This is an urgent, hybrid role in Addison, TX with a large global healthcare and pharmaceutical services organization. The sits on a security operations team running CrowdStrike Falcon, a SIEM, and an email security gateway across an enterprise environment, with a focus on incident response, threat hunting, and detection.
They need someone who has already worked a SOC and is ready to step into the engineer seat. You will be the escalation point for junior analysts, support major incident response efforts, and tune the tooling that makes detection work. The team supports a global user base. If you are a SOC analyst or security engineer with a few years under your belt and want more ownership over incident response and detection, this is a strong step up.
Required Skills & Experience
Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a related field, or equivalent work experience
3 to 5 years of combined IT and cybersecurity experience, with time spent in a SOC or security engineering function
Experience with Splunk or a comparable SIEM for alert triage, correlation, and root cause analysis
Proven experience supporting major incident response activities and EDR detection and response
Strong written communication skills, with the ability to translate complex technical findings into clear language for non-technical stakeholders
Willingness to participate in an on-call rotation, including weekends
Desired Skills & Experience
Security certification such as CompTIA Security+, CySA+, or EC-Council CEH, or equivalent
Depth in digital forensics or threat hunting
Scripting experience in Python, PowerShell, or Bash
Experience developing detection rules and SOAR playbooks
Experience working with a managed detection and response provider
What You Will Be Doing
Tech Breakdown
30% EDR/XDR (CrowdStrike Falcon): detection, investigation, and response
25% SIEM (Splunk): alert triage, correlation, and log analysis
15% Email security gateway: phishing and email threat investigation
10% Threat hunting and MITRE ATT&CK-aligned analysis
10% Scripting and detection/SOAR playbook development
10% ServiceNow: incident documentation and ticketing
Daily Responsibilities
65% Hands On: Investigating and correlating suspicious events, determining root cause, supporting incident response, performing proactive and reactive threat hunting, and recommending changes to security controls and procedures
35% Team Collaboration: Guiding junior analysts on event monitoring, partnering with cross-functional teams, conducting business impact analysis, and participating in IR exercises and drills
Numbers & Facts
Location
Addison, TX
Skills
Analysis Skillsunmatched
Bash Scriptingunmatched
Biotech and Pharmaceuticalunmatched
Business impact analysis (BIA)unmatched
Communication Skillsunmatched
CompTIA - Computing Technology Industry Associationunmatched
CompTIA Security+unmatched
Computer Forensicsunmatched
Computer Scienceunmatched
Computer Securityunmatched
Cross-Functionalunmatched
EC-Councilunmatched
Email Securityunmatched
Huntingunmatched
IR (Infrared)unmatched
Incident Responseunmatched
Information Technology & Information Systemsunmatched
International Healthunmatched
Internet Securityunmatched
Machine Toolunmatched
On Callunmatched
Phishingunmatched
Python Programming/Scripting Languageunmatched
Root Cause Analysisunmatched
Scripting (Scripting Languages)unmatched
Security Analysisunmatched
Security Information and Event Management (SIEM)unmatched
Splunkunmatched
Windows PowerShellunmatched
Writing Skillsunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.