Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Defender for Cloud Engineer

Openkyber

DirectClient: Office of the Attorney General of Texas(OpenKyber) Solicitation Number: 302CSD2702 Title: CrowdStrike SOC Analyst Location: 5500 E. Oltorf St, Austin, TX 78741 Duration: 9/1/2026 to 8/31/2027 with possible extension Last date for submission: August 11 2026 (12.00 PM-CST) Important Note: The working position is Telework. Texas local candidates only.

DESCRIPTION OF SERVICES: The Office of the Attorney General (OpenKyber) is seeking a senior-level Security Operations Analyst to strengthen detection, response, and orchestration capabilities across the agency's security operations. This role blends deep SOC (Security Operations Center) investigative expertise with hands-on security automation engineering, focusing on CrowdStrike Falcon and Torq to build scalable, AI-assisted detection and response workflows. The ideal candidate has practical experience integrating large language model (LLM) tools such as Claude into security operations - for triage acceleration, playbook generation, and analyst augmentation - while operating within a strict Zero Trust, defense-in-depth security posture appropriate to a state Attorney General's office.

Key Responsibilities

  • Serve as a SOC analysis & Tier 3 escalation point for complex security incidents, performing deep-dive investigation, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.
  • Design, build, and maintain detection analytics, dashboards, and hunting queries (Falcon Query Language / FQL) within CrowdStrike Falcon, tuning correlation rules and detection logic to reduce false positives and improve mean-time-to-detect (MTTD).
  • Architect and maintain security orchestration, automation, and response (SOAR) playbooks in Torq, integrating CrowdStrike Falcon, identity providers, ticketing, and communication platforms into automated response workflows.
  • Design AI-assisted analyst workflows (e.g., automated triage summarization, alert enrichment, playbook drafting) using approved generative AI tooling, ensuring all inputs are sanitized and free of regulated or case-specific data.
  • Lead incident response efforts for high-severity events, coordinating with IT, legal, and divisional stakeholders while strictly adhering to FTI/CJI handling restrictions.
  • Develop and maintain detection engineering documentation, runbooks, and standard operating procedures (SOPs) for Tier 1/Tier 2 analyst use.
  • Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts; review and validate their investigative work and escalation quality.
  • Continuously evaluate and integrate emerging SOC automation and AI capabilities, presenting proposals for tooling changes with documented risk and compliance analysis.
  • Participate in an on-call rotation for critical incident escalations.

The above job description and requirements are general in nature and may be subject to change based on the specific needs and requirements of the organization and project.

CANDIDATE SKILLS AND QUALIFICATIONS Minimum Requirements:

  • 8 Required Progressive SOC / security operations experience, including 2+ years functioning at a Tier 3 / senior analyst or detection engineering level.
  • 8 Required Hands-on production experience with CrowdStrike Falcon (Insight XDR, Discover, and/or Fusion SOAR), including custom detection/IOA authoring, Falcon Query Language (FQL) use, and dashboard development.
  • 8 Required Demonstrated experience building or maintaining SOAR automation (Torq strongly preferred)
  • 8 Required Practical, hands-on experience using AI/LLM tools (e.g., Claude, GPT-based tools) to support security operations, with clear understanding of data sanitization and safe-use boundaries in a regulated environment.
  • 8 Required Working knowledge of Zero Trust architecture principles (NIST 800-207) and general familiarity with regulatory frameworks such as IRS Pub. 1075, FBI CJIS Policy, and HIPAA.
  • 8 Required Strong scripting/automation ability (PowerShell, Python, or Falcon Query Language-based automation) for building custom detections and integrations.
  • 8 Required Excellent written communication skills for incident reporting, runbook authorship, and cross-divisional coordination.
  • 8 Required Experience documenting investigations, creating hunt reports, and communicating technical findings to diverse audiences.
  • 8 Required Strong analytical, problem-solving, and critical-thinking skills
  • 8 Required Ability to work independently while collaborating effectively within cross-functional cybersecurity teams.
  • 8 Required Ability to resolve complex security issues in diverse and decentralized environments; learn, communicate, teach new security technologies; and communicate effectively.
  • 8 Required Conduct forensic investigations on cyberattacks to determine how they occurred and can be prevented in the future.
  • 8 Required Experience creating/reviewing/updating security policies and standards for the public/private/hybrid cloud contexts.
  • 4 Required Bachelor's degree in Computer Science, Information Security, or related field, or equivalent professional experience.
  • 1 Preferred GIAC certifications (GCIH, GCIA, GCFA) or equivalent.
  • 1 Preferred CrowdStrike Certified Falcon Responder (CCFR) or CrowdStrike Certified Falcon Administrator (CCFA), or equivalent CrowdStrike security certification.
  • 1 Preferred Torq certification or demonstrated portfolio of built automation workflows
  • 1 Preferred Experience designing AI-assisted playbooks or analyst copilots for SOC use cases while maintaining strict data-handling guardrails.
  • 1 Preferred Familiarity with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One / cloud security posture management (CSPM) tooling.
  • 1 Preferred Experience in government, legal, or law-enforcement-adjacent security environments

For applications and inquiries, contact:View email address on us.fitly.work

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Defender for Cloud Engineer in Virgin Islands vacancy
  • $90 per hour

     ...Role Software Engineer (AI Agent Platform): Location San Jose, CA (Onsite) Client - OpenKyber Rate - $90 Interview Mode - Face to Face...  ...( Docker , Kubernetes ), and at least one major cloud platform ( AWS , Azure , or Google Cloud Platform ). Experience... 
    Suggested

    Openkyber

    Virgin Islands
    1 day ago
  •  ...automated environment Experience with data storage and data backup technologies Knowledge of baseline and operations inside a cloud environment Experience with Infrastructure as Code (IAC) tools (e.g. Chef, Puppet and Ansible) and fluency in the associated... 
    Suggested
    Full time
    Remote work
    Flexible hours

    Openkyber

    Virgin Islands
    1 day ago
  • $60 per hour

     ...Role : Core Platform Engineer Location : Charlotte-Concord-Gastonia, NC-SC (Hybrid) Rate: $60/hr Core Platform Engineer Primary Role: Build and maintain secure, scalable infrastructure and services. Responsibilities: Support a highly available... 
    Suggested

    Openkyber

    Virgin Islands
    1 day ago
  •  ...embedded natively across CI/CD pipelines at enterprise scale (500+ engineering teams). - Sigstore - Production-level implementation of...  ...distributed system failure experimentation across microservices and cloud-native workloads - Azure Confidential Computing - Architecture... 
    Suggested
    Remote work
    Visa sponsorship

    Openkyber

    Virgin Islands
    1 day ago
  •  ...lead efforts to architect, manage, and optimize Azure and Oracle Cloud infrastructure to ensure it meets the firm's business needs....  ...procedures. Responsibilities will include: Lead cloud engineering initiatives and collaborate with cross-functional teams to... 
    Suggested

    Openkyber

    Virgin Islands
    1 day ago
  •  ...features Drive architectural standards across managed/unmanaged packages, permission set design, integration patterns, and Data Cloud deployment practices "OpenKyber is an Equal Opportunity Employer and does not discriminate in employment on the basis of... 

    Openkyber

    Virgin Islands
    1 day ago
  •  ...Job Description Job Description Job Title Telecom Electrical Engineer Department Critical Facilities & Wireless Network Engineering Location USVI Reports to Director of Wireless & Critical Facilities Grade: 22 Job Code: Type of... 
    Full time
    Part time
    Remote work
    Flexible hours
    Night shift

    ATN International Inc

    Virgin Islands
    9 days ago
  •  ...markets.As part of the HFW companies network, the combined firm is supported by a national platform of award-winning architecture and engineering companies focused on delivering visionary infrastructure and design solutions. HFW's growing network includes more than 700... 
    Local area
    Relocation
    Relocation package

    HFW Companies

    Virgin Islands
    10 days ago
  •  ...Navy’s high-tech fleet of ships, aircraft, equipment, and personnel. At the center of these projects is a talented group of Civil Engineers who help to ensure that each initiative is conceived, planned and completed on time, in budget and according to specification. If... 
    Civilian Contractor
    Full time
    Contract work
    Part time
    Work at office

    U.S. Navy

    Virgin Islands
    14 hours ago
  •  ...position, candidates must either reside on St. Thomas or be able to relocate before the start date. Job Summary: The Maintenance Engineer is responsible for ensuring quality and efficient general facility and equipment maintenance under minimum supervision, as well... 
    Work experience placement
    Relocation
    Shift work
    Night shift
    Weekend work

    Harborside Corporation

    Virgin Islands
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Defender for Cloud Engineer. Be the first to apply!