JobTitle -Senior SOC Detection Engineer
Location: Texas – Remote
Work Arrangement: Remote within Texas only
Duration: 12+ Months, Extendable
Interview: Team Interview
Eligibility: Candidates must currently reside in Texas. No out-of-state or relocation candidates.
Position Overview
We are seeking a Senior SOC Detection Engineer with deep experience in advanced SOC operations, detection engineering, incident response, CrowdStrike Falcon, SOAR automation, and AI-assisted security operations.
The ideal candidate will serve as a Tier 3 SOC escalation point, developing advanced detections and threat-hunting capabilities while building automated response workflows using CrowdStrike Falcon and Torq SOAR. Experience applying AI/LLM technologies such as Claude or GPT-based tools to security operations is highly desirable.
Candidates must have 2+ years of experience working in government, legal, law-enforcement-adjacent, or similarly regulated security environments.
Key Responsibilities
· Serve as a Tier 3 SOC escalation point for complex security incidents.
· Perform advanced incident investigation, root cause analysis, threat hunting, and forensic analysis across endpoint, network, cloud, and identity telemetry.
· Develop and maintain detection analytics, dashboards, and hunting queries using CrowdStrike Falcon Query Language (FQL).
· Author and tune custom detections/IOAs and correlation rules to reduce false positives and improve MTTD.
· Design, build, and maintain SOAR playbooks using Torq, integrating CrowdStrike, identity providers, ticketing, and communication platforms.
· Develop AI-assisted SOC workflows for alert triage, enrichment, investigation summarization, and playbook generation.
· Apply strict data-sanitization and security controls when using generative AI/LLM technologies.
· Lead high-severity incident response efforts and coordinate with technical, legal, and business stakeholders.
· Develop cybersecurity runbooks, SOPs, detection engineering documentation, and hunt reports.
· Mentor Tier 1 and Tier 2 SOC analysts and review escalation/investigation quality.
· Evaluate emerging security automation and AI technologies.
· Participate in an on-call rotation for critical security incidents.
Required Qualifications
· Progressive SOC/security operations experience with 2+ years at Tier 3, Senior SOC Analyst, or Detection Engineer level.
· Strong hands-on production experience with CrowdStrike Falcon, including Insight XDR, Discover, and/or Fusion SOAR.
· Experience with custom detection/IOA development, FQL, dashboards, and threat-hunting queries.
· Hands-on experience building or maintaining SOAR automation; Torq strongly preferred.
· Practical experience using AI/LLM tools such as Claude or GPT-based solutions for security operations.
· Strong understanding of AI data-sanitization and safe-use practices in regulated environments.
· Knowledge of Zero Trust architecture and NIST 800-207.
· Familiarity with regulatory/security frameworks including IRS Publication 1075, FBI CJIS Policy, and HIPAA.
· Strong scripting and automation skills using PowerShell, Python, and/or FQL.
· Experience conducting forensic investigations and determining attack root cause.
· Experience creating security policies, standards, runbooks, and SOPs.
· Excellent written and verbal communication skills.
· Strong analytical, problem-solving, and critical-thinking abilities.
· Bachelor''s degree in Computer Science, Information Security, Cybersecurity, or a related field, or equivalent professional experience.
Required Certifications
· GCIH or equivalent – Required
· GCIA or equivalent – Required
· GCFA or equivalent – Required
Highly Preferred Certifications
· CrowdStrike Certified Falcon Responder (CCFR) or equivalent
· CrowdStrike Certified Falcon Administrator (CCFA) or equivalent
· Torq certification