Senior SOC Detection Engineer – CrowdStrike Falcon & SOAR / AI
Client: State of Texas
Location: Austin, TX – Remote within Texas
Duration: 12 Months + Extension
Interview: Team Interview
Work Authorization: Must be authorized to work in the U.S.
Candidate Location: Texas Residents Only – No Out-of-State or Relocation Candidates
IMPORTANT REQUIREMENT
Candidates must have a minimum of 2+ years of experience working in government, legal, law-enforcement, or law-enforcement-adjacent security environments.
Position Overview
The State of Texas is seeking a Senior SOC Detection Engineer with strong hands-on experience in CrowdStrike Falcon, SOAR automation, detection engineering, threat hunting, incident response, and AI/LLM-assisted security operations.
The ideal candidate will have Tier 3/Senior SOC experience and the ability to develop custom detections, automate security workflows, conduct forensic investigations, and support advanced security operations in a highly regulated environment.
Key Responsibilities
- Develop, tune, maintain, and optimize CrowdStrike Falcon detections and Indicators of Attack (IOAs).
- Work extensively with CrowdStrike Falcon Insight XDR, Discover, and Fusion SOAR.
- Develop and utilize Falcon Query Language (FQL) for threat hunting, detection engineering, investigations, and analytics.
- Build and maintain SOAR automation workflows, with Torq experience strongly preferred.
- Develop security automation and integrations using Python, PowerShell, FQL, APIs, and other scripting technologies.
- Conduct advanced threat hunting and forensic investigations of cybersecurity incidents and attacks.
- Determine attack vectors, root causes, indicators of compromise, and recommendations for preventing recurrence.
- Create detailed hunt reports, incident reports, investigation documentation, runbooks, and technical security documentation.
- Design and maintain dashboards and security analytics supporting SOC operations.
- Leverage AI/LLM technologies such as GPT-based tools and Claude to improve SOC efficiency, detection engineering, investigation, and automation.
- Design AI-assisted playbooks and analyst copilots while maintaining strict data sanitization, privacy, and security controls.
- Apply appropriate data-handling safeguards when using AI tools in regulated environments.
- Support Zero Trust security architecture initiatives based on NIST SP 800-207 principles.
- Develop, review, and update security policies, procedures, standards, and technical controls across public, private, and hybrid cloud environments.
- Collaborate with cybersecurity, infrastructure, application, compliance, and other cross-functional teams.
- Communicate complex technical findings clearly to both technical and non-technical audiences.
- Troubleshoot and resolve complex cybersecurity issues across decentralized and diverse environments.
- Research, evaluate, communicate, and help implement emerging security technologies.
Regulatory / Compliance Knowledge
Candidates should have familiarity with regulated security environments and frameworks including:
- IRS Publication 1075
- FBI CJIS Security Policy
- HIPAA
- NIST Zero Trust Architecture – SP 800-207
Required Experience
- Progressive SOC / Security Operations experience.
- 2+ years at Tier 3 / Senior SOC Analyst / Detection Engineering level.
- 2+ years in government, legal, law-enforcement, or law-enforcement-adjacent security environments.
- Hands-on production experience with CrowdStrike Falcon.
- Experience authoring custom detections/IOAs and using FQL.
- Experience developing or maintaining SOAR automation.
- Hands-on experience with AI/LLM tools supporting cybersecurity operations.
- Strong scripting and automation experience using Python, PowerShell, or FQL-based automation.
- Experience conducting forensic investigations and advanced threat hunting.
- Experience documenting investigations and communicating technical findings.
- Experience creating or updating security policies and standards.
- Ability to work independently and effectively within cross-functional cybersecurity teams.
Education & Certifications
Education:
- Bachelor''s degree in Computer Science, Information Security, Cybersecurity, or related field preferred.
- Equivalent professional experience may be considered.
Preferred Certifications:
- GIAC certifications such as GCIH, GCIA, FA, or equivalent.
- CrowdStrike Certified Falcon Responder (CCFR) or CrowdStrike Certified Falcon Administrator (CCFA), or equivalent CrowdStrike certification.
- Torq certification or demonstrated portfolio of SOAR automation workflows.