Haystack
← Back to Jobs
Technology
BT

CyberSecurity Engineer

Bansar Technologies Inc.Austin, TX🇺🇸United StatesPosted 11 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Austin, TX, United States
Posted
17 hours ago
SplunkActive DirectoryBashPowerShellPrismaPython

Job Description

DirectClient: Texas Health and Human Services Commission(HHSC)
Solicitation Number: 529701769
Title: CyberSecurity Analyst
Location: 701 W. 51st, Austin, Texas 78751
Duration: Until 8/31/2027 with possible extension
Last date for submission: September 16, 2026 (12.00 PM-CST)
 
Important Note: Position will be 100% ONSITE. Texas local candidates only.

DESCRIPTION OF SERVICES:
The Network Security Analyst I performs advanced cybersecurity analysis and threat triage activities within the Cybersecurity Operations Center (CSOC). Work involves continuously monitoring, triaging, analyzing, and prioritizing cybersecurity alerts; investigating suspicious activity; identifying potential threats; and coordinating incident response activities to protect agency information systems, networks, and data. Serves as a primary point of contact for security event analysis, threat identification, and incident escalation. 

Essential Job Functions 
•    Monitors, analyzes, and triages cybersecurity alerts generated by Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), cloud security, email security, identity protection, and network security platforms. 
•    Conducts initial investigations of detected and reported security events to determine severity, scope, impact, and potential risk to agency operations. 
•    Identifies, validates, and prioritizes potential cybersecurity incidents, escalating confirmed threats to Incident Response, Threat Hunting, or SOC Engineering teams according to established procedures. 
•    Correlates security events from multiple data sources, including endpoints (EDR), firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), cloud services, authentication systems, and threat intelligence feeds. 
•    Reviews and analyzes indicators of compromise (IOCs), suspicious network activity, phishing emails, malware detections, and anomalous user behavior. 
•    Documents investigations, findings, and response actions in ticketing and case management systems to ensure accurate tracking and reporting. 
•    Assists with incident containment, eradication, and recovery efforts by coordinating with technical teams and stakeholders. 
•    Reports and escalates to the CSOC Team Lead and/or SOC Manager. 
•    Supports the continuous improvement of threat detection capabilities through alert tuning, process refinement, threat intelligence integration, and identification of false-positive trends. 
•    Performs vulnerability assessment reviews and evaluates identified vulnerabilities for potential risk and remediation prioritization. 
•    Supports development and maintenance of operational procedures, playbooks, workflows, and knowledge base articles related to threat detection and incident response. 
•    Researches emerging cyber threats, attack techniques, tactics, and procedures (TTPs) to improve detection and response effectiveness. 
 
Knowledge, Skills, and Abilities 
Knowledge of: 
•    Cybersecurity Operations Center (CSOC/SOC) operations and best practices. 
•    Security incident triage, analysis, investigation, and escalation procedures. 
•    Security monitoring technologies, including SIEM, EDR/XDR, IDS/IPS, firewalls, endpoint security solutions, and cloud security platforms. 
•    Common cyber threats, attack vectors, malware, phishing campaigns, insider threats, and advanced persistent threat (APT) techniques. 
•    Threat intelligence concepts, indicators of compromise (IOCs), indicators of attack (IOAs), and MITRE ATT&CK methodologies. 
•    Windows, Linux, networking protocols, Active Directory, Microsoft Entra ID, cloud environments, and enterprise security controls. 
•    Incident response lifecycle and cybersecurity frameworks such as NIST Cybersecurity Framework, NIST Incident Response guidance, and PICERL. 

Skill in: 
•    Security event analysis and threat triage. 
•    Correlating and interpreting data from multiple cybersecurity tools. 
•    Investigating suspicious activity and identifying indicators of compromise. 
•    Using SIEM, EDR/XDR, threat intelligence, vulnerability management, and case management platforms. 
•    Producing clear documentation, incident reports, and technical communications. 
•    Prioritizing and managing multiple investigations in a fast-paced operational environment for a large organization. 
•    Knowledge of and experience with query languages such as KQL, Lucene, SPL, ESQL, etc. 
•    Knowledge of and experience with scripting languages such as PowerShell, Python, Bash, etc. 

Ability to: 
•    Analyze complex security events and distinguish legitimate threats from false positives. 
•    Make risk-based decisions during incident investigations. 
•    Execute established incident response and escalation procedures. 
•    Collaborate effectively with security engineers, incident responders, system administrators, CISO leadership, and business stakeholders. 
•    Communicate technical information clearly to both technical and non-technical audiences. 
•    Work independently and as part of a 24x7 cybersecurity operations team. 
 
Preferred Education and Certifications 
•    Graduation from an accredited four-year college or university with major coursework in cybersecurity, information security, computer science, computer information systems, management information systems, or a related field is preferred. Relevant education and experience may be substituted for one another. 
•    One or more of the following certifications are preferred: 
•    CompTIA Security+ 
•    GIAC Certified Incident Handler (GCIH) 
•    GIAC Certified Intrusion Analyst (GCIA) 
•    Certified SOC Analyst (CSA) 
•    Microsoft Cybersecurity Analyst (SC-200) 
•    Other GIAC or SOC-related certifications 
 
Required Qualifications 
•    Minimum of five (5) years of experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines. 
•    Experience working with one or more of the following technologies: 
•    SIEM platforms (NetWitness, Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, etc.) 
•    Microsoft Security (Microsoft 365 Defender XDR, Microsoft Sentinel) 
•    Endpoint Detection and Response (Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, etc.) 
•    IDS/IPS technologies (Trellix/FireEye, Corelight) 
•    Threat intelligence platforms (VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, MISP) 
•    Vulnerability management tools (Tenable, Qualys, Rapid7) 
•    Email security platforms (IronPort ESA, Abnormal.ai, Proofpoint) 
•    Cloud security monitoring solutions (Google Wiz, MDCA, Cortex Cloud, Sysdig) 
•    Secure Access Service Edge (Zscaler, Prisma, Netskope) 
•    Experience triaging security alerts, analyzing security events, and documenting incident investigations. 
•    Experience with cybersecurity frameworks, incident response processes, and threat detection methodologies.

Similar jobs