More jobs:
Cyber Automation Engineer
Job in
Austin, Travis County, Texas, 78716, USA
Listed on 2026-08-19
Listing for:
Neos Consulting
Full Time
position Listed on 2026-08-19
Job specializations:
-
IT/Tech
Cybersecurity, Security Management & Operations
Job Description & How to Apply Below
State : Texas
Neos is Seeking a Cyber Automation Engineer for a long-term contract role for with our client in Austin, TX.
Experience in security automation, detection engineering, and Crowd Strike. The ideal candidate is passionate about improving Security Operations Center (SOC) processes through automation and has experience working in highly regulated or government environments.
*** REMOTE - CANDIDATES CURRENTLY RESIDING IN THE AUSTIN, TEXAS AREA OR IN U.S. NEED APPLY***
This position is Remote
No calls, no emails, please respond directly to the "apply" link with your resume and contact details.
DESCRIPTION OF SERVICES
Seeking a senior-level Security Operations Analyst to strengthen detection, response, and orchestration capabilities across the agency's security operations. This role blends deep SOC (Security Operations Center) investigative expertise with hands-on security automation engineering, focusing on Crowd Strike Falcon and Torq to build scalable, AI-assisted detection and response workflows. The ideal candidate has practical experience integrating large language model (LLM) tools such as Claude into security operations - for triage acceleration, playbook generation, and analyst augmentation - while operating within a strict Zero Trust, defense-in-depth security posture appropriate to a state Attorney General's office.
Key Responsibilities
Serve as a SOC analysis & Tier 3 escalation point for complex security incidents, performing deep-dive investigation, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.
Design, build, and maintain detection analytics, dashboards, and hunting queries (Falcon Query Language / FQL) within Crowd Strike Falcon, tuning correlation rules and detection logic to reduce false positives and improve mean-time-to-detect (MTTD).
Architect and maintain security orchestration, automation, and response (SOAR) playbooks in Torq, integrating Crowd Strike Falcon, identity providers, ticketing, and communication platforms into automated response workflows.
Design AI-assisted analyst workflows (e.g., automated triage summarization, alert enrichment, playbook drafting) using approved generative AI tooling, ensuring all inputs are sanitized and free of regulated or case-specific data.
Lead incident response efforts for high-severity events, coordinating with IT, legal, and divisional stakeholders while strictly adhering to FTI/CJI handling restrictions.
Develop and maintain detection engineering documentation, runbooks, and standard operating procedures (SOPs) for Tier 1/Tier 2 analyst use.
Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts; review and validate their investigative work and escalation quality.
Continuously evaluate and integrate emerging SOC automation and AI capabilities, presenting proposals for tooling changes with documented risk and compliance analysis.
Participate in an on-call rotation for critical incident escalations.
The above job description and requirements are general in nature and may be subject to change based on the specific needs and requirements of the organization and project.
CANDIDATE SKILLS AND QUALIFICATIONS
Requirements
8 years Required - Progressive SOC / security operations experience, including 2+ years functioning at a Tier 3 / senior analyst or detection engineering level.
8 years Required - Hands-on production experience with Crowd Strike Falcon (Insight XDR, Discover, and/or Fusion SOAR), including custom detection/IOA authoring, Falcon Query Language (FQL) use, and dashboard development.
8 years Required - Demonstrated experience building or maintaining SOAR automation (Torq strongly preferred).
8 years Required - Practical, hands-on experience using AI/LLM tools (e.g., Claude, GPT-based tools) to support security operations, with clear understanding of data sanitization and safe-use boundaries in a regulated environment.
8 years Required - Working knowledge of Zero Trust architecture principles (NIST 800-207) and general familiarity with regulatory frameworks such as IRS Pub. 1075, FBI CJIS Policy, and HIPAA.
8 years Required - Strong scripting/automation ability…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×