BF

Senior SOC Detection Engineer – CrowdStrike Falcon & SOAR / AI

BizTech Fusion

Remoteremote globalPosted Aug 7, 2026
Posting intelligenceActively listed

Skills

pythonllm

About the role

Senior SOC Detection Engineer – CrowdStrike Falcon & SOAR / AI

Company: BizTech Fusion

Location: Remote (Texas Only)

Duration: 12+ Months (Extendable)

Experience: Senior-Level Security Operations Professional

About the Role

BizTech Fusion is seeking a Senior SOC Detection Engineer – CrowdStrike Falcon & SOAR / AI for one of our valued clients. This is a senior-level cybersecurity role focused on advanced SOC operations, detection engineering, incident response, threat hunting, security automation, and AI-assisted security operations.

The ideal candidate will have deep hands-on experience with CrowdStrike Falcon, SOAR automation, Falcon Query Language (FQL), threat hunting, detection analytics, and incident response. The candidate should also have practical experience leveraging AI/LLM tools to improve security operations workflows while maintaining strict security and data-handling standards.

Required Qualifications

Senior-level SOC, Detection Engineering, or Security Operations experience.

Minimum 2+ years of experience supporting government, legal, or law-enforcement-adjacent security environments.

Experience working at a Tier 3 SOC Analyst or Detection Engineer level.

Strong incident response, threat hunting, and forensic investigation experience.

Strong written and verbal communication skills.

Ability to work independently and collaborate with security, IT, and business teams.

Required Technical Skills

CrowdStrike Falcon & Detection Engineering

Strong hands-on experience with CrowdStrike Falcon platform.

Experience with Falcon Insight XDR, Discover, and/or Fusion SOAR.

Experience creating custom detections and Indicators of Attack (IOA).

Strong experience with Falcon Query Language (FQL).

Experience developing detection analytics, dashboards, and hunting queries.

Experience tuning alerts and improving detection accuracy.

SOC Operations & Incident Response

Experience handling complex security incidents and Tier 3 escalations.

Advanced threat hunting experience across endpoint, network, cloud, and identity telemetry.

Root cause analysis and forensic investigation experience.

Experience with security monitoring, alert tuning, and investigation workflows.

Experience creating hunt reports, incident reports, runbooks, and SOP documentation.

SOAR & Security Automation

Experience designing and maintaining SOAR playbooks.

Strong experience with security automation workflows.

Experience integrating security tools, ticketing systems, identity platforms, and communication platforms.

Torq SOAR experience is highly preferred.

AI-Assisted Security Operations

Practical experience using AI/LLM tools such as:

Claude

GPT-based tools

Other enterprise-approved AI assistants

Experience using AI tools for:

Alert triage acceleration.

Security investigation support.

Playbook generation.

Detection engineering assistance.

Analyst workflow automation.

Security documentation.

Candidates must understand secure AI usage practices, including data sanitization and protection of sensitive information.

Key Responsibilities

Serve as a Tier 3 SOC escalation point for complex security incidents.

Perform advanced investigations, threat hunting, and root cause analysis.

Design, develop, and maintain CrowdStrike Falcon detection logic and analytics.

Create and optimize FQL queries, dashboards, and hunting workflows.

Build and maintain SOAR automation playbooks using Torq and related security tools.

Develop AI-assisted security workflows for analyst productivity.

Lead incident response activities for high-severity cybersecurity events.

Create security documentation, runbooks, SOPs, and investigation reports.

Mentor Tier 1 and Tier 2 SOC analysts.

Evaluate emerging security automation and AI capabilities.

Participate in critical incident escalation support.

Additional Required Experience

Strong scripting and automation skills using:

Python

PowerShell

Falcon Query Language (FQL)

Knowledge of Zero Trust Architecture principles (NIST 800-207).

Familiarity with security compliance frameworks such as:

IRS Pub. 1075

FBI CJIS Policy

HIPAA

Experience with security tools such as:

Microsoft Defender XDR

Splunk

Entra ID Protection

Tenable One / CSPM platforms

Certifications (Highly Preferred)

GCIH or equivalent

GCIA or equivalent

GCFA or equivalent

CrowdStrike Certified Falcon Responder (CCFR)

CrowdStrike Certified Falcon Administrator (CCFA)

Torq Certification

Education

Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related field preferred. Equivalent professional experience will also be considered.

Questions about this role

Click "Apply with AI Applyd" above and you are done. Your resume is rewritten for this advert, the screening questions are answered, and it is submitted on BizTech Fusion's own hiring system. No retyping your history, no fourteen tabs, no evening lost.

Compensation varies by seniority, employer size, and location. When this listing publishes a salary band you'll see it in the badge row above the description.

You never touch the form - the application is filled and submitted for you on BizTech Fusion's own hiring system. It is not marked sent when we press submit. It is marked sent when a confirmation from their system arrives at the address we apply with, and your dashboard shows which stage each application is at until then.

Twelve applicant tracking systems have a real apply path: Workday, Greenhouse, Lever, Ashby, Workable, iCIMS, Personio, Recruitee, Teamtailor, Rippling, Breezy and SmartRecruiters. Your application goes in on the employer's own hiring system, never into an aggregator queue.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.