×
Register Here to Apply for Jobs or Post Jobs. X

Senior SOC Analyst — Advanced Incident Response & CrowdStrike Engineering

Job in Greensboro, Guilford County, North Carolina, 27497, USA
Listing for: Biogen
Full Time position
Listed on 2026-08-01
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 115000 - 154000 USD Yearly USD 115000.00 154000.00 YEAR
Job Description & How to Apply Below
About This Role This is a individual contributor role and the technical backbone of Biogen's Security Operations Center — an analyst who leads complex incident investigations, engineers and optimizes the Crowd Strike Falcon platform across advanced modules (AIDR, Data Security, NG-SIEM, Identity Protection), and extends detection capabilities into operational technology (OT) environments supporting pharmaceutical manufacturing.

You will own the most complex escalations, build the detection logic that catches what others miss, and serve as the bridge between IT security operations and OT/manufacturing environments. This is not a monitoring role — it is an engineering and investigation role that happens to sit in the SOC.Why This Role Exists Biogen's threat landscape demands deeper investigative capability — advanced persistent threats, insider risk, and pharmaceutical IP targeting require an analyst who can conduct full-spectrum forensic investigations and threat hunting

Crowd

Strike Falcon is our primary detection and response platform — we need an engineer who can maximize the value of AIDR, Data Security, NG-SIEM (Log Scale), and Identity Protection modules beyond default configurations IT/OT convergence in our manufacturing environments creates unique detection challenges — DeltaV/DCS systems, GxP-regulated processes, and industrial protocols require specialized security monitoring

Key Responsibilities Advanced Incident Response & Investigations (40%)Lead complex, multi-stage incident investigations from initial detection through containment, eradication, recovery, and lessons learned

Conduct deep-dive forensic analysis: memory forensics (Volatility), disk forensics, network artifact analysis, and malware triage to determine attacker TTPsPerform kill chain reconstruction — map attacker activity to MITRE ATT&CK, identify lateral movement paths, persistence mechanisms, and data staging/exfiltration techniques

Develop and execute proactive threat hunts based on intelligence, behavioral anomalies, and hypothesis-driven analysis across endpoint, network, identity, and cloud telemetry

Produce actionable incident reports with root cause analysis, business impact assessment, and concrete remediation recommendations

Crowd

Strike Falcon Platform Engineering (35%)Engineer, tune, and operationalize these Falcon modules:

NG-SIEM (Log Scale)
Develop and maintain CQL (Crowd Strike Query Language) queries for advanced correlation, threat hunting, and detection rules

Build custom dashboards, scheduled searches, and automated alerting pipelines

Optimize log ingestion, parsing, and retention policies across all telemetry sources

Create detection-as-code workflows — version-controlled queries that map to MITRE ATT&CK coverage gapsAIDR (AI Detection & Response)
Configure and tune AI-driven detection policies for prompt injection, data leakage, and shadow AI usage

Build custom rules to monitor GenAI application interactions across endpoints and cloud workloads

Assess and respond to AI-specific threats: model poisoning indicators, unauthorized AI tool installations, sensitive data in AI prompts

Integrate AIDR telemetry into investigation workflows and incident playbooks

Identity Protection Engineer identity-based detection rules:
Kerberoasting, credential stuffing, lateral movement via pass-the-hash/ticket, suspicious service account behavior

Configure conditional access policies, risk-based authentication enforcement, and identity threat hunting queries

Monitor Active Directory attack paths and privilege escalation techniques (DCSync, Golden Ticket, NTLM relay)
Coordinate with IAM team on identity hygiene findings and remediation priorities

Data Security (Data Protection)
Configure data classification policies and egress monitoring rules for sensitive content (IP, PII, regulated data)
Tune anomaly detection for unusual data movement patterns: bulk downloads, new destination usage, abnormal upload volumes

Build response workflows for data exfiltration alerts — user notification, manager escalation, automatic evidence preservation

Define and enforce policies for removable media, cloud storage, and web upload channels

Platform…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary