CrowdStrike SOC Analyst

Remote • Posted 1 hour ago • Updated 54 minutes ago
Contract Corp To Corp
Contract W2
Contract Independent
12 Months
No Travel Required
Remote
Depends on Experience
Fitment

Dice Job Match Score™

👤 Reviewing your profile...

Job Details

Skills

  • SOC / security operations
  • CrowdStrike Falcon (Insight XDR/ Discover/ Fusion SOAR) / Falcon Query Language (FQL)
  • Building or maintaining SOAR automation (Torq)
  • AI/LLM tools (Claude/ GPT-based tools)
  • Zero Trust architecture principles (NIST 800-207) / IRS Pub 1075/ FBI CJIS Policy/ HIPAA
  • GIAC certifications / CrowdStrike security certification

Summary

DirectClient: Office of the Attorney General of Texas(OAG)
Solicitation Number: 302CSD2702
Title: CrowdStrike SOC Analyst
Location: 5500 E. Oltorf St, Austin, TX 78741
Duration: 9/1/2026 to 8/31/2027 with possible extension
Last date for submission: August 11 2026 (12.00 PM-CST)
 
Important Note: The working position is Telework. Texas local candidates only.

DESCRIPTION OF SERVICES:
The Office of the Attorney General (OAG) is seeking a senior-level Security Operations Analyst to strengthen detection, response, and orchestration capabilities across the agency''''''''s security operations. This role blends deep SOC (Security Operations Center) investigative expertise with hands-on security automation engineering, focusing on CrowdStrike Falcon and Torq to build scalable, AI-assisted detection and response workflows. The ideal candidate has practical experience integrating large language model (LLM) tools such as Claude into security operations — for triage acceleration, playbook generation, and analyst augmentation — while operating within a strict Zero Trust, defense-in-depth security posture appropriate to a state Attorney General''''''''s office.
 
Key Responsibilities
•    Serve as a SOC analysis & Tier 3 escalation point for complex security incidents, performing deep-dive investigation, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.
•    Design, build, and maintain detection analytics, dashboards, and hunting queries (Falcon Query Language / FQL) within CrowdStrike Falcon, tuning correlation rules and detection logic to reduce false positives and improve mean-time-to-detect (MTTD).
•    Architect and maintain security orchestration, automation, and response (SOAR) playbooks in Torq, integrating CrowdStrike Falcon, identity providers, ticketing, and communication platforms into automated response workflows.
•    Design AI-assisted analyst workflows (e.g., automated triage summarization, alert enrichment, playbook drafting) using approved generative AI tooling, ensuring all inputs are sanitized and free of regulated or case-specific data.
•    Lead incident response efforts for high-severity events, coordinating with IT, legal, and divisional stakeholders while strictly adhering to FTI/CJI handling restrictions.
•    Develop and maintain detection engineering documentation, runbooks, and standard operating procedures (SOPs) for Tier 1/Tier 2 analyst use.
•    Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts; review and validate their investigative work and escalation quality.
•    Continuously evaluate and integrate emerging SOC automation and AI capabilities, presenting proposals for tooling changes with documented risk and compliance analysis.
•    Participate in an on-call rotation for critical incident escalations.
 
The above job description and requirements are general in nature and may be subject to change based on the specific needs and requirements of the organization and project.

CANDIDATE SKILLS AND QUALIFICATIONS
Minimum Requirements:
Years    Required/Preferred    Experience
8    Required    Progressive SOC / security operations experience, including 2+ years functioning at a Tier 3 / senior analyst or detection engineering level.
8    Required    Hands-on production experience with CrowdStrike Falcon (Insight XDR, Discover, and/or Fusion SOAR), including custom detection/IOA authoring, Falcon Query Language (FQL) use, and dashboard development.
8    Required    Demonstrated experience building or maintaining SOAR automation (Torq strongly preferred)
8    Required    Practical, hands-on experience using AI/LLM tools (e.g., Claude, GPT-based tools) to support security operations, with clear understanding of data sanitization and safe-use boundaries in a regulated environment.
8    Required    Working knowledge of Zero Trust architecture principles (NIST 800-207) and general familiarity with regulatory frameworks such as IRS Pub. 1075, FBI CJIS Policy, and HIPAA.
8    Required    Strong scripting/automation ability (PowerShell, Python, or Falcon Query Language-based automation) for building custom detections and integrations.
8    Required    Excellent written communication skills for incident reporting, runbook authorship, and cross-divisional coordination.
8    Required    Experience documenting investigations, creating hunt reports, and communicating technical findings to diverse audiences.
8    Required    Strong analytical, problem-solving, and critical-thinking skills
8    Required    Ability to work independently while collaborating effectively within cross-functional cybersecurity teams.
8    Required    Ability to resolve complex security issues in diverse and decentralized environments; learn, communicate, teach new security technologies; and communicate effectively.
8    Required    Conduct forensic investigations on cyberattacks to determine how they occurred and can be prevented in the future.
8    Required    Experience creating/reviewing/updating security policies and standards for the public/private/hybrid cloud contexts.
4    Required    Bachelor''''''''s degree in Computer Science, Information Security, or related field, or equivalent professional experience.
1    Preferred    GIAC certifications (GCIH, GCIA, GCFA) or equivalent.
1    Preferred    CrowdStrike Certified Falcon Responder (CCFR) or CrowdStrike Certified Falcon Administrator (CCFA), or equivalent CrowdStrike security certification.
1    Preferred    Torq certification or demonstrated portfolio of built automation workflows
1    Preferred    Experience designing AI-assisted playbooks or analyst copilots for SOC use cases while maintaining strict data-handling guardrails.
1    Preferred    Familiarity with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One / cloud security posture management (CSPM) tooling.
1    Preferred    Experience in government, legal, or law-enforcement-adjacent security environments

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10283077
  • Position Id: 302CSD2702
  • Posted 1 hour ago
Contact the job poster
Anki Kantheti

Anki Kantheti

Recruitment Lead @ Bansar Technologies Inc.
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

Today

Easy Apply

Contract, Third Party

$90 - $95

Remote

14d ago

Easy Apply

Third Party, Contract

Depends on Experience

Remote

Today

Easy Apply

Contract, Third Party

Remote

23d ago

Easy Apply

Contract

Depends on Experience

Search all similar jobs