COOLSOFT logo

CISSP GCIH CISA API Hipaa Architect

COOLSOFT

Des Moines, IARemoteContractNo compensation foundTracked 3 days agoSeen in employer's feed 3 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
Des Moines, IARemote
Schedule
Contract
Work Authorization
Not specified

Job overview

The Architect role serves as the highest level of technical escalation for endpoint incidents, advanced threat hunting, and complex integrations. It leads platform architecture, multi‑tenant administration, and integration of CrowdStrike Falcon with SIEM/SOAR tools, while providing stakeholder training and vendor management for the State of Iowa’s enterprise security program.

Skills & qualifications

RequiredNice to have

Skills

CrowdStrike FalconSIEMSOARAPI HipaaThreat HuntingIncident ResponseReal‑Time ResponseFusion

Qualifications

CISSPGCIHCISA4+ Years CrowdStrike Falcon Experience

Full job description

CISSP GCIH CISA API Hipaa Architect

(Jobs in Des Moines, IA)

Requirement id 158922

Job title Architect

Job location in Des Moines, IA

Skills required CISSP, GCIH, CISA, API Hipaa

Open Date 18-Aug-2026

Close Date

Job type Contract

Duration 9 Months

Compensation DOE

Status requirement ---

Job interview type ---

Email Recruiter:coolsoft

Job Description Architect: CISSP, GCIH, CISA, API Hipaa

Start Date: 09/14/2026

End Date: 06/30/2027

Submission Deadline: 09/20/2026

Client info: 1084 LGRF Endpoint Detection and Response Platform

Note:

*Remote

*8am - 4:30pm CST; M-F

*Either Web Cam or In Person Interview

Description:

This position acts as the highest level of technical escalation (Tier 3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations (such as Next-Gen SIEM, threat intelligence, and automated orchestration).

The Senior Tier 3 CrowdStrike Architect serves as the primary technical authority for the State of Iowas Enterprise Endpoint Detection and Response (EDR / XDR) platform. Operating within the Information Security Services (ISS) Bureau, this role is responsible for the overall architecture, administration, multi-tenant federation, fine-tuning, and escalation engineering of the CrowdStrike Falcon ecosystem across state agencies.

This position acts as the highest level of technical escalation (Tier 3) for endpoint incidents, advanced threat hunting, platform troubleshooting, and complex integrations (such as Next-Gen SIEM, threat intelligence, and automated orchestration).

  1. Platform Architecture & Multi-Tenant Administration
  • Architect, implement, and maintain the state-wide CrowdStrike Falcon platform architecture across multi-tenant environments (CID hierarchy, RBAC, policy groups).

  • Oversee sensor deployment strategies, policy prevention/detection tuning, custom rule creation (IOAs/IOCs), and feature rollout schedules across diverse agency environments.

  • Manage CrowdStrike platform health, agent updates, host group management, and agent troubleshooting across Windows, macOS, Linux, and virtualized workloads.

  1. Tier 3 Incident Escalation & Response Engineering
  • Act as the final technical escalation point for complex endpoint threats, zero-day vulnerabilities, and persistent malware identified by Tier 1/2 SOC analysts.

  • Execute advanced containment, remediation, and live forensics using Real-Time Response (RTR) and custom scripts during critical incidents.

  • Partner with SOC Analysts and Incident Response teams to refine playbooks, minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), and drive risk reduction.

  1. Integration, Automation & Data Pipeline
  • Design and support telemetry integration between CrowdStrike Falcon, central SIEM/SOAR platforms, network defenses, and threat intelligence feeds.

  • Introduce new integration ideas to better levergage existing security tools.

  • Leverage CrowdStrike Fusion SOAR workflows to automate routine containment, notifications, and response actions.

  • Align endpoint security strategies with Identity Threat Detection and Response (ITDR) and Cloud Security Posture Management (CSPM) modules as platform needs evolve.

  1. Stakeholder Enablement, Training & Vendor Management
  • Translate complex technical threat data into actionable guidance for agency IT administrators and executive leadership.

  • Develop dashboards using the CrowdStrike API to collect daily vulnerability data, and other key metrics, providing clear and actionable visibility into the enterprise environment.

  • Develop standardized operating procedures (SOPs), deployment guides, and platform hardening specifications for state agency IT partners.

  • Serve as the primary technical point of contact with CrowdStrike engineering and technical account managers (TAMs) to drive feature requests and resolve critical bugs.

  • Provide formal and informal technical mentoring and training to Tier 1/2 SOC staff.

Required Technical Experience

  • Platform Mastery: 4+ years of hands-on experience engineering, deploying, and maintaining CrowdStrike Falcon at enterprise scale

Call502-379-4456 Ext 100for more details. Please provide Requirement id: 158922 while calling.

EOE Protected Veterans/Disability

You've read the whole posting — now see how you match it.