
Network Security Analyst 3 – Threat Hunting, AI/LLM
Posted 2 hours ago

Posted 2 hours ago
This is a fully remote position, open to applicants in Texas.
• Act as a Tier 3 SOC escalation point for intricate security incidents.
• Conduct thorough investigations, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.
• Design, develop, and sustain detection analytics, dashboards, and hunting queries utilizing CrowdStrike Falcon Query Language (FQL).
• Adjust detection and correlation logic to minimize false positives and enhance Mean Time to Detect (MTTD).
• Design and manage SOAR playbooks in Torq for automated security responses.
• Incorporate CrowdStrike Falcon, identity providers, ticketing systems, communication platforms, and various security tools into automated workflows.
• Create AI-assisted workflows for security analysts, which include automated triage summaries, alert enrichment, and playbook generation.
• Ensure that AI workflows comply with security, privacy, and regulatory requirements, including the sanitization of sensitive or regulated data.
• Lead incident response efforts for high-severity security events.
• Collaborate with IT, legal, and business stakeholders during critical incidents.
• Create and maintain documentation for detection engineering, runbooks, and Standard Operating Procedures (SOPs).
• Mentor Tier 1 and Tier 2 SOC analysts, offering technical guidance on investigations and escalations.
• Assess emerging security automation and AI capabilities, recommending enhancements based on documented security and compliance considerations.
• Participate in an on-call rotation for urgent security incident escalations.
• Extensive experience at a senior level in Security Operations / SOC environments.
• Proficient in Tier 3 security incident investigation and escalation.
• Practical experience with CrowdStrike Falcon.
• Experience in developing Falcon Query Language (FQL) queries and detection analytics.
• Solid understanding of threat hunting, detection engineering, and incident response.
• Hands-on experience with Torq SOAR or equivalent security orchestration and automation platforms.
• Experience in creating and maintaining SOAR playbooks and automated response workflows.
• Experience in integrating endpoint, identity, ticketing, communication, and security platforms.
• Expertise in investigating security events across endpoint, network, cloud, and identity environments.
• Knowledge of Zero Trust architecture and defense-in-depth security principles.
• Experience with security dashboards, monitoring, alert correlation, and detection tuning.
• Experience with generative AI / LLM technologies in security operations is highly desirable.
• Familiarity with tools like Claude or similar approved LLM platforms for security triage, enrichment, and analyst augmentation.
• Strong comprehension of security automation, scripting, and workflow development.
• Excellent skills in incident response, troubleshooting, and root cause analysis.
• Superior documentation and communication skills.
• Ability to mentor and provide technical guidance to junior SOC analysts.
• Capability to collaborate effectively with technical, legal, and business stakeholders.
• Experience in handling sensitive or regulated security information in compliance with applicable security and regulatory standards.
• Green Card / U.S. Citizens preferred.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance.
• Opportunities for professional development and certifications.
• Flexible working hours and remote work options.
• Generous paid time off and holiday leave.
Proficio
Compass
CyberSheath
Cresol Cooperativa
Get handpicked remote jobs straight to your inbox weekly.