Senior SOC Detection Engineer – CrowdStrike Falcon & SOAR / AI
Skills
About the role
Senior SOC Detection Engineer – CrowdStrike Falcon & SOAR / AI
Company: BizTech Fusion
Location: Remote (Texas Only)
Duration: 12+ Months (Extendable)
Experience: Senior-Level Security Operations Professional
About the Role
BizTech Fusion is seeking a Senior SOC Detection Engineer – CrowdStrike Falcon & SOAR / AI for one of our valued clients. This is a senior-level cybersecurity role focused on advanced SOC operations, detection engineering, incident response, threat hunting, security automation, and AI-assisted security operations.
The ideal candidate will have deep hands-on experience with CrowdStrike Falcon, SOAR automation, Falcon Query Language (FQL), threat hunting, detection analytics, and incident response. The candidate should also have practical experience leveraging AI/LLM tools to improve security operations workflows while maintaining strict security and data-handling standards.
Required Qualifications
Senior-level SOC, Detection Engineering, or Security Operations experience.
Minimum 2+ years of experience supporting government, legal, or law-enforcement-adjacent security environments.
Experience working at a Tier 3 SOC Analyst or Detection Engineer level.
Strong incident response, threat hunting, and forensic investigation experience.
Strong written and verbal communication skills.
Ability to work independently and collaborate with security, IT, and business teams.
Required Technical Skills
CrowdStrike Falcon & Detection Engineering
Strong hands-on experience with CrowdStrike Falcon platform.
Experience with Falcon Insight XDR, Discover, and/or Fusion SOAR.
Experience creating custom detections and Indicators of Attack (IOA).
Strong experience with Falcon Query Language (FQL).
Experience developing detection analytics, dashboards, and hunting queries.
Experience tuning alerts and improving detection accuracy.
SOC Operations & Incident Response
Experience handling complex security incidents and Tier 3 escalations.
Advanced threat hunting experience across endpoint, network, cloud, and identity telemetry.
Root cause analysis and forensic investigation experience.
Experience with security monitoring, alert tuning, and investigation workflows.
Experience creating hunt reports, incident reports, runbooks, and SOP documentation.
SOAR & Security Automation
Experience designing and maintaining SOAR playbooks.
Strong experience with security automation workflows.
Experience integrating security tools, ticketing systems, identity platforms, and communication platforms.
Torq SOAR experience is highly preferred.
AI-Assisted Security Operations
Practical experience using AI/LLM tools such as:
Claude
GPT-based tools
Other enterprise-approved AI assistants
Experience using AI tools for:
Alert triage acceleration.
Security investigation support.
Playbook generation.
Detection engineering assistance.
Analyst workflow automation.
Security documentation.
Candidates must understand secure AI usage practices, including data sanitization and protection of sensitive information.
Key Responsibilities
Serve as a Tier 3 SOC escalation point for complex security incidents.
Perform advanced investigations, threat hunting, and root cause analysis.
Design, develop, and maintain CrowdStrike Falcon detection logic and analytics.
Create and optimize FQL queries, dashboards, and hunting workflows.
Build and maintain SOAR automation playbooks using Torq and related security tools.
Develop AI-assisted security workflows for analyst productivity.
Lead incident response activities for high-severity cybersecurity events.
Create security documentation, runbooks, SOPs, and investigation reports.
Mentor Tier 1 and Tier 2 SOC analysts.
Evaluate emerging security automation and AI capabilities.
Participate in critical incident escalation support.
Additional Required Experience
Strong scripting and automation skills using:
Python
PowerShell
Falcon Query Language (FQL)
Knowledge of Zero Trust Architecture principles (NIST 800-207).
Familiarity with security compliance frameworks such as:
IRS Pub. 1075
FBI CJIS Policy
HIPAA
Experience with security tools such as:
Microsoft Defender XDR
Splunk
Entra ID Protection
Tenable One / CSPM platforms
Certifications (Highly Preferred)
GCIH or equivalent
GCIA or equivalent
GCFA or equivalent
CrowdStrike Certified Falcon Responder (CCFR)
CrowdStrike Certified Falcon Administrator (CCFA)
Torq Certification
Education
Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related field preferred. Equivalent professional experience will also be considered.
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.