Jobs · Engineering · Texas

Cyber Automation Engineer

Neos Consulting Group · Austin, TX · 3 days ago
EngineeringContract

About the role

Neos is seeking a senior-level Security Operations Analyst to strengthen detection, response, and orchestration capabilities for a state Attorney General's office. This long-term contract role blends deep SOC investigative expertise with hands-on security automation engineering, focusing on CrowdStrike Falcon and Torq to build scalable, AI-assisted detection and response workflows. The ideal candidate has practical experience integrating large language model (LLM) tools such as Claude into security operations while operating within a strict Zero Trust, defense-in-depth security posture.

This position is remote, but candidates must currently reside in the Austin, Texas area or in the U.S.

Responsibilities

  • Serve as a SOC analysis and Tier 3 escalation point for complex security incidents, performing deep-dive investigation, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.
  • Design, build, and maintain detection analytics, dashboards, and hunting queries (Falcon Query Language / FQL) within CrowdStrike Falcon, tuning correlation rules and detection logic to reduce false positives and improve mean-time-to-detect (MTTD).
  • Architect and maintain security orchestration, automation, and response (SOAR) playbooks in Torq, integrating CrowdStrike Falcon, identity providers, ticketing, and communication platforms into automated response workflows.
  • Design AI-assisted analyst workflows (e.g., automated triage summarization, alert enrichment, playbook drafting) using approved generative AI tooling, ensuring all inputs are sanitized and free of regulated or case-specific data.
  • Lead incident response efforts for high-severity events, coordinating with IT, legal, and divisional stakeholders while strictly adhering to FTI/CJI handling restrictions.
  • Develop and maintain detection engineering documentation, runbooks, and standard operating procedures (SOPs) for Tier 1/Tier 2 analyst use.
  • Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts; review and validate their investigative work and escalation quality.
  • Continuously evaluate and integrate emerging SOC automation and AI capabilities, presenting proposals for tooling changes with documented risk and compliance analysis.
  • Participate in an on-call rotation for critical incident escalations.
  • Conduct forensic investigations on cyberattacks to determine how they occurred and can be prevented in the future.
  • Create, review, and update security policies and standards for public, private, and hybrid cloud contexts.

Requirements

  • 8 years of progressive SOC / security operations experience, including 2+ years functioning at a Tier 3 / senior analyst or detection engineering level.
  • 8 years of hands-on production experience with CrowdStrike Falcon (Insight XDR, Discover, and/or Fusion SOAR), including custom detection/IOA authoring, Falcon Query Language (FQL) use, and dashboard development.
  • 8 years of demonstrated experience building or maintaining SOAR automation (Torq strongly preferred).
  • 8 years of practical, hands-on experience using AI/LLM tools (e.g., Claude, GPT-based tools) to support security operations, with a clear understanding of data sanitization and safe-use boundaries in a regulated environment.
  • 8 years of working knowledge of Zero Trust architecture principles (NIST 800-207) and general familiarity with regulatory frameworks such as IRS Pub. 1075, FBI CJIS Policy, and HIPAA.
  • 8 years of strong scripting/automation ability (PowerShell, Python, or Falcon Query Language-based automation) for building custom detections and integrations.
  • 8 years of excellent written communication skills for incident reporting, runbook authorship, and cross-divisional coordination.
  • 8 years of experience documenting investigations, creating hunt reports, and communicating technical findings to diverse audiences.
  • 8 years of strong analytical, problem-solving, and critical-thinking skills.
  • 8 years of ability to work independently while collaborating effectively within cross-functional cybersecurity teams.
  • 8 years of ability to resolve complex security issues in diverse and decentralized environments; learn, communicate, and teach new security technologies; and communicate effectively.
  • 4 years of a Bachelor's degree in Computer Science, Information Security, or related field, or equivalent professional experience.

Preferred Qualifications

  • GIAC certifications (GCIH, GCIA, GCFA) or equivalent.
  • CrowdStrike Certified Falcon Responder (CCFR) or CrowdStrike Certified Falcon Administrator (CCFA), or equivalent CrowdStrike security certification.
  • Torq certification or demonstrated portfolio of built automation workflows.
  • Experience designing AI-assisted playbooks or analyst copilots for SOC use cases while maintaining strict data-handling guardrails.
  • Familiarity with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One / cloud security posture management (CSPM) tooling.
  • Experience in government, legal, or law-enforcement-adjacent security environments.

Similar jobs

Cyber Automation Engineer

Booz Allen HamiltonColorado Springs, CO· 1 mo ago
Engineering$87k–$198k/yrapply on careers.boozallen.com