Why This Role Stands Out
Advance your cybersecurity career at Masterapp Labs, a reputable company where you'll gain invaluable experience in a dynamic SOC environment. If you're a proactive and analytical individual eager to protect critical digital assets, this on-site role in Austin is an excellent opportunity to contribute to impactful security operations. Apply now to join a team dedicated to safeguarding innovative technology.
Quick Overview
Seniority
Mid Senior
Work mode
On Site
Location
Austin, TX, United States
Posted
22 hours ago
SplunkActive DirectoryBashPowerShellPrismaPython
Job Description
Job Title: Network Security Analyst – Cybersecurity Operations (SOC)
Location: Austin, TX, (Onsite)
Position Type: Contract
Interview Mode: MS Teams
Knowledge, Skills, and Abilities
Knowledge of:
- Cybersecurity Operations Center (CSOC/SOC) operations and best practices.
- Security incident triage, analysis, investigation, and escalation procedures.
- Security monitoring technologies, including SIEM, EDR/XDR, IDS/IPS, firewalls, endpoint security solutions, and cloud security platforms.
- Common cyber threats, attack vectors, malware, phishing campaigns, insider threats, and advanced persistent threat (APT) techniques.
- Threat intelligence concepts, indicators of compromise (IOCs), indicators of attack (IOAs), and MITRE ATT&CK methodologies.
- Windows, Linux, networking protocols, Active Directory, Microsoft Entra ID, cloud environments, and enterprise security controls.
- Incident response lifecycle and cybersecurity frameworks such as NIST Cybersecurity Framework, NIST Incident Response guidance, and PICERL.
Skill in:
- Security event analysis and threat triage.
- Correlating and interpreting data from multiple cybersecurity tools.
- Investigating suspicious activity and identifying indicators of compromise.
- Using SIEM, EDR/XDR, threat intelligence, vulnerability management, and case management platforms.
- Producing clear documentation, incident reports, and technical communications.
- Prioritizing and managing multiple investigations in a fast-paced operational environment for a large organization.
- Knowledge of and experience with query languages such as KQL, Lucene, SPL, ESQL, etc.
- Knowledge of and experience with scripting languages such as PowerShell, Python, Bash, etc.
Ability to:
- Analyze complex security events and distinguish legitimate threats from false positives.
- Make risk-based decisions during incident investigations.
- Execute established incident response and escalation procedures.
- Collaborate effectively with security engineers, incident responders, system administrators, CISO leadership, and business stakeholders.
- Communicate technical information clearly to both technical and non-technical audiences.
- Work independently and as part of a 24x7 cybersecurity operations team.
Preferred Education and Certifications
- Graduation from an accredited four-year college or university with major coursework in cybersecurity, information security, computer science, computer information systems, management information systems, or a related field is preferred. Relevant education and experience may be substituted for one another.
- One or more of the following certifications are preferred:
- CompTIA Security+
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Intrusion Analyst (GCIA)
- Certified SOC Analyst (CSA)
- Microsoft Cybersecurity Analyst (SC-200)
- Other GIAC or SOC-related certifications
Required Qualifications
- Minimum of five (5) years of experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines.
- Experience working with one or more of the following technologies:
- SIEM platforms (NetWitness, Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, etc.)
- Microsoft Security (Microsoft 365 Defender XDR, Microsoft Sentinel)
- Endpoint Detection and Response (Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, etc.)
- IDS/IPS technologies (Trellix/FireEye, Corelight)
- Threat intelligence platforms (VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, MISP)
- Vulnerability management tools (Tenable, Qualys, Rapid7)
- Email security platforms (IronPort ESA, Abnormal.ai, Proofpoint)
- Cloud security monitoring solutions (Google Wiz, MDCA, Cortex Cloud, Sysdig)
- Secure Access Service Edge (Zscaler, Prisma, Netskope)
- Experience triaging security alerts, analyzing security events, and documenting incident investigations.
- Experience with cybersecurity frameworks, incident response processes, and threat detection methodologies.
Work Expectations
- Participate in incident response, escalation, and after-action review activities as needed.
- Support enterprise security monitoring for systems that process, store, or transmit sensitive information.
- Follow HHSC policies, procedures, standards, and applicable state and federal security requirements.
- Maintain accurate operational documentation, investigation notes, metrics, and leadership-ready summaries.
- Must be able to provide support outside of normal business hours during high-priority security incidents, as approved by the SOC Manager.
II. CANDIDATE SKILLS AND QUALIFICATIONS
|
Minimum Requirements:
Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity.
|
||
|
Years
|
Required/Preferred
|
Experience
|
|
3
|
Required
|
Experience triaging security alerts
|
|
3
|
Required
|
Experience analyzing security events
|
|
3
|
Required
|
Experience documenting incident investigations
|
|
3
|
Required
|
Experience with cybersecurity frameworks
|
|
3
|
Required
|
Experience with incident response processes
|
|
3
|
Required
|
Experience with threat detection methodologies
|
|
3
|
Required
|
Experience in cybersecurity operations
|
|
3
|
Required
|
Experience in security monitoring
|
|
3
|
Required
|
Experience in incident response
|
|
3
|
Required
|
Experience in threat detection
|
|
3
|
Required
|
Experience in security investigations
|
|
3
|
Required
|
Experience in related cybersecurity disciplines
|
|
5
|
Preferred
|
Please See Job Description Section for more specific Preferred and Required Skills.
|
Similar jobs
- RD
Principal Information Security Engineer
NewRandstad Digital
St. Louis, MO🇺🇸$155k - $160k/yrHybrid22 hours agoEncryptionTechnology - DT
Information Security Analyst 3
NewDGN Technologies
Sunnyvale, CA🇺🇸Hybrid22 hours agoTechnology - RS
Information System Security Manager with Security Clearance
NewRMantra Solutions Inc.
Fort Meade, MD🇺🇸Hybrid22 hours agoPenetration TestingTechnology - SH
Security Engineer Basic with Security Clearance
NewSystem High Corporation
Fort Belvoir, VA🇺🇸Hybrid22 hours agoTechnology - TA
Senior Reverse Engineer / CNO Engineer with Security Clearance
NewTalentOps
Annapolis Junction, MD🇺🇸$267k - $279k/yrOn-site2 days agoEmbedded SystemsConfluenceJiraEngineering - CG
Security Engineer
NewCapgemini Government Solutions
McLean, VA🇺🇸Hybrid22 hours agoSplunkTCP/IPAzure+4Technology