Detection Engineering SOAR Architect

SMART TECH SKILLS LLC

Austin (TX)

Hybrid

USD 120,000 - 170,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible remote options

Job summary

SMART TECH SKILLS LLC in Austin, TX is seeking a Senior Security Operations Analyst to strengthen detection, response, and orchestration across enterprise security operations. This role blends Tier 3 SOC expertise with hands-on automation using CrowdStrike Falcon and Torq, within a strict Zero Trust, regulated public sector environment.

You will lead incident response, develop AI-assisted workflows, and mentor junior analysts while enforcing data sanitization and compliance.

Qualifications

  • Bachelor's degree or equivalent professional experience in information security.
  • 8+ years in SOC/security operations with Tier 3 or senior analyst experience.
  • 8+ years with CrowdStrike Falcon and related SOAR/EDR tooling.
  • 8+ years building SOAR automations (Torq preferred).
  • 8+ years using AI/LLM tools for security operations with data sanitization.
  • Experience developing automation scripts (PowerShell, Python, or FQL).
  • Experience conducting forensic investigations and producing runbooks.

Responsibilities

  • Serve as Tier 3 escalation for complex incidents with deep-dive investigations.
  • Lead incident response for high-severity events coordinating with IT, legal, and leadership.
  • Mentor Tier 1/2 analysts and validate investigations and escalation quality.
  • Design, tune, and maintain detection analytics, dashboards, and hunting queries.
  • Architect and maintain SOAR playbooks integrating CrowdStrike Falcon and identity providers.
  • Write custom automation scripts for detections and system integrations.

Skills

SOC analysis
Threat hunting
Incident response
Automation scripting (PowerShell, Py)
FQL (CrowdStrike)
AI tooling (Claude)
Zero Trust concepts
Security policy writing

Education

Bachelor's degree in Computer Science, Information Security, or related field

Tools

CrowdStrike Falcon
Torq
FQL
PowerShell
Python

Job description

Location Austin, TX

Experience Level Senior Level (8 or more years of experience)

Role Overview The Senior Security Operations Analyst strengthens detection, response, and orchestration capabilities across enterprise security operations. This role combines Tier 3 SOC investigation expertise with hands‑on security automation engineering, focusing on CrowdStrike Falcon and Torq to build scalable, AI‑assisted detection and response workflows. Operating within a strict Zero Trust defense‑in‑depth security posture, the analyst leverages generative AI tools (such as Claude) for triage acceleration, alert enrichment, and playbook drafting while enforcing rigorous data sanitization in a regulated public sector environment.

Key Responsibilities

SOC Analysis & Threat Hunting

  • Serve as a Tier 3 escalation point for complex security incidents, performing deep-dive investigations, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.
  • Conduct forensic investigations on cyberattacks to determine attack vectors, scope, and preventive measures.
  • Lead incident response efforts for high-severity events, coordinating with IT, legal, and operational leadership.
  • Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts, reviewing and validating investigative work and escalation quality.
Detection Engineering & SOAR Automation
  • Design, build, and maintain detection analytics, dashboards, and hunting queries using Falcon Query Language (FQL) in CrowdStrike Falcon.
  • Tune correlation rules and detection logic to minimize false positives and improve mean-time-to-detect (MTTD).
  • Architect and maintain SOAR playbooks in Torq, integrating CrowdStrike Falcon, identity providers, ticketing platforms, and communication channels into automated response workflows.
  • Write custom automation scripts using PowerShell, Python, or FQL-based automation for bespoke detections and system integrations.
AI Integration & Governance
  • Design AI‑assisted analyst workflows (such as automated triage summarization, alert enrichment, and playbook drafting) using approved generative AI tooling.
  • Enforce strict data sanitization guardrails to ensure AI prompts and inputs remain free of regulated, sensitive, or case-specific data.
  • Continuously evaluate emerging SOC automation and AI capabilities, presenting proposals for tooling updates accompanied by risk and compliance evaluations.
  • Develop and maintain detection engineering documentation, runbooks, security policies, and standard operating procedures (SOPs).
Required Qualifications
  • Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent professional experience).
  • 8 or more years of progressive experience in SOC and security operations, including 2 or more years operating at a Tier 3, senior analyst, or detection engineering level.
  • 8 or more years of hands‑on production experience with CrowdStrike Falcon (Insight XDR, Discover, Fusion SOAR), including custom IOA authoring, FQL, and dashboard development.
  • 8 or more years of experience building or maintaining SOAR automation workflows (Torq preferred).
  • 8 or more years of experience utilizing AI/LLM tools (such as Claude or GPT-based tools) to support security operations while adhering to data sanitization boundaries.
  • 8 or more years of experience developing automation scripts (PowerShell, Python, or FQL) for detections and tool integrations.
  • 8 or more years of experience conducting forensic investigations and documenting findings, hunt reports, and technical runbooks.
  • Working knowledge of Zero Trust architecture principles (NIST 800-207) and familiarity with regulatory frameworks (IRS Pub. 1075, FBI CJIS Policy, HIPAA).
  • Demonstrated ability to create, review, and update security policies across public, private, and hybrid cloud contexts.
Preferred Qualifications
  • Relevant professional security certifications, such as GIAC (GCIH, GCIA, GCFA), CrowdStrike certifications (CCFR, CCFA), or Torq certifications.
  • Experience designing AI‑assisted playbooks or analyst copilots within SOC environments while enforcing data‑handling guardrails.
  • Experience supporting security operations in government, legal, or law enforcement‑adjacent organizations.
  • Familiarity with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One / Cloud Security Posture Management (CSPM) tooling.
Core Skills & Attributes
  • Exceptional analytical, problem‑solving, and critical‑thinking skills for complex incident resolution.
  • Strong written and verbal communication skills to present technical findings to diverse technical and executive audiences.
  • Ability to work independently with high self‑sufficiency while collaborating effectively in cross‑functional cybersecurity teams.
  • Ability to teach, mentor, and communicate new security technologies to team members.

Flexible work from home options available.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Detection & SOAR Architect - Remote
Senior Detection & SOAR Architect - Remote

SMART TECH SKILLS LLC • Austin (TX)

Hybrid
USD 120,000 - 170,000
Flexible remote options
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000
Senior Security Automation, SOAR Engineer
Senior Security Automation, SOAR Engineer

Jobtailor • Colorado

On-site
USD 140,000 - 170,000
Cyber Defense Detection and Automation Engineer
Cyber Defense Detection and Automation Engineer

Crane NXT • United States

On-site
USD 120,000 - 150,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Manager, Threat Detection Engineer
Manager, Threat Detection Engineer

Jobtailor • Washington

On-site
USD 140,000 - 190,000
Expert Cyber Security Incident and Threat Engineer
Expert Cyber Security Incident and Threat Engineer

Request Technology, LLC • Oakland (CA)

On-site
USD 150,000 - 190,000
Bonus eligible
Cyber Defense Detection and Automation Engineer
Cyber Defense Detection and Automation Engineer

Crane NXT, Co. • Northern (KY)

Hybrid
USD 100,000 - 180,000
Detection Engineer III
Detection Engineer III

OU Health • Oklahoma City (OK)

On-site
USD 110,000 - 140,000
PTO
401(k)
Medical and dental plans
Senior Detection & Response Analyst
Senior Detection & Response Analyst

Remote Jobs • United States

On-site
USD 110,000 - 190,000