OAG - Entp Information Security | Cybersecurity Analyst IV | 26-0675
We tailor your resume to this role and apply for you in seconds.
Apply to OAG - Entp Information Security | Cybersecurity Analyst IV | 26-0675 at Office of the Attorney GeneralJob details
- Location
- Austin, Texas
- Work type
- Hybrid
- Compensation
- $130,008 - $150,000/yr
- Posted
- yesterday
- Apply on
- erphcmprd.cpa.texas.gov
About this role
Job Description
GENERAL DESCRIPTION
The Office of the Attorney General (OAG) is seeking a senior-level AI Cyber Automation Engineer / Tier 3 SOC Analyst to strengthen detection, response, and orchestration capabilities across the agency's security operations. This role blends deep SOC investigative expertise with hands-on security automation engineering, focusing on CrowdStrike Falcon and Torq to build scalable, AI-assisted detection and response workflows. The ideal candidate has practical experience integrating large language model (LLM) tools such as Claude into security operations, for triage acceleration, playbook generation, and analyst augmentation, while operating within a strict Zero Trust, defense-in-depth security posture appropriate to a state Attorney General's office. This position operates in an environment governed by IRS Publication 1075 (FTI), FBI CJIS Security Policy, and Texas Government Code requirements.
The Office of the Attorney General is a dynamic organization with over 4,000 employees throughout the State of Texas. Our agency provides exemplary legal representation for every arm of the State, fights human trafficking, helps victims of crime, protects our constituents, and runs the most effective Medicaid Fraud Control and Child Support Enforcement programs in the nation. OAG employees enjoy excellent benefits (http://ers.texas.gov/Benefits-at-a-Glance) along with tremendous opportunities to do important work at a large, dynamic state agency making a positive difference in the lives of Texans.
ESSENTIAL POSITION FUNCTIONS
- Serve as a SOC analysis & Tier 3 escalation point for complex security incidents, performing deep-dive investigation, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.
- Design, build, and maintain detection analytics, dashboards, and hunting queries (Falcon Query Language / FQL) within CrowdStrike Falcon, tuning correlation rules and detection logic to reduce false positives and improve mean-time-to-detect (MTTD).
- Architect and maintain security orchestration, automation, and response (SOAR) playbooks in Torq, integrating Sentinel, EDR, identity providers, ticketing, and communication platforms into automated response workflows.
- Design AI-assisted analyst workflows (e.g., automated triage summarization, alert enrichment, playbook drafting) using approved generative AI tooling, ensuring all inputs are sanitized and free of regulated or case-specific data.
- Lead incident response efforts for high-severity events, coordinating with IT, legal, and divisional stakeholders while
strictly adhering to FTI/CJI handling restrictions. - Develop and maintain detection engineering documentation, runbooks, and standard operating procedures (SOPs) for Tier 1/Tier 2 analyst use.
- Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts; review and validate their investigative work and escalation quality.
- Continuously evaluate and integrate emerging SOC automation and AI capabilities, presenting proposals for tooling changes with documented risk and compliance analysis.
- Participate in an on-call rotation for critical incident escalations. May require after-hours availability for critical incident response.
- Subject to session logging, audit review, and monitoring in accordance with Texas Government Code and applicable federal security requirements.
- Performs related work as assigned.
- Maintains relevant knowledge necessary to perform essential job functions.
- Attends work regularly in compliance with agreed-upon work schedule. Telework schedules are permitted for employees based on the agency¿s approved Telework Plan, if schedule does not adversely affect operations and service levels, and standard hours of operation are maintained.
- Ensures security and confidentiality of sensitive and/or protected information.
- Complies with all agency policies and procedures, including those pertaining to ethics and integrity.
MINIMUM QUALIFICATIONS
- Education: Graduation from high school or equivalent
- Experience: Nine years of full-time experience in progressive SOC / security operations experience, including 2 years as functioning at a Tier 3 / senior analyst or detection engineering level; may substitute credit hours from an accredited college or university for the required experience on a year-for-year basis
- Hands-on production experience with CrowdStrike Falcon (Insight XDR, Discover, and/or Fusion SOAR), including custom detection/IOA authoring, Falcon Query Language (FQL) use, and dashboard development.
- Demonstrated experience building or maintaining SOAR automation (Torq strongly preferred)
- Solid understanding of the MITRE ATT&CK framework, incident response lifecycle, and threat intelligence integration.
- Practical, hands-on experience using AI/LLM tools (e.g., Claude, GPT-based tools) to support security operations, with clear understanding of data sanitization and safe-use boundaries in a regulated environment.
- Working knowledge of Zero Trust architecture principles (NIST 800-207) and general familiarity with regulatory frameworks such as IRS Pub. 1075, FBI CJIS Policy, and HIPAA.
- Strong scripting/automation ability (PowerShell, Python, or Falcon Query Language-based automation) for building custom detections and integrations.
- Excellent written communication skills for incident reporting, runbook authorship, and cross-divisional coordination.
- Ability to obtain and maintain a Texas state government background clearance.
- Skill in exercising sound judgment and effective decision making.
- Skill in effective oral and written communication.
- Ability to handle multiple tasks, prioritize, and meet deadlines.
- Ability to gather, assemble, correlate, and analyze facts; to devise solutions to problems.
- Ability to develop, evaluate, and interpret policies and procedures.
- Ability to train others.
- Ability to receive and respond positively to constructive feedback.
- Ability to work cooperatively with others in a professional office environment.
- Ability to provide excellent customer service.
- Ability to arrange for personal transportation for business-related travel.
- Ability to work more than 40 hours as needed and in compliance with the FLSA.
- Ability to lift and relocate 30 lbs.
- Ability to travel (including overnight travel) up to 5%
PREFERRED QUALIFICATIONS
- Education: Bachelor's degree in Computer Science, Information Security, or related field; may substitute credit hours from an accredited college or university for the required experience on a year-for-year basis
- CrowdStrike Certified Falcon Responder (CCFR) or CrowdStrike Certified Falcon Administrator (CCFA), or equivalent CrowdStrike security certification.
- Torq certification or demonstrated portfolio of built automation workflows.
- Experience in government, legal, or law-enforcement-adjacent security environments
- Experience designing AI-assisted playbooks or analyst copilots for SOC use cases while maintaining strict data-handling guardrails.
- GIAC certifications (GCIH, GCIA, GCFA) or equivalent.
- Familiarity with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One / cloud security posture management (CSPM) tooling.
TO APPLY
To apply for a job with the OAG, electronic applications can be submitted through CAPPS Recruit. A State of Texas application must be completed to be considered, and paper applications are not accepted. Your application for this position may subject you to a criminal background check pursuant to the Texas Government Code. Military Crosswalk information can be accessed at
https://hr.sao.texas.gov/Compensation/MilitaryCrosswalk/MOSC_InformationTechnology.pdf
THE OAG IS AN EQUAL OPPORTUNITY EMPLOYER