Why This Role Stands Out
This hybrid role at a rapidly growing, award-winning tech company offers significant opportunities for career advancement and skill development in network security. You'll thrive here if you are a mid-senior level analyst eager to contribute to critical security operations within a supportive and globally connected team. Apply now to join a leading IT solutions provider with a strong reputation and exciting government partnerships.
Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
Austin, TX, United States
Posted
Yesterday
PythonPowerShellBashPrismaSplunkActive Directory
Job Description
CCS Global Tech is a rapidly growing Information Technology company with a diverse portfolio of technology products and services and a large network of industry partnerships. With over 22 years of being a successful business with a global talent pool and presence, CCS is a certified Microsoft Gold Partner and specializes in delivering expert Microsoft based solutions for technical and business needs. We have been recognized by Inc. 500 Magazine as one of the fastest growing small companies in the Unites States.
we are a Tier 1 vendor for the City and County of San Francisco for Cloud Services, Staffing Services and Training Services. For this multi-year opportunity with a diverse set of needs to address, we are currently focusing on establishing partnerships with individuals as well as companies who can help us enhance our overall service portfolio, cut lead times, and ultimately help us deliver successfully. We currently hold sizable Government accounts in the San Francisco bay area including City and County of San Francisco, San Mateo County, and Santa Clara County.
We take great pride in our global reach and local influence. Your experience alongside our highly skilled and talented internal team who guide you along the way, offers key insights into what helps you stand out in a competitive job market.
If you are a partner company, please submit resumes with contact information of your own W2 Consultants only. Submitted consultants are expected to have excellent communication skills.
Roles/Responsibilities:
- Monitors, analyzes, and triages cybersecurity alerts generated by Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), cloud security, email security, identity protection, and network security platforms.
- Conducts initial investigations of detected and reported security events to determine severity, scope, impact, and potential risk to agency operations.
- Identifies, validates, and prioritizes potential cybersecurity incidents, escalating confirmed threats to Incident Response, Threat Hunting, or SOC Engineering teams according to established procedures.
- Correlates security events from multiple data sources, including endpoints (EDR), firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), cloud services, authentication systems, and threat intelligence feeds.
- Reviews and analyzes indicators of compromise (IOCs), suspicious network activity, phishing emails, malware detections, and anomalous user behavior.
- Documents investigations, findings, and response actions in ticketing and case management systems to ensure accurate tracking and reporting.
- Assists with incident containment, eradication, and recovery efforts by coordinating with technical teams and stakeholders.
- Reports and escalates to the CSOC Team Lead and/or SOC Manager.
- Supports the continuous improvement of threat detection capabilities through alert tuning, process refinement, threat intelligence integration, and identification of false-positive trends.
- Performs vulnerability assessment reviews and evaluates identified vulnerabilities for potential risk and remediation prioritization.
- Supports development and maintenance of operational procedures, playbooks, workflows, and knowledge base articles related to threat detection and incident response.
- Researches emerging cyber threats, attack techniques, tactics, and procedures (TTPs) to improve detection and response effectiveness.
Knowledge, Skills, and Abilities
Knowledge of:
- Cybersecurity Operations Center (CSOC/SOC) operations and best practices.
- Security incident triage, analysis, investigation, and escalation procedures.
- Security monitoring technologies, including SIEM, EDR/XDR, IDS/IPS, firewalls, endpoint security solutions, and cloud security platforms.
- Common cyber threats, attack vectors, malware, phishing campaigns, insider threats, and advanced persistent threat (APT) techniques.
- Threat intelligence concepts, indicators of compromise (IOCs), indicators of attack (IOAs), and MITRE ATT&CK methodologies.
- Windows, Linux, networking protocols, Active Directory, Microsoft Entra ID, cloud environments, and enterprise security controls.
- Incident response lifecycle and cybersecurity frameworks such as NIST Cybersecurity Framework, NIST Incident Response guidance, and PICERL.
Skill in:
- Security event analysis and threat triage.
- Correlating and interpreting data from multiple cybersecurity tools.
- Investigating suspicious activity and identifying indicators of compromise.
- Using SIEM, EDR/XDR, threat intelligence, vulnerability management, and case management platforms.
- Producing clear documentation, incident reports, and technical communications.
- Prioritizing and managing multiple investigations in a fast-paced operational environment for a large organization.
- Knowledge of and experience with query languages such as KQL, Lucene, SPL, ESQL, etc.
- Knowledge of and experience with scripting languages such as PowerShell, Python, Bash, etc.
Ability to:
- Analyze complex security events and distinguish legitimate threats from false positives.
- Make risk-based decisions during incident investigations.
- Execute established incident response and escalation procedures.
- Collaborate effectively with security engineers, incident responders, system administrators, CISO leadership, and business stakeholders.
- Communicate technical information clearly to both technical and non-technical audiences.
- Work independently and as part of a 24x7 cybersecurity operations team.
Mandatory Skills:
- Minimum of five (5) years of experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines.
- Experience working with one or more of the following technologies:
- SIEM platforms (NetWitness, Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, etc.)
- Microsoft Security (Microsoft 365 Defender XDR, Microsoft Sentinel)
- Endpoint Detection and Response (Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, etc.)
- IDS/IPS technologies (Trellix/FireEye, Corelight)
- Threat intelligence platforms (VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, MISP)
- Vulnerability management tools (Tenable, Qualys, Rapid7)
- Email security platforms (IronPort ESA, Abnormal.ai, Proofpoint)
- Cloud security monitoring solutions (Google Wiz, MDCA, Cortex Cloud, Sysdig)
- Secure Access Service Edge (Zscaler, Prisma, Netskope)
- 3 years- Experience triaging security alerts, analyzing security events, and documenting incident investigations.
- 3 years- Experience with cybersecurity frameworks, incident response processes, and threat detection methodologies.
Desirable Skills:
- Graduation from an accredited four-year college or university with major coursework in cybersecurity, information security, computer science, computer information systems, management information systems, or a related field is preferred. Relevant education and experience may be substituted for one another.
- One or more of the following certifications are preferred:
- CompTIA Security+
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Intrusion Analyst (GCIA)
- Certified SOC Analyst (CSA)
- Microsoft Cybersecurity Analyst (SC-200)
- Other GIAC or SOC-related certifications
Similar jobs
- BS
EXPLOITATION ANALYST Levels I-IV with Security Clearance
BTS Software Solutions
Annapolis Junction, MD🇺🇸$120k - $260k/yrHybrid4 days agoPenetration Testing - GE
Network Firewall Engineer
NewGenesis10
Chandler, AZ🇺🇸$67 - $75/hrHybrid13 hours agoSOAPLoad BalancingSplunk+5 - AL
Cybersecurity Manager
NewAbbott Laboratories
Lake Forest, Illinois🇺🇸Hybrid3 hours agoGCPAWSAzure+1Technology - LE
Junior Security Engineer
NewLeidos
Silver Spring, MD🇺🇸$69.5k - $125.7k/yrOn-siteYesterdayEncryptionSplunkTCP/IP+3Technology - LE
Junior Security Engineer
NewLeidos
Gaithersburg, MD🇺🇸$69.5k - $125.7k/yrOn-siteYesterdayEncryptionSplunkTCP/IP+3Technology - LE
Junior Security Engineer
NewLeidos
Chevy Chase, MD🇺🇸$69.5k - $125.7k/yrOn-siteYesterdayEncryptionSplunkTCP/IP+3Technology