Haystack
← Back to Jobs
Technology
MR

Cyber Security Operations Engineer/Cyber Security Analyst/SOC Analyst/Hybrid/TX

Motion Recruitment Partners, LLCAddison, TX🇺🇸United StatesPosted Oct 8, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Addison, TX, United States
Posted
Yesterday
SplunkBashPowerShellPython

Job Description

This is an urgent, hybrid role in Addison, TX with a large global healthcare and pharmaceutical services organization. The sits on a security operations team running CrowdStrike Falcon, a SIEM, and an email security gateway across an enterprise environment, with a focus on incident response, threat hunting, and detection.
They need someone who has already worked a SOC and is ready to step into the engineer seat. You will be the escalation point for junior analysts, support major incident response efforts, and tune the tooling that makes detection work. The team supports a global user base. If you are a SOC analyst or security engineer with a few years under your belt and want more ownership over incident response and detection, this is a strong step up.
Required Skills & Experience
  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related field, or equivalent work experience
  • 3 to 5 years of combined IT and cybersecurity experience, with time spent in a SOC or security engineering function
  • Experience with Splunk or a comparable SIEM for alert triage, correlation, and root cause analysis
  • Proven experience supporting major incident response activities and EDR detection and response
  • Strong written communication skills, with the ability to translate complex technical findings into clear language for non-technical stakeholders
  • Willingness to participate in an on-call rotation, including weekends

Desired Skills & Experience
  • Security certification such as CompTIA Security+, CySA+, or EC-Council CEH, or equivalent
  • Depth in digital forensics or threat hunting
  • Scripting experience in Python, PowerShell, or Bash
  • Experience developing detection rules and SOAR playbooks
  • Experience working with a managed detection and response provider

What You Will Be Doing
Tech Breakdown
  • 30% EDR/XDR (CrowdStrike Falcon): detection, investigation, and response
  • 25% SIEM (Splunk): alert triage, correlation, and log analysis
  • 15% Email security gateway: phishing and email threat investigation
  • 10% Threat hunting and MITRE ATT&CK-aligned analysis
  • 10% Scripting and detection/SOAR playbook development
  • 10% ServiceNow: incident documentation and ticketing

Daily Responsibilities
  • 65% Hands On: Investigating and correlating suspicious events, determining root cause, supporting incident response, performing proactive and reactive threat hunting, and recommending changes to security controls and procedures
  • 35% Team Collaboration: Guiding junior analysts on event monitoring, partnering with cross-functional teams, conducting business impact analysis, and participating in IR exercises and drills

Similar jobs