Senior SOC Detection Engineer – CrowdStrike Falcon & SOAR / AI

Hybrid in Manor, TX, US • Posted 13 hours ago • Updated 13 hours ago
Contract Independent
Contract W2
Contract Corp To Corp
12 Months
No Travel Required
Hybrid
Depends on Experience
Fitment

Dice Job Match Score™

⏳ Almost there, hang tight...

Job Details

Skills

  • CrowdStrike Falcon
  • Falcon Insight XDR
  • Falcon Discover
  • Falcon Fusion SOAR
  • Falcon Query Language (FQL)
  • Custom Detection / IOA Development
  • SOAR Automation
  • Torq
  • Python
  • PowerShell
  • Threat Hunting
  • Incident Response
  • Digital/Forensic Investigation
  • Security Automation & Integrations
  • AI / LLM Security Operations
  • GPT-based Tools
  • Claude
  • Zero Trust
  • NIST 800-207
  • Microsoft Defender XDR
  • Splunk
  • Microsoft Entra ID Protection
  • Tenable One
  • CSPM

Summary

Senior SOC Detection Engineer – CrowdStrike Falcon & SOAR / AI

Client: State of Texas
Location: Austin, TX – Remote within Texas
Duration: 12 Months + Extension
Interview: Team Interview
Work Authorization: Must be authorized to work in the U.S.
Candidate Location: Texas Residents Only – No Out-of-State or Relocation Candidates

IMPORTANT REQUIREMENT

Candidates must have a minimum of 2+ years of experience working in government, legal, law-enforcement, or law-enforcement-adjacent security environments.

Position Overview

The State of Texas is seeking a Senior SOC Detection Engineer with strong hands-on experience in CrowdStrike Falcon, SOAR automation, detection engineering, threat hunting, incident response, and AI/LLM-assisted security operations.

The ideal candidate will have Tier 3/Senior SOC experience and the ability to develop custom detections, automate security workflows, conduct forensic investigations, and support advanced security operations in a highly regulated environment.

Key Responsibilities

  • Develop, tune, maintain, and optimize CrowdStrike Falcon detections and Indicators of Attack (IOAs).
  • Work extensively with CrowdStrike Falcon Insight XDR, Discover, and Fusion SOAR.
  • Develop and utilize Falcon Query Language (FQL) for threat hunting, detection engineering, investigations, and analytics.
  • Build and maintain SOAR automation workflows, with Torq experience strongly preferred.
  • Develop security automation and integrations using Python, PowerShell, FQL, APIs, and other scripting technologies.
  • Conduct advanced threat hunting and forensic investigations of cybersecurity incidents and attacks.
  • Determine attack vectors, root causes, indicators of compromise, and recommendations for preventing recurrence.
  • Create detailed hunt reports, incident reports, investigation documentation, runbooks, and technical security documentation.
  • Design and maintain dashboards and security analytics supporting SOC operations.
  • Leverage AI/LLM technologies such as GPT-based tools and Claude to improve SOC efficiency, detection engineering, investigation, and automation.
  • Design AI-assisted playbooks and analyst copilots while maintaining strict data sanitization, privacy, and security controls.
  • Apply appropriate data-handling safeguards when using AI tools in regulated environments.
  • Support Zero Trust security architecture initiatives based on NIST SP 800-207 principles.
  • Develop, review, and update security policies, procedures, standards, and technical controls across public, private, and hybrid cloud environments.
  • Collaborate with cybersecurity, infrastructure, application, compliance, and other cross-functional teams.
  • Communicate complex technical findings clearly to both technical and non-technical audiences.
  • Troubleshoot and resolve complex cybersecurity issues across decentralized and diverse environments.
  • Research, evaluate, communicate, and help implement emerging security technologies.

 

Regulatory / Compliance Knowledge

Candidates should have familiarity with regulated security environments and frameworks including:

  • IRS Publication 1075
  • FBI CJIS Security Policy
  • HIPAA
  • NIST Zero Trust Architecture – SP 800-207

Required Experience

  • Progressive SOC / Security Operations experience.
  • 2+ years at Tier 3 / Senior SOC Analyst / Detection Engineering level.
  • 2+ years in government, legal, law-enforcement, or law-enforcement-adjacent security environments.
  • Hands-on production experience with CrowdStrike Falcon.
  • Experience authoring custom detections/IOAs and using FQL.
  • Experience developing or maintaining SOAR automation.
  • Hands-on experience with AI/LLM tools supporting cybersecurity operations.
  • Strong scripting and automation experience using Python, PowerShell, or FQL-based automation.
  • Experience conducting forensic investigations and advanced threat hunting.
  • Experience documenting investigations and communicating technical findings.
  • Experience creating or updating security policies and standards.
  • Ability to work independently and effectively within cross-functional cybersecurity teams.

Education & Certifications

Education:

  • Bachelor''s degree in Computer Science, Information Security, Cybersecurity, or related field preferred.
  • Equivalent professional experience may be considered.

Preferred Certifications:

  • GIAC certifications such as GCIH, GCIA, FA, or equivalent.
  • CrowdStrike Certified Falcon Responder (CCFR) or CrowdStrike Certified Falcon Administrator (CCFA), or equivalent CrowdStrike certification.
  • Torq certification or demonstrated portfolio of SOAR automation workflows.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 90979441
  • Position Id: 9050520
  • Posted 13 hours ago
Contact the job poster
Srini Rao

Srini Rao

Recruiter @ Conquest Consulting
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Austin, Texas

3d ago

Easy Apply

Contract, Third Party

Depends on Experience

Remote or Manor, Texas

Today

Easy Apply

Third Party, Contract

65 - 70

Austin, Texas

Today

Contract

Hourly

Austin, Texas

Today

Full-time

USD 10,834.00 - 12,500.00 per month

Search all similar jobs