OAG - Entp Information Security | Cybersecurity Analyst IV | 26-0675

CAPPS

$108K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 9+ years of SOC/security operations experience, including 2 years in a senior analyst or detection engineering role
  • Hands-on experience with CrowdStrike Falcon and custom detection authoring
  • Experience building or maintaining SOAR automation, preferably with Torq
  • Solid understanding of MITRE ATT&CK, incident response lifecycle, and threat intelligence
  • Practical experience using AI tools for security operations while ensuring data safety in compliance with regulations

Responsibilities

  • Serve as Tier 3 escalation point for complex security incidents, conducting investigations and threat hunting
  • Design and maintain detection analytics and dashboards within CrowdStrike Falcon
  • Architect SOAR playbooks in Torq, integrating various platforms into automated workflows
  • Implement AI-assisted analyst workflows for triage and alert enrichment
  • Lead incident response for high-severity events, coordinating across IT and legal teams
  • Develop SOPs and documentation for Tier 1/Tier 2 analyst training
  • Continuously evaluate and integrate emerging SOC automation and AI capabilities

Benefits

  • Flexible telework options based on agency's plan
  • Supportive work environment focused on professional development
  • Opportunity to impact state security operations directly
  • Involvement in cutting-edge AI and SOC automation initiatives
  • Potential for hands-on work with advanced cybersecurity tools and frameworks
Full Job Description
Job Description

GENERAL DESCRIPTION

The Office of the Attorney General (OAG) is seeking a seniorlevel AI Cyber Automation Engineer / Tier 3 SOC Analyst to strengthen detection, response, and orchestration capabilities across the agency's security operations. This role blends deep SOC investigative expertise with handson security automation engineering, focusing on CrowdStrike Falcon and Torq to build scalable, AIassisted detection and response workflows. The ideal candidate has practical experience integrating large language model (LLM) tools such as Claude into security operations, for triage acceleration, playbook generation, and analyst augmentation, while operating within a strict Zero Trust, defenseindepth security posture appropriate to a state Attorney General's office. This position operates in an environment governed by IRS Publication 1075 (FTI), FBI CJIS Security Policy, and Texas Government Code requirements.

ESSENTIAL POSITION FUNCTIONS
  • Serve as a SOC analysis & Tier 3 escalation point for complex security incidents, performing deepdive investigation, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.
  • Design, build, and maintain detection analytics, dashboards, and hunting queries (Falcon Query Language / FQL) within CrowdStrike Falcon, tuning correlation rules and detection logic to reduce false positives and improve meantimetodetect (MTTD).
  • Architect and maintain security orchestration, automation, and response (SOAR) playbooks in Torq, integrating Sentinel, EDR, identity providers, ticketing, and communication platforms into automated response workflows.
  • Design AIassisted analyst workflows (e.g., automated triage summarization, alert enrichment, playbook drafting) using approved generative AI tooling, ensuring all inputs are sanitized and free of regulated or casespecific data.
  • Lead incident response efforts for highseverity events, coordinating with IT, legal, and divisional stakeholders while
    strictly adhering to FTI/CJI handling restrictions.
  • Develop and maintain detection engineering documentation, runbooks, and standard operating procedures (SOPs) for Tier 1/Tier 2 analyst use.
  • Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts; review and validate their investigative work and escalation quality.
  • Continuously evaluate and integrate emerging SOC automation and AI capabilities, presenting proposals for tooling changes with documented risk and compliance analysis.
  • Participate in an oncall rotation for critical incident escalations. May require afterhours availability for critical incident response.
  • Subject to session logging, audit review, and monitoring in accordance with Texas Government Code and applicable federal security requirements.
  • Performs related work as assigned.
  • Maintains relevant knowledge necessary to perform essential job functions.
  • Attends work regularly in compliance with agreedupon work schedule. Telework schedules are permitted for employees based on the agency's approved Telework Plan, if schedule does not adversely affect operations and service levels, and standard hours of operation are maintained.
  • Ensures security and confidentiality of sensitive and/or protected information.
  • Complies with all agency policies and procedures, including those pertaining to ethics and integrity.

MINIMUM QUALIFICATIONS
  • Education: Graduation from high school or equivalent
  • Experience: Nine years of fulltime experience in progressive SOC / security operations experience, including 2 years as functioning at a Tier 3 / senior analyst or detection engineering level; may substitute credit hours from an accredited college or university for the required experience on a yearforyear basis
  • Handson production experience with CrowdStrike Falcon (Insight XDR, Discover, and/or Fusion SOAR), including custom detection/IOA authoring, Falcon Query Language (FQL) use, and dashboard development.
  • Demonstrated experience building or maintaining SOAR automation (Torq strongly preferred)
  • Solid understanding of the MITRE ATT&CK framework, incident response lifecycle, and threat intelligence integration.
  • Practical, handson experience using AI/LLM tools (e.g., Claude, GPTbased tools) to support security operations, with clear understanding of data sanitization and safeuse boundaries in a regulated environment.
  • Working knowledge of Zero Trust architecture principles (NIST 800207) and general familiarity with regulatory frameworks such as IRS Pub. 1075, FBI CJIS Policy, and HIPAA.
  • Strong scripting/automation ability (PowerShell, Python, or Falcon Query Languagebased automation) for building custom detections and integrations.
  • Excellent written communication skills for incident reporting, runbook authorship, and crossdivisional coordination.
  • Ability to obtain and maintain a Texas state government background clearance.
  • Skill in exercising sound judgment and effective decision making.
  • Skill in effective oral and written communication.
  • Ability to handle multiple tasks, prioritize, and meet deadlines.
  • Ability to gather, assemble, correlate, and analyze facts; to devise solutions to problems.
  • Ability to develop, evaluate, and interpret policies and procedures.
  • Ability to train others.
  • Ability to receive and respond positively to constructive feedback.
  • Ability to work cooperatively with others in a professional office environment.
  • Ability to provide excellent customer service.
  • Ability to arrange for personal transportation for businessrelated travel.
  • Ability to work more than 40 hours as needed and in compliance with the FLSA.
  • Ability to lift and relocate 30 lbs.
  • Ability to travel (including overnight travel) up to 5%

PREFERRED QUALIFICATIONS
  • Education: Bachelor's degree in Computer Science, Information Security, or related field; may substitute credit hours from an accredited college or university for the required experience on a yearforyear basis
  • CrowdStrike Certified Falcon Responder (CCFR) or CrowdStrike Certified Falcon Administrator (CCFA), or equivalent CrowdStrike security certification.
  • Torq certification or demonstrated portfolio of built automation workflows.
  • Experience in government, legal, or lawenforcementadjacent security environments
  • Experience designing AIassisted playbooks or analyst copilots for SOC use cases while maintaining strict datahandling guardrails.
  • GIAC certifications (GCIH, GCIA, GCFA) or equivalent.
  • Familiarity with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One / cloud security posture management (CSPM) tooling.

TO APPLY

To apply for a job with the OAG, electronic applications can be submitted through CAPPS Recruit. A State of Texas application must be completed to be considered, and paper applications are not accepted. Your application for this position may subject you to a criminal background check pursuant to the Texas Government Code. Military Crosswalk information can be accessed at

https://hr.sao.texas.gov/Compensation/MilitaryCrosswalk/MOSC_InformationTechnology.pdf

Similar Jobs

More Jobs at CAPPS

More Information Technology Jobs

Find similar OAG - Entp Information Security | Cybersecurity Analyst IV | 26-0675 jobs: