About The Position

BizTech Fusion is seeking a Senior SOC Detection Engineer – CrowdStrike Falcon & SOAR / AI for one of our valued clients. This is a senior-level cybersecurity role focused on advanced SOC operations, detection engineering, incident response, threat hunting, security automation, and AI-assisted security operations. The ideal candidate will have deep hands-on experience with CrowdStrike Falcon, SOAR automation, Falcon Query Language (FQL), threat hunting, detection analytics, and incident response. The candidate should also have practical experience leveraging AI/LLM tools to improve security operations workflows while maintaining strict security and data-handling standards.

Requirements

  • Senior-level SOC, Detection Engineering, or Security Operations experience.
  • Minimum 2+ years of experience supporting government, legal, or law-enforcement-adjacent security environments.
  • Experience working at a Tier 3 SOC Analyst or Detection Engineer level.
  • Strong incident response, threat hunting, and forensic investigation experience.
  • Strong written and verbal communication skills.
  • Ability to work independently and collaborate with security, IT, and business teams.
  • Strong hands-on experience with CrowdStrike Falcon platform.
  • Experience with Falcon Insight XDR, Discover, and/or Fusion SOAR.
  • Experience creating custom detections and Indicators of Attack (IOA).
  • Strong experience with Falcon Query Language (FQL).
  • Experience developing detection analytics, dashboards, and hunting queries.
  • Experience tuning alerts and improving detection accuracy.
  • Experience handling complex security incidents and Tier 3 escalations.
  • Advanced threat hunting experience across endpoint, network, cloud, and identity telemetry.
  • Root cause analysis and forensic investigation experience.
  • Experience with security monitoring, alert tuning, and investigation workflows.
  • Experience creating hunt reports, incident reports, runbooks, and SOP documentation.
  • Experience designing and maintaining SOAR playbooks.
  • Strong experience with security automation workflows.
  • Experience integrating security tools, ticketing systems, identity platforms, and communication platforms.
  • Practical experience using AI/LLM tools such as: Claude, GPT-based tools, Other enterprise-approved AI assistants.
  • Experience using AI tools for: Alert triage acceleration, Security investigation support, Playbook generation, Detection engineering assistance, Analyst workflow automation, Security documentation.
  • Candidates must understand secure AI usage practices, including data sanitization and protection of sensitive information.
  • Strong scripting and automation skills using: Python, PowerShell, Falcon Query Language (FQL).
  • Knowledge of Zero Trust Architecture principles (NIST 800-207).
  • Familiarity with security compliance frameworks such as: IRS Pub. 1075, FBI CJIS Policy, HIPAA.
  • Experience with security tools such as: Microsoft Defender XDR, Splunk, Entra ID Protection, Tenable One / CSPM platforms.

Nice To Haves

  • Torq SOAR experience is highly preferred.
  • GCIH or equivalent
  • GCIA or equivalent
  • GCFA or equivalent
  • CrowdStrike Certified Falcon Responder (CCFR)
  • CrowdStrike Certified Falcon Administrator (CCFA)
  • Torq Certification
  • Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related field preferred. Equivalent professional experience will also be considered.

Responsibilities

  • Serve as a Tier 3 SOC escalation point for complex security incidents.
  • Perform advanced investigations, threat hunting, and root cause analysis.
  • Design, develop, and maintain CrowdStrike Falcon detection logic and analytics.
  • Create and optimize FQL queries, dashboards, and hunting workflows.
  • Build and maintain SOAR automation playbooks using Torq and related security tools.
  • Develop AI-assisted security workflows for analyst productivity.
  • Lead incident response activities for high-severity cybersecurity events.
  • Create security documentation, runbooks, SOPs, and investigation reports.
  • Mentor Tier 1 and Tier 2 SOC analysts.
  • Evaluate emerging security automation and AI capabilities.
  • Participate in critical incident escalation support.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service