> Markdown version of [/jobs/ext/1499106-senior-soc-analyst-advanced-incident-response-crowdstrike-engineering](https://www.wearedevelopers.com/jobs/ext/1499106-senior-soc-analyst-advanced-incident-response-crowdstrike-engineering). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior SOC Analyst - Advanced Incident Response & CrowdStrike Engineering - **Company:** Biogen - **Location:** Durham, NC, United States - **Experience:** Expert - **Salary:** $115,000.0 - $154,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Artificial Intelligence, Batch Processing, Cloud Storage, Cyber Security, Continuous Integration, Information Leak Prevention, Extract Transform Load (ETL), Data Security, Query Languages, Domain Name System (DNS), Ethernet, Health Information Management, Hypertext Transfer Protocols (HTTP), Supervisory Control and Data Acquisition (SCADA), Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Kerberos (Protocol), Network Security, Modbus, Network Forensics, Network Segmentation, Packet Analyzer, NT LAN Manager, Windows PowerShell, Role-Based Access Control, Remote Access Technology, Cloud Services, CrowdStrike Falcon Management, OPC Unified Architecture, Reverse Engineering, Security Information and Event Management, TCP/IP, Software Vulnerability Management, Data Classification, Mitre Att&ck, Cyber Threat Analysis, Falcon Platform, Information Technology, Cybercrime, Operational Systems, Api Management, GXP - **Published:** July 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=504f52cfd89fd7e9 ## About the Role * Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field required; advanced degree preferred * 3-5+ years in Security Operations, Incident Response, or Threat Hunting with progressive responsibility * 3+ years hands-on experience with CrowdStrike Falcon platform in an engineering/administration capacity (not just alert triage) * Demonstrated experience leading complex incident investigations involving APT, ransomware, insider threats, or supply chain compromise * Experience with OT/ICS security monitoring, industrial environments, or manufacturing cybersecurity * Track record of building detection rules, SIEM correlation logic, or behavioral analytics that caught real threats Technical Skills * CrowdStrike Falcon: NG-SIEM (LogScale/CQL), AIDR, Identity Protection, Data Security, Falcon Fusion, Real Time Response, custom IOA development * Forensics: memory analysis (Volatility), disk forensics, network forensics, malware triage/reverse engineering fundamentals * Threat Hunting: hypothesis-driven hunts, MITRE ATT&CK mapping, behavioral analysis across endpoint/network/identity/cloud telemetry * Scripting & Automation: Python and PowerShell for investigation tooling, data parsing, API integrations, and SOAR playbook development * Network Security: deep understanding of TCP/IP, DNS, HTTP/TLS, lateral movement protocols (SMB, RDP, WMI, WinRM), and packet analysis * Identity Security: Active Directory attack techniques, Kerberos/NTLM fundamentals, privilege escalation paths, identity-based detection * OT/ICS: familiarity with industrial protocols (Modbus, EtherNet/IP, OPC-UA), Purdue Model architecture, DCS/SCADA security principles, * CrowdStrike: CCFA (Falcon Administrator), CCFR (Falcon Responder), CCFH (Falcon Hunter) * SANS/GIAC: GCFA, GCIH, GREM, GCIA, or GNFA * OT/ICS: GICSP (Global Industrial Cyber Security Professional) or GRID (Response and Industrial Defense) * General: CISSP, CySA+, or equivalent, * Experience in pharmaceutical, biotech, or life sciences environments with GxP-regulated systems * Familiarity with DeltaV DCS, batch automation systems, or laboratory automation security * Experience with CrowdStrike NG-SIEM migration, parser development, or LogScale administration * Background in detection engineering as code (version-controlled detections, CI/CD for security content)Experience coordinating with CrowdStrike OverWatch or similar managed hunting services Job Level: Management ## Description This is a individual contributor role and the technical backbone of Biogen's Security Operations Center - an analyst who leads complex incident investigations, engineers and optimizes the CrowdStrike Falcon platform across advanced modules (AIDR, Data Security, NG-SIEM, Identity Protection), and extends detection capabilities into operational technology (OT) environments supporting pharmaceutical manufacturing. You will own the most complex escalations, build the detection logic that catches what others miss, and serve as the bridge between IT security operations and OT/manufacturing environments. This is not a monitoring role - it is an engineering and investigation role that happens to sit in the SOC. Why This Role Exists * Biogen's threat landscape demands deeper investigative capability - advanced persistent threats, insider risk, and pharmaceutical IP targeting require an analyst who can conduct full-spectrum forensic investigations and threat hunting * CrowdStrike Falcon is our primary detection and response platform - we need an engineer who can maximize the value of AIDR, Data Security, NG-SIEM (LogScale), and Identity Protection modules beyond default configurations * IT/OT convergence in our manufacturing environments creates unique detection challenges - DeltaV/DCS systems, GxP-regulated processes, and industrial protocols require specialized security monitoring, Advanced Incident Response & Investigations (40%) * Lead complex, multi-stage incident investigations from initial detection through containment, eradication, recovery, and lessons learned * Conduct deep-dive forensic analysis: memory forensics (Volatility), disk forensics, network artifact analysis, and malware triage to determine attacker TTPs * Perform kill chain reconstruction - map attacker activity to MITRE ATT&CK, identify lateral movement paths, persistence mechanisms, and data staging/exfiltration techniques * Develop and execute proactive threat hunts based on intelligence, behavioral anomalies, and hypothesis-driven analysis across endpoint, network, identity, and cloud telemetry * Produce actionable incident reports with root cause analysis, business impact assessment, and concrete remediation recommendations, * Develop and maintain CQL (CrowdStrike Query Language) queries for advanced correlation, threat hunting, and detection rules * Build custom dashboards, scheduled searches, and automated alerting pipelines * Optimize log ingestion, parsing, and retention policies across all telemetry sources * Create detection-as-code workflows - version-controlled queries that map to MITRE ATT&CK coverage gaps AIDR (AI Detection & Response) * Configure and tune AI-driven detection policies for prompt injection, data leakage, and shadow AI usage * Build custom rules to monitor GenAI application interactions across endpoints and cloud workloads * Assess and respond to AI-specific threats: model poisoning indicators, unauthorized AI tool installations, sensitive data in AI prompts * Integrate AIDR telemetry into investigation workflows and incident playbooks Identity Protection * Engineer identity-based detection rules: Kerberoasting, credential stuffing, lateral movement via pass-the-hash/ticket, suspicious service account behavior * Configure conditional access policies, risk-based authentication enforcement, and identity threat hunting queries * Monitor Active Directory attack paths and privilege escalation techniques (DCSync, Golden Ticket, NTLM relay) * Coordinate with IAM team on identity hygiene findings and remediation priorities Data Security (Data Protection) * Configure data classification policies and egress monitoring rules for sensitive content (IP, PII, regulated data) * Tune anomaly detection for unusual data movement patterns: bulk downloads, new destination usage, abnormal upload volumes * Build response workflows for data exfiltration alerts - user notification, manager escalation, automatic evidence preservation * Define and enforce policies for removable media, cloud storage, and web upload channels Platform Administration * Manage sensor deployment health, prevention policies, and RBAC across 25,000+ endpoints * Develop custom IOA (Indicator of Attack) rules and behavioral detections tailored to Biogen's environment * Build and maintain Falcon Fusion (SOAR) workflows for automated containment and enrichment * Coordinate with CrowdStrike OverWatch for managed hunting findings and recommended actions, * Extend SOC monitoring into operational technology environments supporting pharmaceutical manufacturing (DeltaV DCS, SCADA, PLCs, HMIs) * Develop and tune detection rules for OT-specific threats: unauthorized engineering workstation access, controller logic changes, anomalous industrial protocol traffic (Modbus, EtherNet/IP, OPC-UA) * Maintain and enforce IT/OT network segmentation aligned with the Purdue Reference Model - monitor for segmentation bypass attempts * Lead incident response for OT security events in coordination with Process Automation, Engineering, and Plant Operations teams * Support OT asset inventory maintenance and vulnerability management in GxP-regulated environments (21 CFR Part 11, cGMP considerations) * Conduct tabletop exercises for OT-specific scenarios (ransomware impacting batch processing, unauthorized remote access to control systems) ## Related Videos - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Optimizing Land-Based Fish Feeding with Node-RED](https://www.wearedevelopers.com/videos/2032-optimizing-land-based-fish-feeding-with-node-red) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023)