Haystack
← Back to Jobs
Engineering

Senior SOC Detection Engineer – CrowdStrike Falcon & SOAR / AI

Conquest ConsultingManor, TX🇺🇸United StatesPosted 10 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Senior SOC Detection Engineer – CrowdStrike Falcon & SOAR / AI

Client: State of Texas
Location: Austin, TX – Remote within Texas
Duration: 12 Months + Extension
Interview: Team Interview
Work Authorization: Must be authorized to work in the U.S.
Candidate Location: Texas Residents Only – No Out-of-State or Relocation Candidates

IMPORTANT REQUIREMENT

Candidates must have a minimum of 2+ years of experience working in government, legal, law-enforcement, or law-enforcement-adjacent security environments.

Position Overview

The State of Texas is seeking a Senior SOC Detection Engineer with strong hands-on experience in CrowdStrike Falcon, SOAR automation, detection engineering, threat hunting, incident response, and AI/LLM-assisted security operations.

The ideal candidate will have Tier 3/Senior SOC experience and the ability to develop custom detections, automate security workflows, conduct forensic investigations, and support advanced security operations in a highly regulated environment.

Key Responsibilities

  • Develop, tune, maintain, and optimize CrowdStrike Falcon detections and Indicators of Attack (IOAs).
  • Work extensively with CrowdStrike Falcon Insight XDR, Discover, and Fusion SOAR.
  • Develop and utilize Falcon Query Language (FQL) for threat hunting, detection engineering, investigations, and analytics.
  • Build and maintain SOAR automation workflows, with Torq experience strongly preferred.
  • Develop security automation and integrations using Python, PowerShell, FQL, APIs, and other scripting technologies.
  • Conduct advanced threat hunting and forensic investigations of cybersecurity incidents and attacks.
  • Determine attack vectors, root causes, indicators of compromise, and recommendations for preventing recurrence.
  • Create detailed hunt reports, incident reports, investigation documentation, runbooks, and technical security documentation.
  • Design and maintain dashboards and security analytics supporting SOC operations.
  • Leverage AI/LLM technologies such as GPT-based tools and Claude to improve SOC efficiency, detection engineering, investigation, and automation.
  • Design AI-assisted playbooks and analyst copilots while maintaining strict data sanitization, privacy, and security controls.
  • Apply appropriate data-handling safeguards when using AI tools in regulated environments.
  • Support Zero Trust security architecture initiatives based on NIST SP 800-207 principles.
  • Develop, review, and update security policies, procedures, standards, and technical controls across public, private, and hybrid cloud environments.
  • Collaborate with cybersecurity, infrastructure, application, compliance, and other cross-functional teams.
  • Communicate complex technical findings clearly to both technical and non-technical audiences.
  • Troubleshoot and resolve complex cybersecurity issues across decentralized and diverse environments.
  • Research, evaluate, communicate, and help implement emerging security technologies.

 

Regulatory / Compliance Knowledge

Candidates should have familiarity with regulated security environments and frameworks including:

  • IRS Publication 1075
  • FBI CJIS Security Policy
  • HIPAA
  • NIST Zero Trust Architecture – SP 800-207

Required Experience

  • Progressive SOC / Security Operations experience.
  • 2+ years at Tier 3 / Senior SOC Analyst / Detection Engineering level.
  • 2+ years in government, legal, law-enforcement, or law-enforcement-adjacent security environments.
  • Hands-on production experience with CrowdStrike Falcon.
  • Experience authoring custom detections/IOAs and using FQL.
  • Experience developing or maintaining SOAR automation.
  • Hands-on experience with AI/LLM tools supporting cybersecurity operations.
  • Strong scripting and automation experience using Python, PowerShell, or FQL-based automation.
  • Experience conducting forensic investigations and advanced threat hunting.
  • Experience documenting investigations and communicating technical findings.
  • Experience creating or updating security policies and standards.
  • Ability to work independently and effectively within cross-functional cybersecurity teams.

Education & Certifications

Education:

  • Bachelor''s degree in Computer Science, Information Security, Cybersecurity, or related field preferred.
  • Equivalent professional experience may be considered.

Preferred Certifications:

  • GIAC certifications such as GCIH, GCIA, FA, or equivalent.
  • CrowdStrike Certified Falcon Responder (CCFR) or CrowdStrike Certified Falcon Administrator (CCFA), or equivalent CrowdStrike certification.
  • Torq certification or demonstrated portfolio of SOAR automation workflows.

Similar jobs