Detection Engineering & SOAR Architect

SMART TECH SKILLS LLCAustin, TX
Remote

About The Position

The Senior Security Operations Analyst strengthens detection, response, and orchestration capabilities across enterprise security operations. This role combines Tier 3 SOC investigation expertise with hands-on security automation engineering, focusing on CrowdStrike Falcon and Torq to build scalable, AI-assisted detection and response workflows. Operating within a strict Zero Trust defense-in-depth security posture, the analyst leverages generative AI tools (such as Claude) for triage acceleration, alert enrichment, and playbook drafting while enforcing rigorous data sanitization in a regulated public sector environment.

Requirements

  • Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent professional experience).
  • 8 or more years of progressive experience in SOC and security operations, including 2 or more years operating at a Tier 3, senior analyst, or detection engineering level.
  • 8 or more years of hands-on production experience with CrowdStrike Falcon (Insight XDR, Discover, Fusion SOAR), including custom IOA authoring, FQL, and dashboard development.
  • 8 or more years of experience building or maintaining SOAR automation workflows (Torq preferred).
  • 8 or more years of experience utilizing AI/LLM tools (such as Claude or GPT-based tools) to support security operations while adhering to data sanitization boundaries.
  • 8 or more years of experience developing automation scripts (PowerShell, Python, or FQL) for detections and tool integrations.
  • 8 or more years of experience conducting forensic investigations and documenting findings, hunt reports, and technical runbooks.
  • Working knowledge of Zero Trust architecture principles (NIST 800-207) and familiarity with regulatory frameworks (IRS Pub. 1075, FBI CJIS Policy, HIPAA).
  • Demonstrated ability to create, review, and update security policies across public, private, and hybrid cloud contexts.
  • Exceptional analytical, problem-solving, and critical-thinking skills for complex incident resolution.
  • Strong written and verbal communication skills to present technical findings to diverse technical and executive audiences.
  • Ability to work independently with high self-sufficiency while collaborating effectively in cross-functional cybersecurity teams.
  • Ability to teach, mentor, and communicate new security technologies to team members.

Nice To Haves

  • Relevant professional security certifications, such as GIAC (GCIH, GCIA, GCFA), CrowdStrike certifications (CCFR, CCFA), or Torq certifications.
  • Experience designing AI-assisted playbooks or analyst copilots within SOC environments while enforcing data-handling guardrails.
  • Experience supporting security operations in government, legal, or law enforcement-adjacent organizations.
  • Familiarity with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One / Cloud Security Posture Management (CSPM) tooling.

Responsibilities

  • Serve as a Tier 3 escalation point for complex security incidents, performing deep-dive investigations, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.
  • Conduct forensic investigations on cyberattacks to determine attack vectors, scope, and preventive measures.
  • Lead incident response efforts for high-severity events, coordinating with IT, legal, and operational leadership.
  • Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts, reviewing and validating investigative work and escalation quality.
  • Design, build, and maintain detection analytics, dashboards, and hunting queries using Falcon Query Language (FQL) in CrowdStrike Falcon.
  • Tune correlation rules and detection logic to minimize false positives and improve mean-time-to-detect (MTTD).
  • Architect and maintain SOAR playbooks in Torq, integrating CrowdStrike Falcon, identity providers, ticketing platforms, and communication channels into automated response workflows.
  • Write custom automation scripts using PowerShell, Python, or FQL-based automation for bespoke detections and system integrations.
  • Design AI-assisted analyst workflows (such as automated triage summarization, alert enrichment, and playbook drafting) using approved generative AI tooling.
  • Enforce strict data sanitization guardrails to ensure AI prompts and inputs remain free of regulated, sensitive, or case-specific data.
  • Continuously evaluate emerging SOC automation and AI capabilities, presenting proposals for tooling updates accompanied by risk and compliance evaluations.
  • Develop and maintain detection engineering documentation, runbooks, security policies, and standard operating procedures (SOPs).

Benefits

  • Flexible work from home options available.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service