Biogen

Senior SOC Analyst - Advanced Incident Response & CrowdStrike Engineering

Biogen$115K — $154K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, or related field; advanced degree preferred.
  • 3-5+ years in Security Operations or Incident Response with progressive responsibility.
  • 3+ years hands-on experience with CrowdStrike Falcon platform engineering/admin.
  • Proven track record in leading complex incident investigations (APT, ransomware).
  • Experience with OT/ICS security monitoring or manufacturing cybersecurity.

Responsibilities

  • Lead deep-dive forensic investigations from detection to recovery.
  • Conduct memory/disk forensics and malware triage to decipher attacker behaviors.
  • Map attacker activity to MITRE ATT&CK and identify persistence mechanisms.
  • Execute proactive threat hunts based on intelligence and anomalies.
  • Produce actionable incident reports with analysis and remediation guidance.
  • Engineer and optimize CrowdStrike Falcon modules for advanced detection.
  • Extend SOC capabilities to monitor and secure operational technology environments.

Benefits

  • Medical, Dental, Vision, & Life insurances
  • Fitness & Wellness programs including a fitness reimbursement
  • 15 days of paid vacation plus additional end-of-year shutdown time off
  • Up to 12 company paid holidays and 3 personal significance days off
  • 401(k) program participation with company matched contributions
Full Job Description
About This Role

This is a individual contributor role and the technical backbone of Biogen's Security Operations Center - an analyst who leads complex incident investigations, engineers and optimizes the CrowdStrike Falcon platform across advanced modules (AIDR, Data Security, NG-SIEM, Identity Protection), and extends detection capabilities into operational technology (OT) environments supporting pharmaceutical manufacturing.

You will own the most complex escalations, build the detection logic that catches what others miss, and serve as the bridge between IT security operations and OT/manufacturing environments. This is not a monitoring role - it is an engineering and investigation role that happens to sit in the SOC.

Why This Role Exists
  • Biogen's threat landscape demands deeper investigative capability - advanced persistent threats, insider risk, and pharmaceutical IP targeting require an analyst who can conduct full-spectrum forensic investigations and threat hunting
  • CrowdStrike Falcon is our primary detection and response platform - we need an engineer who can maximize the value of AIDR, Data Security, NG-SIEM (LogScale), and Identity Protection modules beyond default configurations
  • IT/OT convergence in our manufacturing environments creates unique detection challenges - DeltaV/DCS systems, GxP-regulated processes, and industrial protocols require specialized security monitoring


Key Responsibilities
Advanced Incident Response & Investigations (40%)
  • Lead complex, multi-stage incident investigations from initial detection through containment, eradication, recovery, and lessons learned
  • Conduct deep-dive forensic analysis: memory forensics (Volatility), disk forensics, network artifact analysis, and malware triage to determine attacker TTPs
  • Perform kill chain reconstruction - map attacker activity to MITRE ATT&CK, identify lateral movement paths, persistence mechanisms, and data staging/exfiltration techniques
  • Develop and execute proactive threat hunts based on intelligence, behavioral anomalies, and hypothesis-driven analysis across endpoint, network, identity, and cloud telemetry
  • Produce actionable incident reports with root cause analysis, business impact assessment, and concrete remediation recommendations
CrowdStrike Falcon Platform Engineering (35%)

Engineer, tune, and operationalize these Falcon modules:

NG-SIEM (LogScale)
  • Develop and maintain CQL (CrowdStrike Query Language) queries for advanced correlation, threat hunting, and detection rules
  • Build custom dashboards, scheduled searches, and automated alerting pipelines
  • Optimize log ingestion, parsing, and retention policies across all telemetry sources
  • Create detection-as-code workflows - version-controlled queries that map to MITRE ATT&CK coverage gaps

AIDR (AI Detection & Response)
  • Configure and tune AI-driven detection policies for prompt injection, data leakage, and shadow AI usage
  • Build custom rules to monitor GenAI application interactions across endpoints and cloud workloads
  • Assess and respond to AI-specific threats: model poisoning indicators, unauthorized AI tool installations, sensitive data in AI prompts
  • Integrate AIDR telemetry into investigation workflows and incident playbooks

Identity Protection
  • Engineer identity-based detection rules: Kerberoasting, credential stuffing, lateral movement via pass-the-hash/ticket, suspicious service account behavior
  • Configure conditional access policies, risk-based authentication enforcement, and identity threat hunting queries
  • Monitor Active Directory attack paths and privilege escalation techniques (DCSync, Golden Ticket, NTLM relay)
  • Coordinate with IAM team on identity hygiene findings and remediation priorities

Data Security (Data Protection)
  • Configure data classification policies and egress monitoring rules for sensitive content (IP, PII, regulated data)
  • Tune anomaly detection for unusual data movement patterns: bulk downloads, new destination usage, abnormal upload volumes
  • Build response workflows for data exfiltration alerts - user notification, manager escalation, automatic evidence preservation
  • Define and enforce policies for removable media, cloud storage, and web upload channels

Platform Administration
  • Manage sensor deployment health, prevention policies, and RBAC across 25,000+ endpoints
  • Develop custom IOA (Indicator of Attack) rules and behavioral detections tailored to Biogen's environment
  • Build and maintain Falcon Fusion (SOAR) workflows for automated containment and enrichment
  • Coordinate with CrowdStrike OverWatch for managed hunting findings and recommended actions
OT/ICS Security Operations (25%)
  • Extend SOC monitoring into operational technology environments supporting pharmaceutical manufacturing (DeltaV DCS, SCADA, PLCs, HMIs)
  • Develop and tune detection rules for OT-specific threats: unauthorized engineering workstation access, controller logic changes, anomalous industrial protocol traffic (Modbus, EtherNet/IP, OPC-UA)
  • Maintain and enforce IT/OT network segmentation aligned with the Purdue Reference Model - monitor for segmentation bypass attempts
  • Lead incident response for OT security events in coordination with Process Automation, Engineering, and Plant Operations teams
  • Support OT asset inventory maintenance and vulnerability management in GxP-regulated environments (21 CFR Part 11, cGMP considerations)
  • Conduct tabletop exercises for OT-specific scenarios (ransomware impacting batch processing, unauthorized remote access to control systems)


Required Qualifications
Experience
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field required; advanced degree preferred
  • 3-5+ years in Security Operations, Incident Response, or Threat Hunting with progressive responsibility
  • 3+ years hands-on experience with CrowdStrike Falcon platform in an engineering/administration capacity (not just alert triage)
  • Demonstrated experience leading complex incident investigations involving APT, ransomware, insider threats, or supply chain compromise
  • Experience with OT/ICS security monitoring, industrial environments, or manufacturing cybersecurity
  • Track record of building detection rules, SIEM correlation logic, or behavioral analytics that caught real threats
Technical Skills
  • CrowdStrike Falcon: NG-SIEM (LogScale/CQL), AIDR, Identity Protection, Data Security, Falcon Fusion, Real Time Response, custom IOA development
  • Forensics: memory analysis (Volatility), disk forensics, network forensics, malware triage/reverse engineering fundamentals
  • Threat Hunting: hypothesis-driven hunts, MITRE ATT&CK mapping, behavioral analysis across endpoint/network/identity/cloud telemetry
  • Scripting & Automation: Python and PowerShell for investigation tooling, data parsing, API integrations, and SOAR playbook development
  • Network Security: deep understanding of TCP/IP, DNS, HTTP/TLS, lateral movement protocols (SMB, RDP, WMI, WinRM), and packet analysis
  • Identity Security: Active Directory attack techniques, Kerberos/NTLM fundamentals, privilege escalation paths, identity-based detection
  • OT/ICS: familiarity with industrial protocols (Modbus, EtherNet/IP, OPC-UA), Purdue Model architecture, DCS/SCADA security principles
Certifications (Preferred - not all required)
  • CrowdStrike: CCFA (Falcon Administrator), CCFR (Falcon Responder), CCFH (Falcon Hunter)
  • SANS/GIAC: GCFA, GCIH, GREM, GCIA, or GNFA
  • OT/ICS: GICSP (Global Industrial Cyber Security Professional) or GRID (Response and Industrial Defense)
  • General: CISSP, CySA+, or equivalent
Preferred Qualifications
  • Experience in pharmaceutical, biotech, or life sciences environments with GxP-regulated systems
  • Familiarity with DeltaV DCS, batch automation systems, or laboratory automation security
  • Experience with CrowdStrike NG-SIEM migration, parser development, or LogScale administration
  • Background in detection engineering as code (version-controlled detections, CI/CD for security content)
  • Experience coordinating with CrowdStrike OverWatch or similar managed hunting services


Job Level: Management

Additional Information

The base compensation range for this role is: $115,000.00-$154,000.00

Base salary offered is determined through an analytical approach utilizing a combination of factors including, but not limited to, relevant skills & experience, job location, and internal equity.

Regular employees are eligible to receive both short term and long-term incentives, including cash bonus and equity incentive opportunities, designed to reward recent achievements and recognize your future potential based on individual, business unit and company performance.

In addition to compensation, Biogen offers a full and highly competitive range of benefits designed to support our employees' and their families physical, financial, emotional, and social well-being; including, but not limited to:
  • Medical, Dental, Vision, & Life insurances
  • Fitness & Wellness programs including a fitness reimbursement
  • Short- and Long-Term Disability insurance
  • A minimum of 15 days of paid vacation and an additional end-of-year shutdown time off (Dec 26-Dec 31)
  • Up to 12 company paid holidays + 3 paid days off for Personal Significance
  • 80 hours of sick time per calendar year
  • Paid Maternity and Parental Leave benefit
  • 401(k) program participation with company matched contributions
  • Employee stock purchase plan
  • Tuition reimbursement of up to $10,000 per calendar year
  • Employee Resource Groups participation


Job Level: Management

About Biogen

Biogen is a biotechnology company engaged in the development of innovative therapies for neurological and neurodegenerative diseases. Biogen is developing a pipeline of possible medicines in neurology, neuropsychiatry, specialized immunology, and rare illness, and the company is laser-focused on its mission of helping humanity through science and building a healthier, more sustainable, and equitable world.

Biogen Careers

Join Biogen, a leader in biotechnology, and be part of a team that is dedicated to pioneering neurological and neurodegenerative diseases research. At Biogen, our mission is to lead the way in science and medicine, and we offer job opportunities that challenge and reward your professional growth. Work You’ll Do At Biogen, you will contribute to groundbreaking projects that help improve the lives of millions. Our commitment to innovation and leadership in the industry provides a dynamic environment for both seasoned professionals and those at the beginning of their career. With a variety of job opportunities ranging from research and development to marketing and sales, Biogen is where your skills will help shape the future of healthcare. Join our diverse team and embrace the culture of excellence and collaboration that Biogen is known for. Here, every position contributes to our mission, driving us forward with shared purpose and vision. Biogen’s Employment Philosophy We believe in the power of our people and invest in their future. The growth and development of our team members are paramount, which is why we offer robust benefits, diversity training, and career advancement opportunities. At Biogen, leadership and innovation go hand in hand, fostering an environment where you can thrive. Internship and Early Career Programs Kickstart your career with a Biogen internship. Gain invaluable industry experience, enhance your resume, and build a professional network that will serve you throughout your career. Our internships provide a platform to develop your skills and test your knowledge in a real-world setting, preparing you for full-time employment in the biotechnology field. Hiring Process Our hiring process is designed to identify and attract professionals who are passionate about making a difference. From the initial application and resume submission to the interview and final selection, each step is an opportunity to showcase your unique talents and potential. At Biogen, we look for individuals who are curious, creative, and eager to tackle new challenges. Stay Connected Join Our Team Explore the various positions available at Biogen and find the one that best matches your skills and interests. We are constantly looking for individuals who are driven to explore, innovate, and lead. Keep Up to Date Stay informed with the latest career tips, insider perspectives, and industry-leading insights—all from the people who work here. Biogen is not just a company; it’s a community where you can grow, connect, and contribute to exciting, meaningful work. Job Alert Emails Customize your subscription to receive job alerts, the latest news, and insider tips tailored to your preferences. Discover the rewarding opportunities waiting for you at Biogen and be part of our mission to lead in the biotechnology industry. Join Biogen today and be part of a team that is dedicated to redefining the boundaries of science and medicine. Your career at Biogen is not just a job—it’s a pathway to personal and professional fulfillment.
Learn more about Biogen
Size
9,610 employees
Market Cap
$39.7 billion
Industry
Net Income
$4 billion
Founded
1978
5 Year Trend
-0.8%
Revenue
$13.4 billion
NASDAQ

Similar Jobs

More Jobs at Biogen

More Information Technology Jobs

Find similar Senior SOC Analyst - Advanced Incident Response & CrowdStrike Engineering jobs: