Detection Engineering & SOAR Architect (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Detection Engineering & SOAR Architect (Cybersecurity): Building scalable detection, response, and orchestration workflows with an accent on CrowdStrike Falcon, Torq, threat hunting, and AI-assisted SOC operations. Focus on investigating complex incidents, designing automated playbooks, developing detection analytics, and enforcing data-sanitization controls in a regulated public-sector environment.
Location: Hybrid in Austin, Texas, United States; flexible work-from-home options are available.
Company
is a technology and professional services firm established in 2004, specializing in innovative technology solutions and nationwide technology management.
What you will do
- Act as a Tier 3 escalation point for complex incidents, conducting deep investigations, root cause analysis, threat hunting, and forensic assessments.
- Lead high-severity incident response efforts and coordinate with IT, legal, and operational stakeholders.
- Design and maintain CrowdStrike Falcon detection analytics, dashboards, hunting queries, correlation rules, and custom IOAs.
- Architect Torq SOAR playbooks integrating endpoint, identity, ticketing, and communication platforms.
- Develop PowerShell, Python, and FQL automation for detections and system integrations.
- Build AI-assisted triage, enrichment, and playbook-drafting workflows while enforcing data-sanitization guardrails and maintaining security documentation.
Requirements
- Senior-level experience: 8+ years in SOC and security operations, including 2+ years at Tier 3, senior analyst, or detection engineering level.
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent professional experience.
- 8+ years of production experience with CrowdStrike Falcon, including Insight XDR, Discover, Fusion SOAR, FQL, custom IOA authoring, and dashboard development.
- 8+ years of experience with SOAR workflows, AI/LLM tools, automation scripting, forensic investigations, and technical security documentation.
- Working knowledge of Zero Trust principles, NIST 800-207, and regulatory frameworks including IRS Pub. 1075, FBI CJIS Policy, and HIPAA.
- Must work in a hybrid arrangement in Austin, Texas, United States.
Nice to have
- GIAC, CrowdStrike, or Torq certifications.
- Experience designing AI-assisted SOC playbooks or analyst copilots with data-handling guardrails.
- Experience supporting government, legal, or law-enforcement-adjacent organizations.
- Familiarity with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One or CSPM tools.
Culture & Benefits
- Flexible work-from-home options within a hybrid work model.
- Cross-functional collaboration with cybersecurity, IT, legal, and operational teams.
- Opportunities to mentor SOC analysts and communicate emerging security technologies.
- Work focused on regulated public-sector security operations and defense-in-depth practices.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →