Detection Engineering & SOAR Architect Hybrid - US

Detection Engineering & SOAR Architect

Full Time • Hybrid - US
Location
Austin, TX

Experience Level
Senior Level (8 or more years of experience)

Role Overview
The Senior Security Operations Analyst strengthens detection, response, and orchestration capabilities across enterprise security operations. This role combines Tier 3 SOC investigation expertise with hands-on security automation engineering, focusing on CrowdStrike Falcon and Torq to build scalable, AI-assisted detection and response workflows. Operating within a strict Zero Trust defense-in-depth security posture, the analyst leverages generative AI tools (such as Claude) for triage acceleration, alert enrichment, and playbook drafting while enforcing rigorous data sanitization in a regulated public sector environment.

Key Responsibilities

SOC Analysis & Threat Hunting
• Serve as a Tier 3 escalation point for complex security incidents, performing deep-dive investigations, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.
• Conduct forensic investigations on cyberattacks to determine attack vectors, scope, and preventive measures.
• Lead incident response efforts for high-severity events, coordinating with IT, legal, and operational leadership.
• Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts, reviewing and validating investigative work and escalation quality.

Detection Engineering & SOAR Automation
• Design, build, and maintain detection analytics, dashboards, and hunting queries using Falcon Query Language (FQL) in CrowdStrike Falcon.
• Tune correlation rules and detection logic to minimize false positives and improve mean-time-to-detect (MTTD).
• Architect and maintain SOAR playbooks in Torq, integrating CrowdStrike Falcon, identity providers, ticketing platforms, and communication channels into automated response workflows.
• Write custom automation scripts using PowerShell, Python, or FQL-based automation for bespoke detections and system integrations.

AI Integration & Governance
• Design AI-assisted analyst workflows (such as automated triage summarization, alert enrichment, and playbook drafting) using approved generative AI tooling.
• Enforce strict data sanitization guardrails to ensure AI prompts and inputs remain free of regulated, sensitive, or case-specific data.
• Continuously evaluate emerging SOC automation and AI capabilities, presenting proposals for tooling updates accompanied by risk and compliance evaluations.
• Develop and maintain detection engineering documentation, runbooks, security policies, and standard operating procedures (SOPs).

Required Qualifications
• Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent professional experience).
• 8 or more years of progressive experience in SOC and security operations, including 2 or more years operating at a Tier 3, senior analyst, or detection engineering level.
• 8 or more years of hands-on production experience with CrowdStrike Falcon (Insight XDR, Discover, Fusion SOAR), including custom IOA authoring, FQL, and dashboard development.
• 8 or more years of experience building or maintaining SOAR automation workflows (Torq preferred).
• 8 or more years of experience utilizing AI/LLM tools (such as Claude or GPT-based tools) to support security operations while adhering to data sanitization boundaries.
• 8 or more years of experience developing automation scripts (PowerShell, Python, or FQL) for detections and tool integrations.
• 8 or more years of experience conducting forensic investigations and documenting findings, hunt reports, and technical runbooks.
• Working knowledge of Zero Trust architecture principles (NIST 800-207) and familiarity with regulatory frameworks (IRS Pub. 1075, FBI CJIS Policy, HIPAA).
• Demonstrated ability to create, review, and update security policies across public, private, and hybrid cloud contexts.

Preferred Qualifications
• Relevant professional security certifications, such as GIAC (GCIH, GCIA, GCFA), CrowdStrike certifications (CCFR, CCFA), or Torq certifications.
• Experience designing AI-assisted playbooks or analyst copilots within SOC environments while enforcing data-handling guardrails.
• Experience supporting security operations in government, legal, or law enforcement-adjacent organizations.
• Familiarity with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One / Cloud Security Posture Management (CSPM) tooling.

Core Skills & Attributes
• Exceptional analytical, problem-solving, and critical-thinking skills for complex incident resolution.
• Strong written and verbal communication skills to present technical findings to diverse technical and executive audiences.
• Ability to work independently with high self-sufficiency while collaborating effectively in cross-functional cybersecurity teams.
• Ability to teach, mentor, and communicate new security technologies to team members.

Flexible work from home options available.





(if you already have a resume on Indeed)

Or apply here.

* required fields

Location
Or
Or
If no code provided, add their name instead.
Privacy Policy