Role: CrowdStrike Architect
Duration: 10 Months
Location: Des Moines, IA
Work Mode: Remote
CrowdStrike Architect serves as the primary technical authority for the our Client Enterprise Endpoint Detection and Response (EDR / XDR) platform. Operating within the Information Security Services (ISS) Bureau, this role is responsible for the overall architecture, administration, multi-tenant federation, fine-tuning, and escalation engineering of the CrowdStrike Falcon ecosystem across state agencies.
Required Technical Experience
- Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).
- Tier 3 IR Capabilities: Demonstrated proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting.
- OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated remediation and API integration.
- Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management, vulnerability assessments, and MITRE ATT&CK framework mapping.
Required Certifications (Must hold at least one active certification)
• CrowdStrike Specific (Highly Preferred):
• CrowdStrike Certified Falcon Administrator (CCFA)
• CrowdStrike Certified Falcon Responder (CCFR)
• CrowdStrike Certified Falcon Hunter (CCFH)
Industry Certifications:
• CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.
Professional & Soft Skills
- Integrity & Ethics: Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations.
- Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly.
- Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments, agency-specific constraints, and conflicting operational priorities.
- Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team-oriented working environment.
Preferred Qualifications
• Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.
• Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).
• Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).
Required Skill
Industry Certifications: CISSP, GCFA, GCIH, GSEC, CISA, or equivalent advanced security credential.
Required Certifications (must hold at least one active CrowdStrike specific certification):
CrowdStrike Certified Falcon Administrator (CCFA); CrowdStrike Certified Falcon Responder (CCFR); CrowdStrike Certified Falcon Hunter (CCFH)
Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale (10,000+ endpoints).
Tier 3 IR Capabilities: Proficiency using CrowdStrike Real-Time Response (RTR), writing custom IOAs/IOCs, and performing endpoint threat hunting
OS & Scripting: Strong knowledge of Windows, Linux, and macOS internals, along with scripting capabilities (PowerShell, Python, Bash) for automated...
automated remediation and API integration.
Security Ecosystems: Solid grasp of network security (firewalls, IDS/IPS), Identity & Access Management (AD/Entra ID), patch management,
vulnerability assessments, and MITRE ATT&CK framework mapping.
Integrity & Ethics: Unwavering commitment to confidentiality, integrity, and compliance standards necessary for state government operations.
Communication & Translation: Proven ability to explain technical risk to non-technical stakeholders and state agency leaders clearly.
Complex Problem Solving: High analytical capability to navigate complex multi-tenant environments, agency-specific constraints, and conflicting...
operational policies
Collaboration & Inclusion: Strong interpersonal skills with a commitment to fostering a diverse, supportive, and team-oriented working environment.
Prior experience in state/local government (SLTT), higher education, or large-scale multi-tenant enterprise environments.
Experience integrating CrowdStrike Falcon APIs with external automation platforms or SIEMs (e.g., Splunk, Microsoft Sentinel, Palo Alto Cortex).
Familiarity with federal/state compliance frameworks (NIST SP 800-53, CJIS, HIPAA, IRS Pub 1075).