Twk_3346 Security Operations Analyst | State Of Texas | Austin, Tx# Remote In Texas State | Local
Job Description
Share profiles along with Job ID number
S E K H A R @ TEKWINGS. COM
Note: If this email is not relevant to you, sorry for your Inconvenience
Share profiles ASAP
Requirement details:
Internal job ID:TWK_3346
Security Operations Analyst
State of Texas
Austin, TX# Remote
Note:
1)Position is Remote in Texas state
2) The program will allow candidates who are LOCAL TO Texas state only
- Active Texas DL & LinkedIn ID Must for submission
- LOCAL to Texas profiles only
- Please do not submit candidates who are currently out of state and are planning to move to Texas. Candidates must already reside in Texas.
Interview Mode: ☒ In person ☒ Through Microsoft Teams
NO OPT / Fake GC
MUST-HAVE TECHNICAL SKILLS
- 8+ years of progressive SOC / Security Operations experience
- 2+ years at Tier 3 / Senior Analyst / Detection Engineering level
- Strong hands-on CrowdStrike Falcon
- Falcon Insight XDR
- Falcon Discover
- Falcon Fusion SOAR
- Custom Detection / IOA authoring
- Falcon Query Language (FQL)
- Dashboard development
- SOAR automation – Torq strongly preferred
- Hands-on AI / LLM tools such as Claude / GPT for security operations
- Understanding of Zero Trust / NISTxxxxxxxxxxxxxxx
- Familiarity with IRS Pub. 1075, FBI CJIS Policy, HIPAA
- Strong scripting skills – PowerShell / Python / FQL
- Incident Response, Threat Hunting & Forensics
- Detection Engineering & Security Automation
- Security policies and standards for cloud environments
- Strong documentation, reporting and communication skills
PREFERRED
- GIAC certifications – GCIH, GCIA, GCFA
- CrowdStrike CCFR / CCFA
- Torq certification or automation portfolio
- AI-assisted SOC playbooks / analyst copilots
- Microsoft Defender XDR
- Splunk
- Entra ID Protection
- Tenable One / CSPM
- Government / Legal / Law Enforcement security experience
CANDIDATE SUBMISSION DETAILS
Please include the following with every profile:
- Updated Resume
- Job ID: TWK_3346
- Current Location in Texas state:
- Active Texas DL – Yes/No
- LinkedIn Profile
- Work Authorization
- Availability
- Rate
- Total Years of Experience
- CrowdStrike Experience
- Torq Experience
- AI/LLM Security Experience
- Certifications:
- Interview Availability
Job Description:
The Client is seeking a senior-level Security Operations Analyst to strengthen detection, response, and orchestration capabilities across the agency's security operations. This role blends deep SOC (Security Operations Center) investigative expertise with hands-on security automation engineering, focusing on CrowdStrike Falcon and Torq to build scalable, AI-assisted detection and response workflows. The ideal candidate has practical experience integrating large language model (LLM) tools such as Claude into security operations — for triage acceleration, playbook generation, and analyst augmentation — while operating within a strict Zero Trust, defense-in-depth security posture appropriate to a state Attorney General's office.
Key Responsibilities
• Serve as a SOC analysis & Tier 3 escalation point for complex security incidents, performing deep-dive investigation, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.
• Design, build, and maintain detection analytics, dashboards, and hunting queries (Falcon Query Language / FQL) within CrowdStrike Falcon, tuning correlation rules and detection logic to reduce false positives and improve mean-time-to-detect (MTTD).
• Architect and maintain security orchestration, automation, and response (SOAR) playbooks in Torq, integrating CrowdStrike Falcon, identity providers, ticketing, and communication platforms into automated response workflows.
• Design AI-assisted analyst workflows (e.g., automated triage summarization, alert enrichment, playbook drafting) using approved generative AI tooling, ensuring all inputs are sanitized and free of regulated or case-specific data.
• Lead incident response efforts for high-severity events, coordinating with IT, legal, and divisional stakeholders while strictly adhering to FTI/CJI handling restrictions.
• Develop and maintain detection engineering documentation, runbooks, and standard operating procedures (SOPs) for Tier 1/Tier 2 analyst use.
• Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts; review and validate their investigative work and escalation quality.
• Continuously evaluate and integrate emerging SOC automation and AI capabilities, presenting proposals for tooling changes with documented risk and compliance analysis.
• Participate in an on-call rotation for critical incident escalations.
SKILLS AND QUALIFICATIONS
--
Thanks & Regards
Sekhar | Sr.IT Technical Recruiter
Tekwings LLC
Email : xxxxxxxxxxxxxxx
Tekwings Requirements Email group :
LinkedIn Group:
LinkedIn:
Similar Jobs
Twk_3349 Child Welfare Project Manager | State Of Texas | Austin, Tx# Remote In Texas State
Remote
Twk_3348 Enterprise Data Architect With Mdm,Metadata & AI | Stateoftexas | Remote In Tx State| Local
Remote
Twk_3347 Dynamic 365 Developer | State Of Texas Austin, Tx#Onsite | Local Profiles | Certifications
Texas
Twk_3345 QA Test Manager | State Of Texas | Austin, Tx#Onsite | Locals Only | 8+Y Ehr Implementatio
Texas
Twko_242 Sr Automation QA |State Of Or | Remote #Local Profiles | State / Public Sector Exp Must
Remote