Why This Role Stands Out
This role offers an exciting opportunity to contribute to critical cybersecurity operations within a reputable global IT services company, fostering significant skills development and career advancement. You'll thrive here if you are a proactive and detail-oriented professional eager to make a tangible impact on network security. Apply today to join a dynamic team and elevate your career.
Quick Overview
Job Description
NMK Global Inc. is a global IT Services & Solutions company specializing in IT Staffing, Technology Consulting, Workforce Solutions, and Application Development Services. We help organizations build high-performing technology teams by connecting them with exceptional talent across a wide range of industries. Our expertise, industry knowledge, and consultative approach enable clients to achieve successful business outcomes while helping professionals advance their careers.
Role: Network Security Analyst I
Location: Austin, TX – Onsite
Position Type: Contract
Job Summary
Texas Health and Human Services Commission (HHSC) is seeking a Network Security Analyst I to support its Cybersecurity Operations Center (CSOC).
The Network Security Analyst I will perform cybersecurity analysis and threat-triage activities, including continuously monitoring security alerts, investigating suspicious activity, identifying potential threats, and coordinating incident-response activities to protect agency information systems, networks, and data.
The ideal candidate should have hands-on experience with SIEM, EDR/XDR, IDS/IPS, firewalls, threat intelligence, vulnerability management, and security monitoring platforms.
Key Responsibilities
- Monitor, analyze, and triage cybersecurity alerts from SIEM, EDR, cloud security, email security, identity protection, and network security platforms.
- Investigate security events to determine severity, scope, impact, and potential risk.
- Identify, validate, and prioritize potential cybersecurity incidents.
- Escalate confirmed threats to Incident Response, Threat Hunting, or SOC Engineering teams.
- Correlate security events across endpoints, firewalls, IDS/IPS, cloud services, authentication systems, and threat-intelligence feeds.
- Investigate indicators of compromise (IOCs), suspicious network activity, phishing emails, malware detections, and anomalous user behavior.
- Document investigations, findings, and response activities in ticketing and case-management systems.
- Assist with incident containment, eradication, and recovery activities.
- Report and escalate security incidents to CSOC leadership.
- Support alert tuning, detection improvements, threat-intelligence integration, and false-positive analysis.
- Perform vulnerability assessment reviews and assist with remediation prioritization.
- Support the development and maintenance of security procedures, playbooks, workflows, and knowledge-base documentation.
- Research emerging cyber threats, attack techniques, tactics, and procedures (TTPs).
Required Qualifications
- Minimum 5 years of experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines.
- Experience triaging security alerts and analyzing security events.
- Experience documenting incident investigations.
- Experience with cybersecurity frameworks and incident-response processes.
- Experience with threat-detection methodologies.
- Experience working in a SOC/CSOC environment.
- Strong understanding of security monitoring technologies.
Technical Skills
Experience with one or more of the following technologies is required:
SIEM:
- Microsoft Sentinel
- Splunk
- QRadar
- ArcSight
- LogRhythm
- NetWitness
EDR/XDR:
- Microsoft Defender for Endpoint
- CrowdStrike
- SentinelOne
- Microsoft 365 Defender XDR
Network Security:
- IDS/IPS
- Firewalls
- Trellix/FireEye
- Corelight
Threat Intelligence:
- VirusTotal
- Google Threat Intelligence
- Cisco Talos
- Recorded Future
- MISP
Vulnerability Management:
- Tenable
- Qualys
- Rapid7
Email Security:
- IronPort ESA
- Abnormal.ai
- Proofpoint
Cloud Security:
- Wiz
- MDCA
- Cortex Cloud
- Sysdig
SASE:
- Zscaler
- Prisma
- Netskope
Additional Technical Skills
- Windows and Linux
- Networking protocols
- Active Directory
- Microsoft Entra ID
- Cloud environments
- Enterprise security controls
- MITRE ATT&CK
- Indicators of Compromise (IOCs)
- Indicators of Attack (IOAs)
- NIST Cybersecurity Framework
- NIST Incident Response guidance
- PICERL
- KQL, Lucene, SPL, ESQL, or similar query languages
- PowerShell, Python, Bash, or similar scripting languages
Education & Certifications
A four-year degree in Cybersecurity, Information Security, Computer Science, Computer Information Systems, Management Information Systems, or a related field is preferred. Relevant education and experience may be substituted.
Preferred certifications include:
- CompTIA Security+
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Intrusion Analyst (GCIA)
- Certified SOC Analyst (CSA)
- Microsoft Cybersecurity Analyst (SC-200)
- Other GIAC or SOC-related certifications
Work Expectations
- Participate in incident response, escalation, and after-action review activities.
- Support enterprise security monitoring for systems handling sensitive information.
- Maintain accurate investigation notes, operational documentation, metrics, and leadership-ready summaries.
- Provide support outside normal business hours during high-priority security incidents when requested.
- Work independently and as part of a 24x7 cybersecurity operations environment.
NMK Global Inc. is an Equal Opportunity Employer. We are committed to creating an inclusive workplace and consider all qualified applicants without regard to age, race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation, gender identity, or any other characteristic protected by applicable law.
Similar jobs
- MA
Information Systems Security Engineer
NewMANTECH
Maryland🇺🇸Hybrid16 minutes agoPKITechnology - TE
SailPoint Engineer, Mount Airey Group, Arlington, VA
NewTechnologist, Inc.
Arlington, Virginia🇺🇸On-siteYesterday401kPowerShellPythonEngineering - ES
Cybersecurity Architect - Active TS/SCI with CI Poly
NewENS Solutions, LLC
Reston, Virginia🇺🇸On-site6 hours ago401kGCPAWS+5Technology - ES
Cybersecurity Architect - Active TS/SCI with CI Poly
NewENS Solutions, LLC
Washington, District of Columbia🇺🇸On-site6 hours ago401kGCPAWS+5Technology - SD
1756 - Cybersecurity Engineer
NewSigma Defense
Rome, New York🇺🇸On-site8 hours agoAzureComplianceHTTPS+2Technology - LS
Information Systems Security Officer (ISSO) Level 3
NewLV8D Solutions
Chantilly, Virginia🇺🇸On-site8 hours agoArticulateDue DiligenceMicrosoft Office+2Technology