Biogen Posted July 28, 2026

Senior SOC Analyst, Advanced Incident Response & CrowdStrike Engineering

Research Triangle Park, United States Full time
Senior

Biogen is the source of truth for this posting and owns the application process. We surface normalized context and market comparison you won't find on the original listing.

About this opportunity

About This Role

This is a individual contributor role and the technical backbone of Biogen's Security Operations Center, an analyst who leads complex incident investigations, engineers and optimizes the CrowdStrike Falcon platform across advanced modules (AIDR, Data Security, NG-SIEM, Identity Protection), and extends detection capabilities into operational technology (OT) environments supporting pharmaceutical manufacturing.

You will own the most complex escalations, build the detection logic that catches what others miss, and serve as the bridge between IT security operations and OT/manufacturing environments. This is not a monitoring role, it is an engineering and investigation role that happens to sit in the SOC.

Why This Role Exists

Biogen's threat landscape demands deeper investigative capability, advanced persistent threats, insider risk, and pharmaceutical IP targeting require an analyst who can conduct full-spectrum forensic investigations and threat hunting

CrowdStrike Falcon is our primary detection and response platform, we need an engineer who can maximize the value of AIDR, Data Security, NG-SIEM (LogScale), and Identity Protection modules beyond default configurations

IT/OT convergence in our manufacturing environments creates unique detection challenges, DeltaV/DCS systems, GxP-regulated processes, and industrial protocols require specialized security monitoring

Key Responsibilities

Advanced Incident Response & Investigations (40%)

Lead complex, multi-stage incident investigations from initial detection through containment, eradication, recovery, and lessons learned

Conduct deep-dive forensic analysis: memory forensics (Volatility), disk forensics, network artifact analysis, and malware triage to determine attacker TTPs

Perform kill chain reconstruction, map attacker activity to MITRE ATT&CK, identify lateral movement paths, persistence mechanisms, and data staging/exfiltration techniques

Develop and execute proactive threat hunts based on intelligence, behavioral anomalies, and hypothesis-driven analysis across endpoint, network, identity, and cloud telemetry

Produce actionable incident reports with root cause analysis, business impact assessment, and concrete remediation recommendations

CrowdStrike Falcon Platform Engineering (35%)

Engineer, tune, and operationalize these Falcon modules:

NG-SIEM (LogScale)

Develop and maintain CQL (CrowdStrike Query Language) queries for advanced correlation, threat hunting, and detection rules

Build custom dashboards, scheduled searches, and automated alerting pipelines

Optimize log ingestion, parsing, and retention policies across all telemetry sources

Create detection-as-code workflows, version-controlled queries that map to MITRE ATT&CK coverage gaps

AIDR (AI Detection & Response)

Configure and tune AI-driven detection policies for prompt injection, data leakage, and shadow AI usage

Build custom rules to monitor GenAI application interactions across endpoints and cloud workloads

Assess and respond to AI-specific threats: model poisoning indicators, unauthorized AI tool installations, sensitive data in AI prompts

Integrate AIDR telemetry into investigation workflows and incident playbooks

Identity Protection

Engineer identity-based detection rules: Kerberoasting, credential stuffing, lateral movement via pass-the-hash/ticket, suspicious service account behavior

Configure conditional access policies, risk-based authentication enforcement, and identity threat hunting queries

Monitor Active Directory attack paths and privilege escalation techniques (DCSync, Golden Ticket, NTLM relay)

Coordinate with IAM team on identity hygiene findings and remediation priorities

Data Security (Data Protection)

Configure data classification policies and egress monitoring rules for sensitive content (IP, PII, regulated data)

Tune anomaly detection for unusual data movement patterns: bulk downloads, new destination usage, abnormal upload volumes

Build response workflows for data exfiltration alerts, user notification, manager escalation, automatic evidence preservation

Define and enforce policies for removable media, cloud storage, and web upload channels

Platform Administration

Manage sensor deployment health, prevention policies, and RBAC across 25,000+ endpoints

Develop custom IOA (Indicator of Attack) rules and behavioral detections tailored to Biogen's environment

Build and maintain Falcon Fusion (SOAR) workflows for automated containment and enrichment

Coordinate with CrowdStrike OverWatch for managed hunting findings and recommended actions

OT/ICS Security Operations (25%)

Extend SOC monitoring into operational technology environments supporting pharmaceutical manufacturing (DeltaV DCS, SCADA, PLCs, HMIs)

Develop and tune detection rules for OT-specific threats: unauthorized engineering workstation access, controller logic changes, anomalous industrial protocol traffic (Modbus, EtherNet/IP, OPC-UA)

Maintain and enforce IT/OT network segmentation aligned with the Purdue Reference Model, monitor for segmentation bypass attempts

Lead incident response for OT security events in coordination with Process Automation, Engineering, and Plant Operations teams

Support OT asset inventory maintenance and vulnerability management in GxP-regulated environments (21 CFR Part 11, cGMP considerations)

Conduct tabletop exercises for OT-specific scenarios (ransomware impacting batch processing, unauthorized remote access to control systems)

Required Qualifications

Experience

Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field required; advanced degree preferred

3-5+ years in Security Operations, Incident Response, or Threat Hunting with progressive responsibility

3+ years hands-on experience with CrowdStrike Falcon platform in an engineering/administration capacity (not just alert triage)

Demonstrated experience leading complex incident investigations involving APT, ransomware, insider threats, or supply chain compromise

Experience with OT/ICS security monitoring, industrial environments, or manufacturing cybersecurity

Track record of building detection rules, SIEM correlation logic, or behavioral analytics that caught real threats

Technical Skills

CrowdStrike Falcon: NG-SIEM (LogScale/CQL), AIDR, Identity Protection, Data Security, Falcon Fusion, Real Time Response, custom IOA development

Forensics: memory analysis (Volatility), disk forensics, network forensics, malware triage/reverse engineering fundamentals

Threat Hunting: hypothesis-driven hunts, MITRE ATT&CK mapping, behavioral analysis across endpoint/network/identity/cloud telemetry

Scripting & Automation: Python and PowerShell for investigation tooling, data parsing, API integrations, and SOAR playbook development

Network Security: deep understanding of TCP/IP, DNS, HTTP/TLS, lateral movement protocols (SMB, RDP, WMI, WinRM), and packet analysis

Identity Security: Active Directory attack techniques, Kerberos/NTLM fundamentals, privilege escalation paths, identity-based detection

OT/ICS: familiarity with industrial protocols (Modbus, EtherNet/IP, OPC-UA), Purdue Model architecture, DCS/SCADA security principles

Certifications (Preferred, not all required)

CrowdStrike: CCFA (Falcon Administrator), CCFR (Falcon Responder), CCFH (Falcon Hunter)

SANS/GIAC: GCFA, GCIH, GREM, GCIA, or GNFA

OT/ICS: GICSP (Global Industrial Cyber Security Professional) or GRID (Response and Industrial Defense)

General: CISSP, CySA+, or equivalent

Preferred Qualifications

Experience in pharmaceutical, biotech, or life sciences environments with GxP-regulated systems

Familiarity with DeltaV DCS, batch automation systems, or laboratory automation security

Experience with CrowdStrike NG-SIEM migration, parser development, or LogScale administration

Background in detection engineering as code (version-controlled detections, CI/CD for security content)

Experience coordinating with CrowdStrike OverWatch or similar managed hunting services

Job Level: Management

Additional Information

The base compensation range for this role is: $115,000.00-$154,000.00

Base salary offered is determined through an analytical approach utilizing a combination of factors including, but not limited to, relevant skills & experience, job location, and internal equity.

Regular employees are eligible to receive both short term and long-term incentives, including cash bonus and equity incentive opportunities, designed to reward recent achievements and recognize your future potential based on individual, business unit and company performance.

In addition to compensation, Biogen offers a full and highly competitive range of benefits designed to support our employees’ and their families physical, financial, emotional, and social well-being ; including, but not limited to:

Medical, Dental, Vision, & Life insurances

Fitness & Wellness programs including a fitness reimbursement

Short- and Long-Term Disability insurance

A minimum of 15 days of paid vacation and an additional end-of-year shutdown time off (Dec 26-Dec 31)

Up to 12 company paid holidays + 3 paid days off for Personal Significance

80 hours of sick time per calendar year

Paid Maternity and Parental Leave benefit

401(k) program participation with company matched contributions

Employee stock purchase plan

Tuition reimbursement of up to $10,000 per calendar year

Employee Resource Groups participation

Why Biogen?

We are a global team with a commitment to excellence, and a pioneering spirit. As a mid-sized biotechnology company, we provide the stability and resources of a well-established business while fostering an environment where individual contributions make a significant impact. Our team encompasses some of the most talented and passionate achievers who have unparalleled opportunities for learning, growth, and expanding their skills. Above all, we work together to deliver life-changing medicines, with every role playing a vital part in our mission. Caring Deeply. Achieving Excellence. Changing Lives.

At Biogen, we are committed to building on our culture of inclusion and belonging that reflects the communities where we operate and the patients we serve. We know that diverse backgrounds, cultures, and perspectives make us a stronger and more innovative company, and we are focused on building teams where every employee feels empowered and inspired.  Read on  to learn more about our Biogen.

All qualified applicants will receive consideration for employment without regard to sex, gender identity or expression, sexual orientation, marital status, race, color, national origin, ancestry, ethnicity, religion, age, veteran status, disability, genetic information or any other basis protected by federal, state or local law. Biogen is an E-Verify Employer in the United States.

Job details

Seniority
Senior
Function
Not listed
Therapeutic area
Not listed
Location
Research Triangle Park, United States
Employment type
Full time

How this role compares

Computed from every other active role in our database, not just this employer's listings.

We don't have enough classified peer data for this role yet, so there's no comparison to show. This happens when a posting's title/category doesn't match any taxonomy rule -- it's excluded rather than compared against the wrong peer group.