Senior SOC Analyst

Marvel Infotech

  • NULL, TX
  • 1 day ago

    Highlights

    Design, build, and maintain detection analytics, dashboards, and hunting queries (Falcon Query Language / FQL) within CrowdStrike Falcon, tuning correlation rules and detection logic to reduce false positives and improve mean-time-to-detect (MTTD). Direct: 732-802-6563 Desk: 732-802-6563 Extn 108 Fax: 732-875-0333 Email:- rahul@marvelinfotech.com www.marvelinfotech.com MBE NMSDC NYNJ

    Numbers & Facts

    LocationNULL, TX

    Description

    Job Title: Senior SOC Analyst

    Position Type: Contract

    Client Location: Austin, TX 78741 - Onsite

    Job Description

    Key Responsibilities

    Serve as a SOC analysis & Tier 3 escalation point for complex security incidents, performing deep-dive investigation, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.

    Design, build, and maintain detection analytics, dashboards, and hunting queries (Falcon Query Language / FQL) within CrowdStrike Falcon, tuning correlation rules and detection logic to reduce false positives and improve mean-time-to-detect (MTTD).

    Architect and maintain security orchestration, automation, and response (SOAR) playbooks in Torq, integrating CrowdStrike Falcon, identity providers, ticketing, and communication platforms into automated response workflows.

    Design AI-assisted analyst workflows (e.g., automated triage summarization, alert enrichment, playbook drafting) using approved generative AI tooling, ensuring all inputs are sanitized and free of regulated or case-specific data.

    Lead incident response efforts for high-severity events, coordinating with IT, legal, and divisional stakeholders while strictly adhering to FTI/CJI handling restrictions.

    Develop and maintain detection engineering documentation, runbooks, and standard operating procedures (SOPs) for Tier 1/Tier 2 analyst use.

    Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts; review and validate their investigative work and escalation quality.

    Continuously evaluate and integrate emerging SOC automation and AI capabilities, presenting proposals for tooling changes with documented risk and compliance analysis.

    Participate in an on-call rotation for critical incident escalations.

    Minimum Requirements: Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity.

    Actual
    Years
    Experience

    Years
    Experience
    Needed

    Required/
    Preferred

    Skills/Experience

    8

    Required

    Progressive SOC / security operations experience, including 2+ years functioning at a Tier 3 / senior analyst or detection engineering level.

    8

    Required

    Hands-on production experience with CrowdStrike Falcon (Insight XDR, Discover, and/or Fusion SOAR), including custom detection/IOA authoring, Falcon Query Language (FQL) use, and dashboard development.

    8

    Required

    Demonstrated experience building or maintaining SOAR automation (Torq strongly preferred)

    8

    Required

    Practical, hands-on experience using AI/LLM tools (e.g., Claude, GPT-based tools) to support security operations, with clear understanding of data sanitization and safe-use boundaries in a regulated environment.

    8

    Required

    Working knowledge of Zero Trust architecture principles (NIST 800-207) and general familiarity with regulatory frameworks such as IRS Pub. 1075, FBI CJIS Policy, and HIPAA.

    8

    Required

    Strong scripting/automation ability (PowerShell, Python, or Falcon Query Language-based automation) for building custom detections and integrations.

    8

    Required

    Excellent written communication skills for incident reporting, runbook authorship, and cross-divisional coordination.

    8

    Required

    Experience documenting investigations, creating hunt reports, and communicating technical findings to diverse audiences.

    8

    Required

    Strong analytical, problem-solving, and critical-thinking skills

    8

    Required

    Ability to work independently while collaborating effectively within cross-functional cybersecurity teams.

    8

    Required

    Ability to resolve complex security issues in diverse and decentralized environments; learn, communicate, teach new security technologies; and communicate effectively.

    8

    Required

    Conduct forensic investigations on cyberattacks to determine how they occurred and can be prevented in the future.

    8

    Required

    Experience creating/reviewing/updating security policies and standards for the public/private/hybrid cloud contexts.

    4

    Required

    Bachelor's degree in Computer Science, Information Security, or related field, or equivalent professional experience.

    1

    Preferred

    GIAC certifications (GCIH, GCIA, GCFA) or equivalent.

    1

    Preferred

    CrowdStrike Certified Falcon Responder (CCFR) or CrowdStrike Certified Falcon Administrator (CCFA), or equivalent CrowdStrike security certification.

    1

    Preferred

    Torq certification or demonstrated portfolio of built automation workflows

    1

    Preferred

    Experience designing AI-assisted playbooks or analyst copilots for SOC use cases while maintaining strict data-handling guardrails.

    1

    Preferred

    Familiarity with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One / cloud security posture management (CSPM) tooling.

    1

    Preferred

    Experience in government, legal, or law-enforcement-adjacent security environments

    Thanks & Regards,
    Rahul Reddy
    MARVEL InfoTech, Inc.
    Direct: 732-802-6563
    Desk: 732-802-6563 Extn 108
    Fax: 732-875-0333
    Email:- rahul@marvelinfotech.com
    www.marvelinfotech.com
    MBE NMSDC NYNJ

    Similar Jobs

    See more jobs