Senior SOC Analyst — Advanced Incident Response & CrowdStrike Engineering
Durham County, NC - USA
Job Summary
This is a individual contributor role and the technical backbone of Biogens Security Operations Center an analyst who leads complex incident investigations engineers and optimizes the CrowdStrike Falcon platform across advanced modules (AIDR Data Security NG-SIEM Identity Protection) and extends detection capabilities into operational technology (OT) environments supporting pharmaceutical manufacturing.
You will own the most complex escalations build the detection logic that catches what others miss and serve as the bridge between IT security operations and OT/manufacturing environments. This is not a monitoring role it is an engineering and investigation role that happens to sit in the SOC.
- Biogens threat landscape demands deeper investigative capability advanced persistent threats insider risk and pharmaceutical IP targeting require an analyst who can conduct full-spectrum forensic investigations and threat hunting
- CrowdStrike Falcon is our primary detection and response platform we need an engineer who can maximize the value of AIDR Data Security NG-SIEM (LogScale) and Identity Protection modules beyond default configurations
- IT/OT convergence in our manufacturing environments creates unique detection challenges DeltaV/DCS systems GxP-regulated processes and industrial protocols require specialized security monitoring
- Lead complex multi-stage incident investigations from initial detection through containment eradication recovery and lessons learned
- Conduct deep-dive forensic analysis: memory forensics (Volatility) disk forensics network artifact analysis and malware triage to determine attacker TTPs
- Perform kill chain reconstruction map attacker activity to MITRE ATT&CK identify lateral movement paths persistence mechanisms and data staging/exfiltration techniques
- Develop and execute proactive threat hunts based on intelligence behavioral anomalies and hypothesis-driven analysis across endpoint network identity and cloud telemetry
- Produce actionable incident reports with root cause analysis business impact assessment and concrete remediation recommendations
Engineer tune and operationalize these Falcon modules:
NG-SIEM (LogScale)
- Develop and maintain CQL (CrowdStrike Query Language) queries for advanced correlation threat hunting and detection rules
- Build custom dashboards scheduled searches and automated alerting pipelines
- Optimize log ingestion parsing and retention policies across all telemetry sources
- Create detection-as-code workflows version-controlled queries that map to MITRE ATT&CK coverage gaps
AIDR (AI Detection & Response)
- Configure and tune AI-driven detection policies for prompt injection data leakage and shadow AI usage
- Build custom rules to monitor GenAI application interactions across endpoints and cloud workloads
- Assess and respond to AI-specific threats: model poisoning indicators unauthorized AI tool installations sensitive data in AI prompts
- Integrate AIDR telemetry into investigation workflows and incident playbooks
Identity Protection
- Engineer identity-based detection rules: Kerberoasting credential stuffing lateral movement via pass-the-hash/ticket suspicious service account behavior
- Configure conditional access policies risk-based authentication enforcement and identity threat hunting queries
- Monitor Active Directory attack paths and privilege escalation techniques (DCSync Golden Ticket NTLM relay)
- Coordinate with IAM team on identity hygiene findings and remediation priorities
Data Security (Data Protection)
- Configure data classification policies and egress monitoring rules for sensitive content (IP PII regulated data)
- Tune anomaly detection for unusual data movement patterns: bulk downloads new destination usage abnormal upload volumes
- Build response workflows for data exfiltration alerts user notification manager escalation automatic evidence preservation
- Define and enforce policies for removable media cloud storage and web upload channels
Platform Administration
- Manage sensor deployment health prevention policies and RBAC across 25000 endpoints
- Develop custom IOA (Indicator of Attack) rules and behavioral detections tailored to Biogens environment
- Build and maintain Falcon Fusion (SOAR) workflows for automated containment and enrichment
- Coordinate with CrowdStrike OverWatch for managed hunting findings and recommended actions
- Extend SOC monitoring into operational technology environments supporting pharmaceutical manufacturing (DeltaV DCS SCADA PLCs HMIs)
- Develop and tune detection rules for OT-specific threats: unauthorized engineering workstation access controller logic changes anomalous industrial protocol traffic (Modbus EtherNet/IP OPC-UA)
- Maintain and enforce IT/OT network segmentation aligned with the Purdue Reference Model monitor for segmentation bypass attempts
- Lead incident response for OT security events in coordination with Process Automation Engineering and Plant Operations teams
- Support OT asset inventory maintenance and vulnerability management in GxP-regulated environments (21 CFR Part 11 cGMP considerations)
- Conduct tabletop exercises for OT-specific scenarios (ransomware impacting batch processing unauthorized remote access to control systems)
- Bachelors degree in Computer Science Cybersecurity Information Technology or related field required; advanced degree preferred
- 3-5 years in Security Operations Incident Response or Threat Hunting with progressive responsibility
- 3 years hands-on experience with CrowdStrike Falcon platform in an engineering/administration capacity (not just alert triage)
- Demonstrated experience leading complex incident investigations involving APT ransomware insider threats or supply chain compromise
- Experience with OT/ICS security monitoring industrial environments or manufacturing cybersecurity
- Track record of building detection rules SIEM correlation logic or behavioral analytics that caught real threats
- CrowdStrike Falcon: NG-SIEM (LogScale/CQL) AIDR Identity Protection Data Security Falcon Fusion Real Time Response custom IOA development
- Forensics: memory analysis (Volatility) disk forensics network forensics malware triage/reverse engineering fundamentals
- Threat Hunting: hypothesis-driven hunts MITRE ATT&CK mapping behavioral analysis across endpoint/network/identity/cloud telemetry
- Scripting & Automation: Python and PowerShell for investigation tooling data parsing API integrations and SOAR playbook development
- Network Security: deep understanding of TCP/IP DNS HTTP/TLS lateral movement protocols (SMB RDP WMI WinRM) and packet analysis
- Identity Security: Active Directory attack techniques Kerberos/NTLM fundamentals privilege escalation paths identity-based detection
- OT/ICS: familiarity with industrial protocols (Modbus EtherNet/IP OPC-UA) Purdue Model architecture DCS/SCADA security principles
- CrowdStrike: CCFA (Falcon Administrator) CCFR (Falcon Responder) CCFH (Falcon Hunter)
- SANS/GIAC: GCFA GCIH GREM GCIA or GNFA
- OT/ICS: GICSP (Global Industrial Cyber Security Professional) or GRID (Response and Industrial Defense)
- General: CISSP CySA or equivalent
- Experience in pharmaceutical biotech or life sciences environments with GxP-regulated systems
- Familiarity with DeltaV DCS batch automation systems or laboratory automation security
- Experience with CrowdStrike NG-SIEM migration parser development or LogScale administration
- Background in detection engineering as code (version-controlled detections CI/CD for security content)
- Experience coordinating with CrowdStrike OverWatch or similar managed hunting services
Additional Information
Base salary offered is determined through an analytical approach utilizing a combination of factors including but not limited to relevant skills & experience job location and internal equity.
Regular employees are eligible to receive both short term and long-term incentives including cash bonus and equity incentive opportunities designed to reward recent achievements and recognize your future potential based on individual business unit and company performance.
In addition to compensation Biogen offers a full and highly competitive range of benefits designed to support our employees and their families physical financial emotional and social well-being; including but not limited to:
- Medical Dental Vision & Life insurances
- Fitness & Wellness programs including a fitness reimbursement
- Short- and Long-Term Disability insurance
- A minimum of 15 days of paid vacation and an additional end-of-year shutdown time off (Dec 26-Dec 31)
- Up to 12 company paid holidays 3 paid days off for Personal Significance
- 80 hours of sick time per calendar year
- Paid Maternity and Parental Leave benefit
- 401(k) program participation with company matched contributions
- Employee stock purchase plan
- Tuition reimbursement of up to $10000 per calendar year
- Employee Resource Groups participation
Why Biogen
We are a global team with a commitment to excellence and a pioneering spirit. As a mid-sized biotechnology company we provide the stability and resources of a well-established business while fostering an environment where individual contributions make a significant impact. Our team encompasses some of the most talented and passionate achievers who have unparalleled opportunities for learning growth and expanding their skills. Above all we work together to deliver life-changing medicines with every role playing a vital part in our mission. Caring Deeply. Achieving Excellence. Changing Lives.
At Biogen we are committed to building on our culture of inclusion and belonging that reflects the communities where we operate and the patients we serve. We know that diverse backgrounds cultures and perspectives make us a stronger and more innovative company and we are focused on building teams where every employee feels empowered and inspired.Read onto learn more about our Biogen.
All qualified applicants will receive consideration for employment without regard to sex gender identity or expression sexual orientation marital status race color national origin ancestry ethnicity religion age veteran status disability genetic information or any other basis protected by federal state or local law. Biogen is an E-Verify Employer in the United States.
Required Experience:
Senior IC
About Company
Founded in 1978, Biogen is a leading biotechnology company that pioneers innovative science to deliver new medicines to transform patients lives and to create value for shareholders and our communities. We apply deep understanding of human biology and leverage different modalities, ... View more