Get C2C/W2 Jobs hotlists update

TWK_3346 Security Operations Analyst | State of Texas | Austin, TX# Remote in Texas state | Local profiles | certifications must & Government / Legal / Law Enforcement security experience must

Contract
  • Contract
  • Anywhere

State of Texas

Share profiles along with Job ID number

S E K H A R @ TEKWINGS. COM

 

Note: If this email is not relevant to you, sorry for your Inconvenience
Share profiles ASAP 

Requirement details:
Internal job ID:TWK_3346
Security Operations Analyst
State of Texas

Austin, TX# Remote
Note: 
 1)Position is Remote in Texas state
 2) The program will allow candidates who are LOCAL TO Texas state only 
 
Active Texas DL & LinkedIn ID  Must for submission
LOCAL to Texas profiles only
Please do not submit candidates who are currently out of state and are planning to move to Texas. Candidates must already reside in Texas.
Interview Mode: ☒    In person ☒    Through Microsoft Teams

NO OPT / Fake GC

MUST-HAVE TECHNICAL SKILLS
8+ years of progressive SOC / Security Operations experience
2+ years at Tier 3 / Senior Analyst / Detection Engineering level
Strong hands-on CrowdStrike FalconFalcon Insight XDR
Falcon Discover
Falcon Fusion SOAR
Custom Detection / IOA authoring
Falcon Query Language (FQL)
Dashboard development
SOAR automation – Torq strongly preferred
Hands-on AI / LLM tools such as Claude / GPT for security operations
Understanding of Zero Trust / NIST 800-207
Familiarity with IRS Pub. 1075, FBI CJIS Policy, HIPAA
Strong scripting skills – PowerShell / Python / FQL
Incident Response, Threat Hunting & Forensics
Detection Engineering & Security Automation
Security policies and standards for cloud environments
Strong documentation, reporting and communication skills
PREFERRED
GIAC certifications – GCIH, GCIA, GCFA
CrowdStrike CCFR / CCFA
Torq certification or automation portfolio
AI-assisted SOC playbooks / analyst copilots
Microsoft Defender XDR
Splunk
Entra ID Protection
Tenable One / CSPM
Government / Legal / Law Enforcement security experience
CANDIDATE SUBMISSION DETAILS
Please include the following with every profile:

Updated Resume
Job ID: TWK_3346
Current Location in Texas state: 
Active Texas DL – Yes/No
LinkedIn Profile
Work Authorization
Availability
Rate
Total Years of Experience
CrowdStrike Experience
Torq Experience
AI/LLM Security Experience
Certifications:
Interview Availability
Job Description:
The Client is seeking a senior-level Security Operations Analyst to strengthen detection, response, and orchestration capabilities across the agency’s security operations. This role blends deep SOC (Security Operations Center) investigative expertise with hands-on security automation engineering, focusing on CrowdStrike Falcon and Torq to build scalable, AI-assisted detection and response workflows. The ideal candidate has practical experience integrating large language model (LLM) tools such as Claude into security operations — for triage acceleration, playbook generation, and analyst augmentation — while operating within a strict Zero Trust, defense-in-depth security posture appropriate to a state Attorney General’s office.

 

Key Responsibilities

•    Serve as a SOC analysis & Tier 3 escalation point for complex security incidents, performing deep-dive investigation, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.

•    Design, build, and maintain detection analytics, dashboards, and hunting queries (Falcon Query Language / FQL) within CrowdStrike Falcon, tuning correlation rules and detection logic to reduce false positives and improve mean-time-to-detect (MTTD).

•    Architect and maintain security orchestration, automation, and response (SOAR) playbooks in Torq, integrating CrowdStrike Falcon, identity providers, ticketing, and communication platforms into automated response workflows.

•    Design AI-assisted analyst workflows (e.g., automated triage summarization, alert enrichment, playbook drafting) using approved generative AI tooling, ensuring all inputs are sanitized and free of regulated or case-specific data.

•    Lead incident response efforts for high-severity events, coordinating with IT, legal, and divisional stakeholders while strictly adhering to FTI/CJI handling restrictions.

•    Develop and maintain detection engineering documentation, runbooks, and standard operating procedures (SOPs) for Tier 1/Tier 2 analyst use.

•    Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts; review and validate their investigative work and escalation quality.

•    Continuously evaluate and integrate emerging SOC automation and AI capabilities, presenting proposals for tooling changes with documented risk and compliance analysis.

•    Participate in an on-call rotation for critical incident escalations.

SKILLS AND QUALIFICATIONS 
Years
Required
Experience
8
Required
Progressive SOC / security operations experience, including 2+ years functioning at a Tier 3 / senior analyst or detection engineering level.
8
Required
Hands-on production experience with CrowdStrike Falcon (Insight XDR, Discover, and/or Fusion SOAR), including custom detection/IOA authoring, Falcon Query Language (FQL) use, and dashboard development.
8
Required
Demonstrated experience building or maintaining SOAR automation (Torq strongly preferred)
8
Required
Practical, hands-on experience using AI/LLM tools (e.g., Claude, GPT-based tools) to support security operations, with clear understanding of data sanitization and safe-use boundaries in a regulated environment.
8
Required
Working knowledge of Zero Trust architecture principles (NIST 800-207) and general familiarity with regulatory frameworks such as IRS Pub. 1075, FBI CJIS Policy, and HIPAA.
8
Required
Strong scripting/automation ability (PowerShell, Python, or Falcon Query Language-based automation) for building custom detections and integrations.
8
Required
Excellent written communication skills for incident reporting, runbook authorship, and cross-divisional coordination.
8
Required
Experience documenting investigations, creating hunt reports, and communicating technical findings to diverse audiences.
8
Required
Strong analytical, problem-solving, and critical-thinking skills
8
Required
Ability to work independently while collaborating effectively within cross-functional cybersecurity teams.
8
Required
Ability to resolve complex security issues in diverse and decentralized environments; learn, communicate, teach new security technologies; and communicate effectively.
8
Required
Conduct forensic investigations on cyberattacks to determine how they occurred and can be prevented in the future.
8
Required
Experience creating/reviewing/updating security policies and standards for the public/private/hybrid cloud contexts.
4
Required
Bachelor’s degree in Computer Science, Information Security, or related field, or equivalent professional experience.
1
Preferred
GIAC certifications (GCIH, GCIA, GCFA) or equivalent.
1
Preferred
CrowdStrike Certified Falcon Responder (CCFR) or CrowdStrike Certified Falcon Administrator (CCFA), or equivalent CrowdStrike security certification.
1
Preferred
Torq certification or demonstrated portfolio of built automation workflows
1
Preferred
Experience designing AI-assisted playbooks or analyst copilots for SOC use cases while maintaining strict data-handling guardrails.
1
Preferred
Familiarity with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One / cloud security posture management (CSPM) tooling.
1
Preferred
Experience in government, legal, or law-enforcement-adjacent security environments

 

Thanks & Regards
 
Sekhar | Sr.IT Technical Recruiter

 

Tekwings LLC
Email :  sekhar@tekwings.com 
 Tekwings Requirements Email group  : https://groups.google.com/d/forum/tekwings_requrements_group1
LinkedIn Group: https://www.linkedin.com/groups/10421204/

LinkedIn: https://www.linkedin.com/in/sekhar-u-27b11a166/

To apply for this job email your details to SEKHAR@TEKWINGS.COM

×

Post your C2C job instantly

Quick & easy posting in 10 seconds

Keep it concise - you can add details later
Please use your company/professional email address
Simple math question to prevent spam