Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior SOC Analyst — Advanced Incident Response & CrowdStrike Engineering

$115k - $154k

Biogen Idec

About This RoleThis is a individual contributor role and the technical backbone of Biogen's Security Operations Center — an analyst who leads complex incident investigations, engineers and optimizes the CrowdStrike Falcon platform across advanced modules (AIDR, Data Security, NG-SIEM, Identity Protection), and extends detection capabilities into operational technology (OT) environments supporting pharmaceutical manufacturing.You will own the most complex escalations, build the detection logic that catches what others miss, and serve as the bridge between IT security operations and OT/manufacturing environments. This is not a monitoring role — it is an engineering and investigation role that happens to sit in the SOC.Why This Role ExistsBiogen's threat landscape demands deeper investigative capability — advanced persistent threats, insider risk, and pharmaceutical IP targeting require an analyst who can conduct full-spectrum forensic investigations and threat huntingCrowdStrike Falcon is our primary detection and response platform — we need an engineer who can maximize the value of AIDR, Data Security, NG-SIEM (LogScale), and Identity Protection modules beyond default configurationsIT/OT convergence in our manufacturing environments creates unique detection challenges — DeltaV/DCS systems, GxP-regulated processes, and industrial protocols require specialized security monitoringKey ResponsibilitiesAdvanced Incident Response & Investigations (40%)Lead complex, multi-stage incident investigations from initial detection through containment, eradication, recovery, and lessons learnedConduct deep-dive forensic analysis: memory forensics (Volatility), disk forensics, network artifact analysis, and malware triage to determine attacker TTPsPerform kill chain reconstruction — map attacker activity to MITRE ATT&CK, identify lateral movement paths, persistence mechanisms, and data staging/exfiltration techniquesDevelop and execute proactive threat hunts based on intelligence, behavioral anomalies, and hypothesis-driven analysis across endpoint, network, identity, and cloud telemetryProduce actionable incident reports with root cause analysis, business impact assessment, and concrete remediation recommendationsCrowdStrike Falcon Platform Engineering (35%)Engineer, tune, and operationalize these Falcon modules:NG-SIEM (LogScale)Develop and maintain CQL (CrowdStrike Query Language) queries for advanced correlation, threat hunting, and detection rulesBuild custom dashboards, scheduled searches, and automated alerting pipelinesOptimize log ingestion, parsing, and retention policies across all telemetry sourcesCreate detection-as-code workflows — version-controlled queries that map to MITRE ATT&CK coverage gapsAIDR (AI Detection & Response)Configure and tune AI-driven detection policies for prompt injection, data leakage, and shadow AI usageBuild custom rules to monitor GenAI application interactions across endpoints and cloud workloadsAssess and respond to AI-specific threats: model poisoning indicators, unauthorized AI tool installations, sensitive data in AI promptsIntegrate AIDR telemetry into investigation workflows and incident playbooksIdentity ProtectionEngineer identity-based detection rules: Kerberoasting, credential stuffing, lateral movement via pass-the-hash/ticket, suspicious service account behaviorConfigure conditional access policies, risk-based authentication enforcement, and identity threat hunting queriesMonitor Active Directory attack paths and privilege escalation techniques (DCSync, Golden Ticket, NTLM relay)Coordinate with IAM team on identity hygiene findings and remediation prioritiesData Security (Data Protection)Configure data classification policies and egress monitoring rules for sensitive content (IP, PII, regulated data)Tune anomaly detection for unusual data movement patterns: bulk downloads, new destination usage, abnormal upload volumesBuild response workflows for data exfiltration alerts — user notification, manager escalation, automatic evidence preservationDefine and enforce policies for removable media, cloud storage, and web upload channelsPlatform AdministrationManage sensor deployment health, prevention policies, and RBAC across 25,000+ endpointsDevelop custom IOA (Indicator of Attack) rules and behavioral detections tailored to Biogen's environmentBuild and maintain Falcon Fusion (SOAR) workflows for automated containment and enrichmentCoordinate with CrowdStrike OverWatch for managed hunting findings and recommended actionsOT/ICS Security Operations (25%)Extend SOC monitoring into operational technology environments supporting pharmaceutical manufacturing (DeltaV DCS, SCADA, PLCs, HMIs)Develop and tune detection rules for OT-specific threats: unauthorized engineering workstation access, controller logic changes, anomalous industrial protocol traffic (Modbus, EtherNet/IP, OPC-UA)Maintain and enforce IT/OT network segmentation aligned with the Purdue Reference Model — monitor for segmentation bypass attemptsLead incident response for OT security events in coordination with Process Automation, Engineering, and Plant Operations teamsSupport OT asset inventory maintenance and vulnerability management in GxP-regulated environments (21 CFR Part 11, cGMP considerations)Conduct tabletop exercises for OT-specific scenarios (ransomware impacting batch processing, unauthorized remote access to control systems)Required QualificationsExperienceBachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field required; advanced degree preferred3-5+ years in Security Operations, Incident Response, or Threat Hunting with progressive responsibility3+ years hands-on experience with CrowdStrike Falcon platform in an engineering/administration capacity (not just alert triage)Demonstrated experience leading complex incident investigations involving APT, ransomware, insider threats, or supply chain compromiseExperience with OT/ICS security monitoring, industrial environments, or manufacturing cybersecurityTrack record of building detection rules, SIEM correlation logic, or behavioral analytics that caught real threatsTechnical SkillsCrowdStrike Falcon: NG-SIEM (LogScale/CQL), AIDR, Identity Protection, Data Security, Falcon Fusion, Real Time Response, custom IOA developmentForensics: memory analysis (Volatility), disk forensics, network forensics, malware triage/reverse engineering fundamentalsThreat Hunting: hypothesis-driven hunts, MITRE ATT&CK mapping, behavioral analysis across endpoint/network/identity/cloud telemetryScripting & Automation: Python and PowerShell for investigation tooling, data parsing, API integrations, and SOAR playbook developmentNetwork Security: deep understanding of TCP/IP, DNS, lateral movement protocols (SMB, RDP, WMI, WinRM), and packet analysisIdentity Security: Active Directory attack techniques, Kerberos/NTLM fundamentals, privilege escalation paths, identity-based detectionOT/ICS: familiarity with industrial protocols (Modbus, EtherNet/IP, OPC-UA), Purdue Model architecture, DCS/SCADA security principlesCertifications (Preferred — not all required)CrowdStrike: CCFA (Falcon Administrator), CCFR (Falcon Responder), CCFH (Falcon Hunter)SANS/GIAC: GCFA, GCIH, GREM, GCIA, or GNFAOT/ICS: GICSP (Global Industrial Cyber Security Professional) or GRID (Response and Industrial Defense)General: CISSP, CySA+, or equivalentPreferred QualificationsExperience in pharmaceutical, biotech, or life sciences environments with GxP-regulated systemsFamiliarity with DeltaV DCS, batch automation systems, or laboratory automation securityExperience with CrowdStrike NG-SIEM migration, parser development, or LogScale administrationBackground in detection engineering as code (version-controlled detections, CI/CD for security content)Experience coordinating with CrowdStrike OverWatch or similar managed hunting servicesJob Level: ManagementAdditional InformationThe base compensation range for this role is: $115,000.00-$154,000.00Base salary offered is determined through an analytical approach utilizing a combination of factors including, but not limited to, relevant skills & experience, job location, and internal equity.Regular employees are eligible to receive both short term and long-term incentives, including cash bonus and equity incentive opportunities, designed to reward recent achievements and recognize your future potential based on individual, business unit and company performance. In addition to compensation, Biogen offers a full and highly competitive range of benefits designed to support our employees’ and their families physical, financial, emotional, and social well-being; including, but not limited to:Medical, Dental, Vision, & Life insurancesFitness & Wellness programs including a fitness reimbursement Short- and Long-Term Disability insuranceA minimum of 15 days of paid vacation and an additional end-of-year shutdown time off (Dec 26-Dec 31)Up to 12 company paid holidays + 3 paid days off for Personal Significance 80 hours of sick time per calendar yearPaid Maternity and Parental Leave benefit 401(k) program participation with company matched contributionsEmployee stock purchase plan Tuition reimbursement of up to $10,000 per calendar year Employee Resource Groups participationWhy Biogen?We are a global team with a commitment to excellence, and a pioneering spirit. As a mid-sized biotechnology company, we provide the stability and resources of a well-established business while fostering an environment where individual contributions make a significant impact. Our team encompasses some of the most talented and passionate achievers who have unparalleled opportunities for learning, growth, and expanding their skills. Above all, we work together to deliver life-changing medicines, with every role playing a vital part in our mission. Caring Deeply. Achieving Excellence. Changing Lives.At Biogen, we are committed to building on our culture of inclusion and belonging that reflects the communities where we operate and the patients we serve. We know that diverse backgrounds, cultures, and perspectives make us a stronger and more innovative company, and we are focused on building teams where every employee feels empowered and inspired. Read on to learn more about our Biogen.All qualified applicants will receive consideration for employment without regard to sex, gender identity or expression, sexual orientation, marital status, race, color, national origin, ancestry, ethnicity, religion, age, veteran status, disability, genetic information or any other basis protected by federal, state or local law. Biogen is an E-Verify Employer in the United States.SummaryLocation: Research Triangle Park, NCType: Full time

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Senior SOC Analyst — Advanced Incident Response & CrowdStrike Engineering in North Carolina vacancy
  •  ...make a difference! The Senior SOC Analyst is an experienced cybersecurity professional responsible for handling complex and high...  ...priority security inquiries, incidents, and service requests. Acting...  ...equivalent experience). ~ Advanced knowledge of SOC operations,... 
    Senior
    Flexible hours
    Shift work
    Weekend work

    N-able Technologies, Inc.

    Morrisville, NC
    1 day ago
  • $80.2k - $111.3k

     ...Overview The Cybersecurity Incident Response Engineer, Senior leads complex incident...  ...automation, custom scripting, and advanced defensive engineering, to...  ...countermeasures, enhances SOC tooling and integrations,...  ...incident handlers and SOC analysts, elevating investigative... 
    Senior
    Contract work
    Work experience placement
    Work at office

    ASM Research, An Accenture Federal Services Company

    Raleigh, NC
    4 days ago
  • $95.7k - $144.9k

     ...every connection. We do this by driving Responsible Growth and delivering for our clients, teammates...  ...who would like to join one of the most advanced cybersecurity teams in the world.• We...  ...candidates with malware analysis and incident response experience. • Specific... 
    Suggested
    Full time
    Work at office
    Flexible hours
    Day shift

    Bank of America

    Denver, NC
    9 hours ago
  • Labcorp in Durham, NC, is seeking a Security Operations Center (SOC) Senior Manager to lead a 24/7 security operations team. This role involves enhancing Labcorp's detection and response strategies and ensuring compliance with security regulations. The ideal candidate... 
    Senior

    Labcorp

    Durham, NC
    4 days ago
  •  ...Senior Cybersecurity Incident Response Administrator (Information Assurance Engineer - Senior) Position is contingent upon contract award and funding. Sev1Tech is looking for a Senior Cybersecurity Incident Response Administrator (Information Assurance Engineer - Senior... 
    Senior
    Contract work

    Sev1Tech

    Fort Bragg, NC
    3 days ago
  •  ...The Incident Response Coordinator, Senior leads tactical coordination of complex IT incidents to minimize mission...  ..., Release, Service Continuity, and SOC/Cyber IR where service impact/...  ...understanding of ITIL principles and advanced incident management and response best... 
    Senior
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Raleigh, NC
    4 days ago
  •  ...inquiries won't receive a response).Regular or Temporary:...  ...The Cyber Hunt & Respond Senior Engineer is a senior-level cybersecurity...  ...Center responsible for advanced threat hunting and incident response activities. This...  ...Operations Centers (SOC), Network Operations Centers... 
    Senior
    Permanent employment
    Full time
    Part time
    H1b
    Work at office
    Work visa
    Shift work
    Night shift
    Day shift

    Truist

    Zebulon, NC
    2 days ago
  •  ...serve, we provide planning, engineering, and infrastructure...  ...Opportunity We're looking for a Senior Noise Analyst to manage our mid-Atlantic...  ...clients. The position will be responsible for providing expertise in...  ...and client relationships to advance communities everywhere, so... 
    Senior
    Full time
    Contract work
    Temporary work
    Part time
    Casual work
    Work at office
    Local area
    Flexible hours

    Stantec Consulting International Ltd.

    Raleigh, NC
    1 day ago
  • $105.4k - $207.8k

     ...will have 5+ years of experience in Cyber Incident Response. This role involves supporting our...  ...deployment of solutions and services to advance Deloitte Cyber's Crisis & Incident Response...  ...From entry-level employees to senior leaders, we believe there’s always room... 
    Senior
    Local area
    Visa sponsorship

    Deloitte

    Charlotte, NC
    3 days ago
  • $125k - $155k

    Company DescriptionPosition: Senior Data Center ConsultantEYP...  ...Facilities, part of Ramboll Americas Engineering, is an innovator and a...  ...rely on EYP MCF to provide responsive solutions to today’s complex...  ...one or more of the following advanced requirements: Applicable... 
    Senior
    Work at office
    Local area
    Home office
    Flexible hours

    Ramboll Management Consulting

    Charlotte, NC
    9 hours ago
  • $126k - $204.5k

     ...Champion proactive automation, engineering sophisticated playbooks to...  ..., and sophisticated response automation.Qualifications 5+...  ...of hands-on experience in a Senior SOC, Detection Engineering, or Security...  ...requests.Strong background in incident response, threat hunting,... 
    Senior
    Full time
    Remote work
    Visa sponsorship
    Work visa

    Palo Alto Networks

    Charlotte, NC
    2 days ago
  • $110k - $125k

     ...human expertise to make advanced real-time...  ...Ultraviolet Cyber is seeking a SOC Analyst to join our Federal...  ...SOC) Analysts will be responsible for 24/7 threat monitoring, analysis, and incident response across a large...  ...with Security Engineering to implement. Collect... 
    Full time
    Temporary work
    Remote work
    Monday to Friday

    GrabJobs

    Charlotte, NC
    1 day ago
  • $142.9k - $266k

    Cyber Incident Response Business Development Senior ManagerThe Opportunity:Join a team to contribute to Booz Allen's growth efforts for its Incident Response...  ...an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity... 
    Senior
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Jacksonville, NC
    3 days ago
  •  ...Information Security Analyst II If you're passionate...  ...teams. As a SOC Analyst II, you will...  ...security monitoring and incident response efforts within a...  ...Center experience ~ Advanced experience with penetration...  ..., threat detection engineering, or digital forensics... 
    Full time
    Fixed term contract
    Work at office

    WGU

    Raleigh, NC
    1 day ago
  • QUALIFICATIONSUndergraduate degree: advanced degree is a plus ideally in a quantitative discipline...  ..., economics, operations research, engineering, computer science) or a healthcare...  ...colleaguesAbility to synthesize complex issues, engage senior leaders, and drive consensusExposure to... 
    Senior
    Apprenticeship
    Easy work

    McKinsey & Company

    Charlotte, NC
    4 days ago
  • $118.3k - $219.8k

     ...deploying AI and advanced technologies to the...  ...the Role : As a Senior Consulting Principal AWS Cloud Engineer, you will provide...  ...strategy. Responsibilities : Enterprise Cloud...  ...management, ensuring SOC 2, HIPAA, PCI-DSS,...  ..., enhancing incident response, automated... 
    Senior
    Temporary work
    Local area
    Immediate start
    Remote work
    Flexible hours

    LexisNexis

    Raleigh, NC
    1 day ago
  •  ...100 manufacturing and engineering innovator that provides...  ...technology is driving advances in medical...  ...The Financial Reporting Analyst at BWXT ensures the accuracy...  ...Your Day to Day as a Senior Financial Reporting Analyst...  ...(BWXT) is not responsible for and does not accept... 
    Senior
    For contractors
    Local area
    Flexible hours
    3 days per week

    Nuclear Fuel Services

    Charlotte, NC
    1 day ago
  • $136.5k - $253.5k

     ...products. As a Physical Design Senior Principal Hardware Engineer, you will drive solutions...  ...platform is the most advanced industry-leading...  ...core technology team.Key Responsibilities:The duties and responsibilities...  ...owned and driven blocks/SoCs to tape-outComfortable in... 
    Senior
    Full time

    Cadence Design Systems

    Cary, NC
    4 days ago
  •  ...organizations of all sizes to confidently advance scientific breakthroughs and introduce...  ...‑profile drug and device programs. Key Responsibilities Build and maintain Dagster‑orchestrated...  ...patterns. Collaborate with the lead engineer on design decisions and jointly own delivery... 
    Senior
    For contractors

    ProPharma

    Raleigh, NC
    3 days ago
  • Fox Rothschild is seeking a Senior Analyst for Cybersecurity Operations in Charlotte, NC. This role is vital...  ...supporting the Firm’s Cybersecurity Operations and Response program by assisting with security operations, incident response, and vulnerability management... 
    Senior

    Fox Rothschild

    Charlotte, NC
    13 hours ago
  • $119.8k - $234.7k

     ...Cloud Hardware, and Infrastructure Engineering (SCHIE) is the team behind...  ...expanding Cloud Infrastructure and responsible for powering Microsoft’s “Intelligent...  .... We are looking for a SoC Performance Verification Engineer - Senior to join the team.#SCHIEResponsibilitiesOwn... 
    Senior
    Ongoing contract
    Permanent employment
    Work at office
    Local area
    Worldwide
    3 days per week

    Microsoft

    Raleigh, NC
    9 hours ago
  • $171k - $227.8k

     ...Description Job Description Senior Analysts serve as technical leads on...  .... Senior staff members are responsible for ensuring technical...  ...Lead and manage complex engineering projects involving thermal...  ...methods Perform and review advanced FEA simulations using Abaqus... 
    Senior
    Temporary work
    Flexible hours

    SI Solutions, LLC

    Huntersville, NC
    14 days ago
  • $105k - $115k

     ...Senior Business Analyst Charlotte, NC, United States *This role requires...  ...partnering with Product, Engineering, and Business leaders to turn...  ...professional growth. Responsibilities: Partner with Product and...  ..., or a related field ~ Advanced SQL skills with demonstrated... 
    Senior
    Work at office
    Remote work
    Monday to Friday

    LendingTree

    Charlotte, NC
    4 hours ago
  •  ...marketing campaigns through advanced analytics, predictive modeling...  ...swift implementation. Responsibilities Translate marketing and business...  ...consensus and influence senior stakeholders to gain confidence...  ...MarTech, Data Science, Data Engineering and other analytics teams... 
    Senior
    Work experience placement

    慨正橡扯

    Charlotte, NC
    4 days ago
  • $75.04k - $112.56k

     ...Technology and more. Overview The Major Incident Management (MIM) Analyst is responsible for leading the response to major...  ...This includes communication with senior executives (e.g., CIO, CTO, SVP,...  ...Postgraduate degree or advanced training/certifications in relevant... 
    Full time
    Work at office
    Remote work
    Flexible hours

    ViziRecruiter

    Salisbury, NC
    5 days ago
  • $75.04k - $112.56k

     ...Store Code: Service Delivery - Incident & Escal (5145455) Primary...  ...Incident Management (MIM) Analyst is responsible for leading the response to...  ...communication with senior executives (e.g., CIO, CTO,...  ...Qualifications Postgraduate degree or advanced training/certifications in... 
    Full time
    Work at office
    Remote work
    Flexible hours

    Loyalty360

    Salisbury, NC
    5 days ago
  •  ...The Clearing House in North Carolina is seeking an Incident Management Analyst to coordinate the incident management process, particularly during major incidents. The successful applicant will analyze incident data, support resolution efforts, and assist in managing processes... 
    Work at office
    2 days per week
    3 days per week

    The Clearing House

    Raleigh, NC
    1 day ago
  • $112.5k - $147.5k

     ...a stakeholder.What you’ll be responsible for: Circle is looking for an experienced Senior Analyst, IT Internal Controls & SOX Compliance...  ...will partner closely with Engineering, Security, Finance, Compliance...  ...-party service providers for SOC reports.Reviewing and... 
    Senior
    Flexible hours

    Circle

    Raleigh, NC
    9 hours ago
  •  ...stakeholders on assigned transactions. Responsibilities:Deal Ownership & Execution: Build and own...  ...when to escalate to Directors or senior leadershipMust be able to travel based...  ...you are just starting out, looking to advance into management or searching for your next... 
    Senior
    Full time
    Work at office
    Local area
    Remote work
    Flexible hours

    Aprio

    Charlotte, NC
    4 days ago
  •  ...Geo Owl is seeking an Expert Full Spectrum GEOINT Analyst (TS/SCI) to perform complex imagery and MASINT...  ...PED of HSI/MSI, thermal, EO, SAR, and LiDAR, with advanced geospatial data management and training responsibilities. Ideal candidates have 8 years in PED of remotely... 
    Senior
    Remote work
    Worldwide

    Geo Owl LLC

    Raleigh, NC
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior SOC Analyst — Advanced Incident Response & CrowdStrike Engineering. Be the first to apply!