Senior SOC Detection Engineer – CrowdStrike Falcon & SOAR / AI at BizTech Fusion
United States
<p><strong>Senior SOC Detection Engineer – CrowdStrike Falcon & SOAR / AI</strong></p><p><strong>Company:</strong> BizTech Fusion</p><p> <strong>Location:</strong> Remote (Texas Only)</p><p> <strong>Duration:</strong> 12+ Months (Extendable)</p><p> <strong>Experience:</strong> Senior-Level Security Operations Professional</p><p><strong>About the Role</strong></p><p>BizTech Fusion is seeking a <strong>Senior SOC Detection Engineer – CrowdStrike Falcon & SOAR / AI</strong> for one of our valued clients. This is a senior-level cybersecurity role focused on advanced SOC operations, detection engineering, incident response, threat hunting, security automation, and AI-assisted security operations.</p><p>The ideal candidate will have deep hands-on experience with <strong>CrowdStrike Falcon, SOAR automation, Falcon Query Language (FQL), threat hunting, detection analytics, and incident response</strong>. The candidate should also have practical experience leveraging AI/LLM tools to improve security operations workflows while maintaining strict security and data-handling standards.</p><p><strong>Required Qualifications</strong></p><ul><li>Senior-level SOC, Detection Engineering, or Security Operations experience. </li><li>Minimum 2+ years of experience supporting government, legal, or law-enforcement-adjacent security environments. </li><li>Experience working at a Tier 3 SOC Analyst or Detection Engineer level. </li><li>Strong incident response, threat hunting, and forensic investigation experience. </li><li>Strong written and verbal communication skills. </li><li>Ability to work independently and collaborate with security, IT, and business teams. </li></ul><p><strong>Required Technical Skills</strong></p><p><strong>CrowdStrike Falcon & Detection Engineering</strong></p><ul><li>Strong hands-on experience with CrowdStrike Falcon platform. </li><li>Experience with Falcon Insight XDR, Discover, and/or Fusion SOAR. </li><li>Experience creating custom detections and Indicators of Attack (IOA). </li><li>Strong experience with Falcon Query Language (FQL). </li><li>Experience developing detection analytics, dashboards, and hunting queries. </li><li>Experience tuning alerts and improving detection accuracy. </li></ul><p><strong>SOC Operations & Incident Response</strong></p><ul><li>Experience handling complex security incidents and Tier 3 escalations. </li><li>Advanced threat hunting experience across endpoint, network, cloud, and identity telemetry. </li><li>Root cause analysis and forensic investigation experience. </li><li>Experience with security monitoring, alert tuning, and investigation workflows. </li><li>Experience creating hunt reports, incident reports, runbooks, and SOP documentation. </li></ul><p><strong>SOAR & Security Automation</strong></p><ul><li>Experience designing and maintaining SOAR playbooks. </li><li>Strong experience with security automation workflows. </li><li>Experience integrating security tools, ticketing systems, identity platforms, and communication platforms. </li><li>Torq SOAR experience is highly preferred. </li></ul><p><strong>AI-Assisted Security Operations</strong></p><ul><li>Practical experience using AI/LLM tools such as: </li><li>Claude </li><li>GPT-based tools </li><li>Other enterprise-approved AI assistants </li></ul><p>Experience using AI tools for:</p><ul><li>Alert triage acceleration. </li><li>Security investigation support. </li><li>Playbook generation. </li><li>Detection engineering assistance. </li><li>Analyst workflow automation. </li><li>Security documentation. </li></ul><p>Candidates must understand secure AI usage practices, including data sanitization and protection of sensitive information.</p><p><strong>Key Responsibilities</strong></p><ul><li>Serve as a Tier 3 SOC escalation point for complex security incidents. </li><li>Perform advanced investigations, threat hunting, and root cause analysis. </li><li>Design, develop, and maintain CrowdStrike Falcon detection logic and analytics. </li><li>Create and optimize FQL queries, dashboards, and hunting workflows. </li><li>Build and maintain SOAR automation playbooks using Torq and related security tools. </li><li>Develop AI-assisted security workflows for analyst productivity. </li><li>Lead incident response activities for high-severity cybersecurity events. </li><li>Create security documentation, runbooks, SOPs, and investigation reports. </li><li>Mentor Tier 1 and Tier 2 SOC analysts. </li><li>Evaluate emerging security automation and AI capabilities. </li><li>Participate in critical incident escalation support. </li></ul><p><strong>Additional Required Experience</strong></p><ul><li>Strong scripting and automation skills using: </li><li>Python </li><li>PowerShell </li><li>Falcon Query Language (FQL) </li><li>Knowledge of Zero Trust Architecture principles (NIST 800-207). </li><li>Familiarity with security compliance frameworks such as: </li><li>IRS Pub. 1075 </li><li>FBI CJIS Policy </li><li>HIPAA </li><li>Experience with security tools such as: </li><li>Microsoft Defender XDR </li><li>Splunk </li><li>Entra ID Protection </li><li>Tenable One / CSPM platforms </li></ul><p><strong>Certifications (Highly Preferred)</strong></p><ul><li>GCIH or equivalent </li><li>GCIA or equivalent </li><li>GCFA or equivalent </li><li>CrowdStrike Certified Falcon Responder (CCFR) </li><li>CrowdStrike Certified Falcon Administrator (CCFA) </li><li>Torq Certification </li></ul><p><strong>Education</strong></p><p>Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related field preferred. Equivalent professional experience will also be considered.</p> <br><h3>Requirements</h3> null
Apply Now