Remote Network Security Analyst

HonorVet Technologies
Austin, TX, United States
3 days ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Cyber Security Query Languages Python (Programming Language) Windows PowerShell Zero Trust Network Access Scripting Large Language Models HybridCloud Information Technology Cybercrime Data Management
+3 more
3-tier Architectures Splunk GPT

Job description

The Client is seeking a senior-level Security Operations Analyst to strengthen detection, response, and orchestration capabilities across the agency’’s security operations. This role blends deep SOC (Security Operations Center) investigative expertise with hands-on security automation engineering, focusing on CrowdStrike Falcon and Torq to build scalable, AI-assisted detection and response workflows. The ideal candidate has practical experience integrating large language model (LLM) tools such as Claude into security operations - for triage acceleration, playbook generation, and analyst augmentation - while operating within a strict Zero Trust, defense-in-depth security posture appropriate., * Serve as a SOC analysis & Tier 3 escalation point for complex security incidents, performing deep-dive investigation, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.

  • Design, build, and maintain detection analytics, dashboards, and hunting queries (Falcon Query Language / FQL) within CrowdStrike Falcon, tuning correlation rules and detection logic to reduce false positives and improve mean-time-to-detect (MTTD).
  • Architect and maintain security orchestration, automation, and response (SOAR) playbooks in Torq, integrating CrowdStrike Falcon, identity providers, ticketing, and communication platforms into automated response workflows.
  • Design AI-assisted analyst workflows (e.g., automated triage summarization, alert enrichment, playbook drafting) using approved generative AI tooling, ensuring all inputs are sanitized and free of regulated or case-specific data.
  • Lead incident response efforts for high-severity events, coordinating with IT, legal, and divisional stakeholders while strictly adhering to FTI/CJI handling restrictions.
  • Develop and maintain detection engineering documentation, runbooks, and standard operating procedures (SOPs) for Tier 1/Tier 2 analyst use.
  • Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts; review and validate their investigative work and escalation quality.
  • Continuously evaluate and integrate emerging SOC automation and AI capabilities, presenting proposals for tooling changes with documented risk and compliance analysis.
  • Participate in an on-call rotation for critical incident escalations.

Requirements

  • 8 years Progressive SOC / security operations experience, including 2+ years functioning at a Tier 3 / senior analyst or detection engineering level.
  • 8 years Hands-on production experience with CrowdStrike Falcon (Insight XDR, Discover, and/or Fusion SOAR), including custom detection/IOA authoring, Falcon Query Language (FQL) use, and dashboard development.
  • 8 years Demonstrated experience building or maintaining SOAR automation (Torq strongly preferred).
  • 8 years Practical, hands-on experience using AI/LLM tools (e.g., Claude, GPT-based tools) to support security operations, with clear understanding of data sanitization and safe-use boundaries in a regulated environment.
  • 8 years Working knowledge of Zero Trust architecture principles (NIST 800-207) and general familiarity with regulatory frameworks such as IRS Pub. 1075, FBI CJIS Policy, and HIPAA.
  • 8 years Strong scripting/automation ability (PowerShell, Python, or Falcon Query Language-based automation) for building custom detections and integrations.
  • 8 years’ Experience documenting investigations, creating hunt reports, and communicating technical findings to diverse audiences.
  • 8 years’ Ability to work independently while collaborating effectively within cross-functional cybersecurity teams.
  • 8 years’ Ability to resolve complex security issues in diverse and decentralized environments; learn, communicate, teach new security technologies; and communicate effectively.
  • 8 years’ Conduct forensic investigations on cyberattacks to determine how they occurred and can be prevented in the future.
  • 8 years’ Experience creating/reviewing/updating security policies and standards for the public/private/hybrid cloud contexts.
  • Bachelor’’s degree in Computer Science, Information Security, or related field, or equivalent professional experience.

Preferred experience:

  • 1 Years GIAC certifications (GCIH, GCIA, GCFA) or equivalent.
  • CrowdStrike Certified Falcon Responder (CCFR) or CrowdStrike Certified Falcon Administrator (CCFA), or equivalent CrowdStrike security certification.
  • Torq certification or demonstrated portfolio of built automation workflows
  • Experience designing AI-assisted playbooks or analyst copilots for SOC use cases while maintaining strict data-handling guardrails.
  • Familiarity with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One / cloud security posture management (CSPM) tooling.
  • Experience in government, legal, or law-enforcement-adjacent security environments

About the company

HonorVet Technologies is a veteran-owned IT staffing firm, ISO 9001 and ISO 27001 certified, working with federal agencies, state governments, and Fortune 500 enterprise clients across the US. What makes us different isn’‘t a tagline - it’’s the way we work. We don’‘t forward resumes and hope for the best. We take the time to understand where a professional like you is headed and only reach out when we genuinely believe there’’s a fit worth exploring.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

40 sec

Generative pre-trained transformer models powering code completions

lgonta lgonta +1 · WWC 2024

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all