Senior SOC Detection Engineer – CrowdStrike Falcon & SOAR / AI
Company: BizTech Fusion
Location: Remote (Texas Only)
Duration: 12+ Months (Extendable)
Experience: Senior-Level Security Operations Professional
About the Role
BizTech Fusion is seeking a Senior SOC Detection Engineer – CrowdStrike Falcon & SOAR / AI for one of our valued clients. This is a senior-level cybersecurity role focused on advanced SOC operations, detection engineering, incident response, threat hunting, security automation, and AI-assisted security operations.
The ideal candidate will have deep hands-on experience with CrowdStrike Falcon, SOAR automation, Falcon Query Language (FQL), threat hunting, detection analytics, and incident response. The candidate should also have practical experience leveraging AI/LLM tools to improve security operations workflows while maintaining strict security and data-handling standards.
Required Qualifications
- Senior-level SOC, Detection Engineering, or Security Operations experience.
- Minimum 2+ years of experience supporting government, legal, or law-enforcement-adjacent security environments.
- Experience working at a Tier 3 SOC Analyst or Detection Engineer level.
- Strong incident response, threat hunting, and forensic investigation experience.
- Strong written and verbal communication skills.
- Ability to work independently and collaborate with security, IT, and business teams.
Required Technical Skills
CrowdStrike Falcon & Detection Engineering
- Strong hands-on experience with CrowdStrike Falcon platform.
- Experience with Falcon Insight XDR, Discover, and/or Fusion SOAR.
- Experience creating custom detections and Indicators of Attack (IOA).
- Strong experience with Falcon Query Language (FQL).
- Experience developing detection analytics, dashboards, and hunting queries.
- Experience tuning alerts and improving detection accuracy.
SOC Operations & Incident Response
- Experience handling complex security incidents and Tier 3 escalations.
- Advanced threat hunting experience across endpoint, network, cloud, and identity telemetry.
- Root cause analysis and forensic investigation experience.
- Experience with security monitoring, alert tuning, and investigation workflows.
- Experience creating hunt reports, incident reports, runbooks, and SOP documentation.
SOAR & Security Automation
- Experience designing and maintaining SOAR playbooks.
- Strong experience with security automation workflows.
- Experience integrating security tools, ticketing systems, identity platforms, and communication platforms.
- Torq SOAR experience is highly preferred.
AI-Assisted Security Operations
- Practical experience using AI/LLM tools such as:
- Claude
- GPT-based tools
- Other enterprise-approved AI assistants
Experience using AI tools for:
- Alert triage acceleration.
- Security investigation support.
- Playbook generation.
- Detection engineering assistance.
- Analyst workflow automation.
- Security documentation.
Candidates must understand secure AI usage practices, including data sanitization and protection of sensitive information.
Key Responsibilities
- Serve as a Tier 3 SOC escalation point for complex security incidents.
- Perform advanced investigations, threat hunting, and root cause analysis.
- Design, develop, and maintain CrowdStrike Falcon detection logic and analytics.
- Create and optimize FQL queries, dashboards, and hunting workflows.
- Build and maintain SOAR automation playbooks using Torq and related security tools.
- Develop AI-assisted security workflows for analyst productivity.
- Lead incident response activities for high-severity cybersecurity events.
- Create security documentation, runbooks, SOPs, and investigation reports.
- Mentor Tier 1 and Tier 2 SOC analysts.
- Evaluate emerging security automation and AI capabilities.
- Participate in critical incident escalation support.
Additional Required Experience
- Strong scripting and automation skills using:
- Python
- PowerShell
- Falcon Query Language (FQL)
- Knowledge of Zero Trust Architecture principles (NIST 800-207).
- Familiarity with security compliance frameworks such as:
- IRS Pub. 1075
- FBI CJIS Policy
- HIPAA
- Experience with security tools such as:
- Microsoft Defender XDR
- Splunk
- Entra ID Protection
- Tenable One / CSPM platforms
Certifications (Highly Preferred)
- GCIH or equivalent
- GCIA or equivalent
- GCFA or equivalent
- CrowdStrike Certified Falcon Responder (CCFR)
- CrowdStrike Certified Falcon Administrator (CCFA)
- Torq Certification
Education
Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related field preferred. Equivalent professional experience will also be considered.
Requirements
null