Why This Role Stands Out
This role offers a fantastic opportunity to significantly impact Masterapp Labs' security posture and develop advanced network defense strategies. You'll thrive here if you're a proactive security professional eager to contribute to a reputable tech company and grow your expertise. Apply today to join their innovative team!
Quick Overview
Seniority
Mid Senior
Work mode
On Site
Location
Austin, TX, United States
Posted
4 days ago
AzureSplunkHIPAATCP/IPDNS
Job Description
Job Title: Sr. Network Security Analyst
Location: Austin, TX, (Onsite)
Position Type: Contract
Interview Mode: MS Teams
Essential Job Functions
- Monitor security alerts, logs, network events, endpoint telemetry, and threat intelligence feeds.
- Analyze suspicious activity, anomalous network behavior, malware indicators, endpoint detections, and SIEM correlation events to determine scope, impact, and required response actions.
- Perform incident triage, investigation, escalation, containment coordination, and documentation in alignment with HHSC security operations procedures.
- Develop, tune, and maintain detection rules, dashboards, alerts, playbooks, and queries to improve visibility across network, endpoint, identity, and cloud environments.
- Support threat hunting activities using KQL, SPL, packet/session analysis, endpoint telemetry, and other investigative techniques.
- Assist with vulnerability, risk, and control assessments for network security infrastructure and enterprise information systems.
- Document findings, prepare incident reports, track corrective actions, and communicate technical information to security leadership and business stakeholders.
- Collaborate with network, infrastructure, cloud, endpoint, and application teams to validate security events and implement risk mitigation measures.
- Maintain awareness of emerging cyber threats, attack techniques, indicators of compromise, and security best practices relevant to healthcare and public-sector environments.
- Support compliance, audit, and reporting activities by providing evidence, metrics, and security operations documentation as requested.
Required Qualifications
- Minimum of seven years of experience in cybersecurity, network security, security operations, incident response, or a closely related information security role.
- Hands-on experience with Microsoft Sentinel, including incident management, analytics rules, workbooks, automation, data connectors, and Kusto Query Language.
- Experience using SIEM for log analysis, alert investigation, dashboarding, correlation searches, and security monitoring.
- Experience with NDR for network traffic analysis, packet/session investigation, threat detection, and incident support.
- Experience with EDR tools, including endpoint alert triage, device investigation, advanced hunting, and response actions.
- Working knowledge of network security concepts, including firewalls, IDS/IPS, proxy logs, DNS, VPN, TCP/IP, segmentation, and secure network architecture.
- Ability to analyze complex security events, correlate data across multiple sources, and produce clear written documentation and recommendations.
- Knowledge of security frameworks, standards, and regulatory considerations such as NIST, CIS Controls, HIPAA, and state information security requirements.
- Strong communication, collaboration, problem-solving, and analytical skills.
Preferred Education and Certifications
- Bachelor’s degree in cybersecurity, computer science, information systems, information technology, or a related field. Relevant experience may be considered in place of education where applicable.
- Microsoft security certifications are strongly preferred, such as Microsoft Certified: Security Operations Analyst Associate, Microsoft Certified: Cybersecurity Architect Expert, Microsoft Certified: Azure Security Engineer Associate, or Microsoft 365 Defender-related certifications.
- Additional preferred certifications include CompTIA Security+, CySA+, GIAC security certifications, CISSP, CISM, CISA, Splunk Core Certified Power User, Splunk Enterprise Security Certified Admin, or SentinelOne product certifications.
Knowledge, Skills, and Abilities
- Knowledge of SIEM, SOAR, EDR, XDR, network detection and response, log management, and threat intelligence concepts.
- Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting.
- Skill in identifying indicators of compromise, attacker tactics, suspicious network patterns, and endpoint-based threats.
- Ability to prioritize alerts, document investigative steps, and escalate incidents based on severity and business impact.
- Ability to work independently and collaboratively in a security operations environment with shifting priorities and time-sensitive incidents.
- Ability to communicate cybersecurity risks, findings, and recommended actions to both technical and non-technical audiences.
Work Expectations
- Participate in incident response, escalation, and after-action review activities as needed.
- Support enterprise security monitoring for systems that process, store, or transmit sensitive information.
- Follow HHSC policies, procedures, standards, and applicable state and federal security requirements.
- Maintain accurate operational documentation, investigation notes, metrics, and leadership-ready summaries.
- May be required to provide support outside normal business hours during high-priority security incidents or planned maintenance activities.
II. CANDIDATE SKILLS AND QUALIFICATIONS
|
Minimum Requirements:
Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity.
|
||
|
Years
|
Required/Preferred
|
Experience
|
|
7
|
Required
|
Knowledge of SIEM, SOAR, EDR, XDR, NDR
|
|
7
|
Required
|
Experience with security log collection and management
|
|
7
|
Required
|
Experience with threat intelligence concepts
|
|
7
|
Required
|
Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting
|
|
7
|
Required
|
Experience in SIEM platform/architecture support
|
|
7
|
Required
|
Experience in detection engineering methodology and implementation
|
|
10
|
Preferred
|
Knowledge of SIEM, SOAR, EDR, XDR, NDR
|
|
10
|
Preferred
|
Experience with security log collection and management
|
|
10
|
Preferred
|
Experience with threat intelligence concepts
|
|
10
|
Preferred
|
Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting
|
|
10
|
Preferred
|
Experience in SIEM platform/architecture support
|
|
10
|
Preferred
|
Experience in detection engineering methodology and implementation
|
Similar jobs
- BS
EXPLOITATION ANALYST Levels I-IV with Security Clearance
BTS Software Solutions
Annapolis Junction, MD🇺🇸$120k - $260k/yrHybrid4 days agoPenetration Testing - GE
Network Firewall Engineer
NewGenesis10
Chandler, AZ🇺🇸$67 - $75/hrHybrid11 hours agoSOAPLoad BalancingSplunk+5 - AL
Cybersecurity Manager
NewAbbott Laboratories
Lake Forest, Illinois🇺🇸Hybrid1 hour agoGCPAWSAzure+1Technology - LE
Junior Security Engineer
NewLeidos
Silver Spring, MD🇺🇸$69.5k - $125.7k/yrOn-siteYesterdayEncryptionSplunkTCP/IP+3Technology - LE
Junior Security Engineer
NewLeidos
Chevy Chase, MD🇺🇸$69.5k - $125.7k/yrOn-siteYesterdayEncryptionSplunkTCP/IP+3Technology - LE
Junior Security Engineer
NewLeidos
Gaithersburg, MD🇺🇸$69.5k - $125.7k/yrOn-siteYesterdayEncryptionSplunkTCP/IP+3Technology