Quick Overview
Job Description
DirectClient: Texas Health and Human Services Commission(HHSC)
Solicitation Number: 529701769
Title: CyberSecurity Analyst
Location: 701 W. 51st, Austin, Texas 78751
Duration: Until 8/31/2027 with possible extension
Last date for submission: September 16, 2026 (12.00 PM-CST)
Important Note: Position will be 100% ONSITE. Texas local candidates only.
DESCRIPTION OF SERVICES:
The Network Security Analyst I performs advanced cybersecurity analysis and threat triage activities within the Cybersecurity Operations Center (CSOC). Work involves continuously monitoring, triaging, analyzing, and prioritizing cybersecurity alerts; investigating suspicious activity; identifying potential threats; and coordinating incident response activities to protect agency information systems, networks, and data. Serves as a primary point of contact for security event analysis, threat identification, and incident escalation.
Essential Job Functions
• Monitors, analyzes, and triages cybersecurity alerts generated by Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), cloud security, email security, identity protection, and network security platforms.
• Conducts initial investigations of detected and reported security events to determine severity, scope, impact, and potential risk to agency operations.
• Identifies, validates, and prioritizes potential cybersecurity incidents, escalating confirmed threats to Incident Response, Threat Hunting, or SOC Engineering teams according to established procedures.
• Correlates security events from multiple data sources, including endpoints (EDR), firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), cloud services, authentication systems, and threat intelligence feeds.
• Reviews and analyzes indicators of compromise (IOCs), suspicious network activity, phishing emails, malware detections, and anomalous user behavior.
• Documents investigations, findings, and response actions in ticketing and case management systems to ensure accurate tracking and reporting.
• Assists with incident containment, eradication, and recovery efforts by coordinating with technical teams and stakeholders.
• Reports and escalates to the CSOC Team Lead and/or SOC Manager.
• Supports the continuous improvement of threat detection capabilities through alert tuning, process refinement, threat intelligence integration, and identification of false-positive trends.
• Performs vulnerability assessment reviews and evaluates identified vulnerabilities for potential risk and remediation prioritization.
• Supports development and maintenance of operational procedures, playbooks, workflows, and knowledge base articles related to threat detection and incident response.
• Researches emerging cyber threats, attack techniques, tactics, and procedures (TTPs) to improve detection and response effectiveness.
Knowledge, Skills, and Abilities
Knowledge of:
• Cybersecurity Operations Center (CSOC/SOC) operations and best practices.
• Security incident triage, analysis, investigation, and escalation procedures.
• Security monitoring technologies, including SIEM, EDR/XDR, IDS/IPS, firewalls, endpoint security solutions, and cloud security platforms.
• Common cyber threats, attack vectors, malware, phishing campaigns, insider threats, and advanced persistent threat (APT) techniques.
• Threat intelligence concepts, indicators of compromise (IOCs), indicators of attack (IOAs), and MITRE ATT&CK methodologies.
• Windows, Linux, networking protocols, Active Directory, Microsoft Entra ID, cloud environments, and enterprise security controls.
• Incident response lifecycle and cybersecurity frameworks such as NIST Cybersecurity Framework, NIST Incident Response guidance, and PICERL.
Skill in:
• Security event analysis and threat triage.
• Correlating and interpreting data from multiple cybersecurity tools.
• Investigating suspicious activity and identifying indicators of compromise.
• Using SIEM, EDR/XDR, threat intelligence, vulnerability management, and case management platforms.
• Producing clear documentation, incident reports, and technical communications.
• Prioritizing and managing multiple investigations in a fast-paced operational environment for a large organization.
• Knowledge of and experience with query languages such as KQL, Lucene, SPL, ESQL, etc.
• Knowledge of and experience with scripting languages such as PowerShell, Python, Bash, etc.
Ability to:
• Analyze complex security events and distinguish legitimate threats from false positives.
• Make risk-based decisions during incident investigations.
• Execute established incident response and escalation procedures.
• Collaborate effectively with security engineers, incident responders, system administrators, CISO leadership, and business stakeholders.
• Communicate technical information clearly to both technical and non-technical audiences.
• Work independently and as part of a 24x7 cybersecurity operations team.
Preferred Education and Certifications
• Graduation from an accredited four-year college or university with major coursework in cybersecurity, information security, computer science, computer information systems, management information systems, or a related field is preferred. Relevant education and experience may be substituted for one another.
• One or more of the following certifications are preferred:
• CompTIA Security+
• GIAC Certified Incident Handler (GCIH)
• GIAC Certified Intrusion Analyst (GCIA)
• Certified SOC Analyst (CSA)
• Microsoft Cybersecurity Analyst (SC-200)
• Other GIAC or SOC-related certifications
Required Qualifications
• Minimum of five (5) years of experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines.
• Experience working with one or more of the following technologies:
• SIEM platforms (NetWitness, Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, etc.)
• Microsoft Security (Microsoft 365 Defender XDR, Microsoft Sentinel)
• Endpoint Detection and Response (Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, etc.)
• IDS/IPS technologies (Trellix/FireEye, Corelight)
• Threat intelligence platforms (VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, MISP)
• Vulnerability management tools (Tenable, Qualys, Rapid7)
• Email security platforms (IronPort ESA, Abnormal.ai, Proofpoint)
• Cloud security monitoring solutions (Google Wiz, MDCA, Cortex Cloud, Sysdig)
• Secure Access Service Edge (Zscaler, Prisma, Netskope)
• Experience triaging security alerts, analyzing security events, and documenting incident investigations.
• Experience with cybersecurity frameworks, incident response processes, and threat detection methodologies.
Similar jobs
- IN
Security Analyst
NewInnosoul inc
Austin, TX🇺🇸On-site17 hours agoAzureSplunkHIPAA+2Technology - CT
Cybersecurity and Network Security Analyst - $111 CTC - ONSITE (CURRENT TX Residents)
NewChandra Technologies, Inc.
Austin, TX🇺🇸On-site17 hours agoSplunkTCP/IPAzure+2Technology - ES
Network Security Analyst/Cybersecurity Analyst (With State/Federal exp)
NewEsolvit, Inc.
Austin, TX🇺🇸On-site17 hours agoSplunkActive DirectoryBash+3Technology - SI
Information System Security Engineer (ISSE)- FTE- 100% onsite- Need Active Top Secret Clearance
NewStellent IT LLC
Washington, DC🇺🇸On-site17 hours agoTechnology - CM
Security Control Assessor (SCA)
NewChenega MIOS
Arlington, VA🇺🇸$159.2k/yrHybrid17 hours agoAdministrative - TS
Network Security Analyst - Local to Texas
NewTriwave Solutions Inc
Austin, TX🇺🇸Hybrid17 hours agoPythonPowerShellBash+3Technology