictly prohibited. Confirm that your candidate has been informed of this policy and agrees to adhere to it. Non-compliance will result in disqualification from the interview process.

Question 8

Background Check Requirements: DOM contractor personnel are required to undergo additional background check investigations (run by DOM) before starting, requiring the completion of several waiver forms & fingerprint processes. The selected candidate will be responsible for completing all the necessary waiver forms, scheduling and completing the fingerprinting process, and returning all completed items to DOM for processing. This is in addition to the National Criminal and Sex Offender check that the vendor

Question 9

Provide candidates with the complete physical address where the DOM DoIT Background Check form and fingerprint cards must be mailed. [REQUIRED] - Failure to provide accurate information will result in disqualification.

Question 10

INTERVIEW DATES: Interviews will be conducted on [August 24, 25, 26] Only submit candidates available for interviews on the date(s) provided.

 

Similar jobs