Network Security Analyst 3 – CrowdStrike | Torq SOAR | Threat Hunting | AI/LLM | Remote

  • Contract

Company Description

  • StarTekk’s adoption of Digital Transformation is to accelerate organizational growth, increase efficiencies and help Star Workforce achieve focused business goals. The Employee will help our organization to identify and bridge the gap that exists in the business by analyzing the data, scale and support digital transformation initiatives.

Job Description

We are seeking a senior-level Security Operations Analyst to strengthen detection, incident response, threat hunting, and security orchestration capabilities across an enterprise security operations environment.

The ideal candidate will have strong hands-on SOC and Tier 3 investigation experience, along with expertise in CrowdStrike Falcon, Torq SOAR, security automation, detection engineering, and AI-assisted security operations. Experience using generative AI/LLM tools such as Claude to accelerate security triage, playbook development, and analyst workflows is highly desirable.

The role operates within a strict Zero Trust and defense-in-depth security model and requires strong knowledge of enterprise security operations, incident response, detection analytics, and security automation.

Key Responsibilities:

  • Serve as a Tier 3 SOC escalation point for complex security incidents.
  • Perform deep-dive investigations, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.
  • Design, develop, and maintain detection analytics, dashboards, and hunting queries using CrowdStrike Falcon Query Language (FQL).
  • Tune detection and correlation logic to reduce false positives and improve Mean Time to Detect (MTTD).
  • Architect and maintain SOAR playbooks in Torq for automated security response.
  • Integrate CrowdStrike Falcon, identity providers, ticketing systems, communication platforms, and other security tools into automated workflows.
  • Develop AI-assisted security analyst workflows, including automated triage summaries, alert enrichment, and playbook generation.
  • Ensure AI workflows follow security, privacy, and compliance requirements, including sanitization of sensitive or regulated data.
  • Lead incident response activities for high-severity security events.
  • Coordinate with IT, legal, and business stakeholders during critical incidents.
  • Develop and maintain detection engineering documentation, runbooks, and Standard Operating Procedures (SOPs).
  • Mentor Tier 1 and Tier 2 SOC analysts and provide technical guidance on investigations and escalations.
  • Evaluate emerging security automation and AI capabilities and recommend improvements based on documented security and compliance considerations.
  • Participate in an on-call rotation for critical security incident escalations.

Qualifications

  • Senior-level experience in Security Operations / SOC environments.
  • Strong experience with Tier 3 security incident investigation and escalation.
  • Hands-on experience with CrowdStrike Falcon.
  • Experience developing Falcon Query Language (FQL) queries and detection analytics.
  • Strong knowledge of threat hunting, detection engineering, and incident response.
  • Hands-on experience with Torq SOAR or comparable security orchestration and automation platforms.
  • Experience developing and maintaining SOAR playbooks and automated response workflows.
  • Experience integrating endpoint, identity, ticketing, communication, and security platforms.
  • Experience investigating security events across endpoint, network, cloud, and identity environments.
  • Knowledge of Zero Trust architecture and defense-in-depth security principles.
  • Experience with security dashboards, monitoring, alert correlation, and detection tuning.
  • Experience with generative AI / LLM technologies for security operations is highly desirable.
  • Familiarity with tools such as Claude or similar approved LLM platforms for security triage, enrichment, and analyst augmentation.
  • Strong understanding of security automation, scripting, and workflow development.
  • Excellent incident response, troubleshooting, and root cause analysis skills.
  • Strong documentation and communication skills.
  • Ability to mentor and provide technical guidance to junior SOC analysts.
  • Ability to work effectively with technical, legal, and business stakeholders.
  • Experience handling sensitive or regulated security information in accordance with applicable security and compliance requirements.

Additional Information

Visa: Green Card / U.S. Citizens Preferred

Preferred Experience:

  • CrowdStrike Falcon detection engineering
  • Falcon Query Language (FQL)
  • Torq SOAR
  • AI-assisted SOC operations
  • LLM/GenAI security use cases
  • Automated alert triage and enrichment
  • Threat hunting
  • Security incident response
  • Zero Trust security
  • Cloud security
  • Identity security
  • SOC automation and orchestration
  • Detection engineering and security analytics
  • FTI/CJI security and compliance environments

 

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply