Why This Role Stands Out
This hybrid role offers a significant opportunity to deepen your expertise in SIEM and SOAR technologies by integrating critical applications into Google SecOps. You'll thrive here if you possess a strong background in security operations, threat hunting, and incident response, and are eager to contribute to a reputable organization. Apply now to advance your career in a dynamic and evolving cybersecurity landscape.
Quick Overview
Job Description
Job Description
We are seeking an experienced Security Consultant / Security Operations Analyst to support the integration of HHSC and DSHS applications into Google SecOps (SIEM/SOAR).
This is a hands-on security operations role focused on monitoring, investigating, detecting, and responding to security events across network, endpoint, identity, and cloud environments.
The ideal candidate will have strong experience with Microsoft Sentinel, SIEM/SOAR, NDR, EDR, KQL, SPL, network security, threat hunting, and incident response, along with the ability to communicate security risks to both technical and business stakeholders.
Key Responsibilities
- Monitor security alerts, logs, network events, endpoint telemetry, and threat intelligence feeds.
- Triage and investigate suspicious activities and determine scope, impact, and severity.
- Lead escalation and coordinate containment and response activities.
- Build, tune, and maintain detection rules, dashboards, alerts, playbooks, and automation workflows.
- Perform threat hunting using KQL, SPL, packet/session analysis, and endpoint telemetry.
- Support vulnerability assessments, risk assessments, and security control evaluations.
- Prepare detailed incident reports and track corrective actions through resolution.
- Provide security briefings and communicate risks to security leadership and business stakeholders.
- Collaborate with network, infrastructure, cloud, and application teams to validate events and reduce security risks.
- Provide security evidence, metrics, and documentation for compliance and audit requests.
- Participate occasionally in after-hours support for high-priority security incidents and planned maintenance.
Required Qualifications
- 7+ years of experience in cybersecurity, network security, security operations, or incident response.
- Hands-on experience with Microsoft Sentinel, including:
- Incident management
- Analytics rules
- Workbooks
- Automation
- Data connectors
- KQL
- Strong SIEM experience with log analysis, alert investigation, correlation searches, and dashboard development.
- Experience with NDR technologies, including network traffic and packet/session analysis.
- Experience with EDR, including alert triage, device investigation, advanced hunting, and response actions.
- Strong understanding of:
- Firewalls
- IDS/IPS
- Proxy logs
- DNS
- VPN
- TCP/IP
- Network segmentation
- Knowledge of NIST, CIS Controls, HIPAA, and state information security requirements.
- Strong analytical, written, and verbal communication skills.
- Ability to explain security risks and technical findings to both technical and non-technical audiences.
- Experience with Google SecOps or Wiz.
Preferred Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field. Equivalent relevant experience may be considered.
- Google SecOps or Wiz certification.
- Microsoft security certifications such as SC-200, AZ-500, or SC-100.
- Security certifications such as:
- Security+
- CySA+
- GIAC
- CISSP
- CISM
- CISA
- Splunk Core Certified Power User
- Splunk ES Administrator
- SentinelOne certifications
- Hands-on Splunk / SPL experience.
- Experience mentoring junior security analysts.
- Healthcare or public-sector cybersecurity experience.
Similar jobs
- TS
Java Developer
NewTechLink Systems, Inc.
San Antonio, TX🇺🇸$60 - $65/hrOn-siteYesterdayOraclePL/SQLSOAP+15Technology - TH
RPG Developer
NewThor, Inc
United States🇺🇸RemoteYesterdaySQLTechnology - TG
Senior ServiceNow Developer
NewTalent Groups
United States🇺🇸HybridYesterdayTechnology - BR
Datastage Developer/Admin
NewBlue Rose Technologies LLC
Culver City, CA🇺🇸On-siteYesterdayOracleSQLSQL Server+2Technology - CS
Network Security Engineer
NewCSZNet, Inc
Washington, DC🇺🇸HybridYesterdayTechnology - BO
Associate Backend Software Engineer, Phantom Works
NewBoeing
Saint Louis, MO🇺🇸$99.5k - $134.6k/yrOn-siteYesterdayDockerMicroservicesPL/SQL+11Technology