Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
BizTech Fusion

Senior SOC Detection Engineer – CrowdStrike Falcon, SOAR, AI

BizTech Fusion

Senior SOC Detection Engineer protecting federal environments with CrowdStrike Falcon, FQL, SOAR, and AI-assisted operations. Leading Tier 3 incident response, threat hunting, detection engineering, and security automation.

Posted 8/8/2026full-timeRemote • Texas • 🇺🇸 United StatesSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in advanced threat hunting, incident response, and security automation, with a strong focus on utilizing CrowdStrike Falcon and developing detection analytics. Proven ability to mentor junior analysts and create comprehensive security documentation and workflows.

Highest-signal resume keywords
CrowdStrike Falcon PlatformIncident ResponseThreat HuntingFalcon Query Language (FQL)Security Automation Workflows

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Advanced Threat HuntingRoot Cause AnalysisForensic InvestigationDetection EngineeringAlert TuningScripting with PythonScripting with PowerShellCreating Custom DetectionsDesigning SOAR PlaybooksDeveloping Detection Analytics
Soft Skills
Strong Written CommunicationStrong Verbal CommunicationCollaboration with TeamsIndependent Work
Tools & Technologies
Falcon Insight XDRFalcon DiscoverFalcon Fusion SOARMicrosoft Defender XDRSplunkEntra ID ProtectionTenable One/CSPMTorq SOAR
Certifications & Qualifications
GCIHGCIAGCFACCFRCCFA
Industry Keywords
SOCDetection EngineeringSecurity OperationsZero Trust ArchitectureIRS Pub. 1075FBI CJIS PolicyHIPAA

Tech Stack

Tools & technologies
CloudCyber SecurityPythonSplunk

About the role

Key responsibilities & impact
  • Serve as a Tier 3 SOC escalation point for complex security incidents
  • Perform advanced investigations, threat hunting, and root cause analysis
  • Design, develop, and maintain CrowdStrike Falcon detection logic and analytics
  • Create and optimize FQL queries, dashboards, and hunting workflows
  • Build and maintain SOAR automation playbooks using Torq and related security tools
  • Develop AI-assisted security workflows for analyst productivity
  • Lead incident response activities for high-severity cybersecurity events
  • Create security documentation, runbooks, SOPs, and investigation reports
  • Mentor Tier 1 and Tier 2 SOC analysts
  • Evaluate emerging security automation and AI capabilities
  • Participate in critical incident escalation support

Requirements

What you’ll need
  • Senior-level SOC, Detection Engineering, or Security Operations experience
  • Minimum 2+ years of experience supporting government, legal, or law-enforcement-adjacent security environments
  • Experience working at a Tier 3 SOC Analyst or Detection Engineer level
  • Strong incident response, threat hunting, and forensic investigation experience
  • Strong written and verbal communication skills
  • Ability to work independently and collaborate with security, IT, and business teams
  • Strong hands-on experience with the CrowdStrike Falcon platform
  • Experience with Falcon Insight XDR, Discover, and/or Fusion SOAR
  • Experience creating custom detections and Indicators of Attack (IOA)
  • Strong experience with Falcon Query Language (FQL)
  • Experience developing detection analytics, dashboards, and hunting queries
  • Experience tuning alerts and improving detection accuracy
  • Experience handling complex security incidents and Tier 3 escalations
  • Advanced threat hunting experience across endpoint, network, cloud, and identity telemetry
  • Root cause analysis and forensic investigation experience
  • Experience with security monitoring, alert tuning, and investigation workflows
  • Experience creating hunt reports, incident reports, runbooks, and SOP documentation
  • Experience designing and maintaining SOAR playbooks
  • Strong experience with security automation workflows
  • Experience integrating security tools, ticketing systems, identity platforms, and communication platforms
  • Practical experience using AI/LLM tools such as Claude, GPT-based tools, or other enterprise-approved AI assistants
  • Experience using AI tools for alert triage acceleration, security investigation support, playbook generation, detection engineering assistance, analyst workflow automation, and security documentation
  • Understanding of secure AI usage practices, including data sanitization and protection of sensitive information
  • Strong scripting and automation skills using Python and PowerShell
  • Knowledge of Zero Trust Architecture principles (NIST 800-207)
  • Familiarity with IRS Pub. 1075, FBI CJIS Policy, and HIPAA
  • Experience with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One/CSPM platforms
  • Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related field preferred
  • Equivalent professional experience will also be considered
  • Torq SOAR experience is highly preferred
  • GCIH, GCIA, GCFA, CCFR, CCFA, or Torq certifications are highly preferred

Benefits

Comp & perks
  • 12+ month extendable duration
  • Remote work (Texas only)
  • Professional certifications highly preferred, including GCIH, GCIA, GCFA, CCFR, CCFA, and Torq Certification