Haystack
← Back to Jobs
Technology
SP

Network Security Analyst

Software People, Inc.Austin, TX🇺🇸United StatesPosted 11 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Austin, TX, United States
Posted
19 hours ago
PythonPowerShellBashActive Directory

Job Description

Phone/Skype Hire. Onsite from day 1

Local preferred. State of TX residency is must.

Location: Austin, Texas

Duration: 6+ months

Need 3-page resumes. Must have current LinkedIn profile. Please complete the enclosed documentation in its entirety and always get RTR physically signed.

The Network Security Analyst I performs advanced cybersecurity analysis and threat triage activities within the Cybersecurity Operations Center (CSOC). Work involves continuously monitoring, triaging, analyzing, and prioritizing cybersecurity alerts; investigating suspicious activity; identifying potential threats; and coordinating incident response activities to protect agency information systems, networks, and data. Serves as a primary point of contact for security event analysis, threat identification, and incident escalation.

Responsibilities

  • Monitors, analyzes, and triages cybersecurity alerts generated by Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), cloud security, email security, identity protection, and network security platforms.
  • Conducts initial investigations of detected and reported security events to determine severity, scope, impact, and potential risk to agency operations.
  • Identifies, validates, and prioritizes potential cybersecurity incidents, escalating confirmed threats to Incident Response, Threat Hunting, or SOC Engineering teams according to established procedures.
  • Correlates security events from multiple data sources, including endpoints (EDR), firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), cloud services, authentication systems, and threat intelligence feeds.
  • Reviews and analyzes indicators of compromise (IOCs), suspicious network activity, phishing emails, malware detections, and anomalous user behavior.
  • Documents investigations, findings, and response actions in ticketing and case management systems to ensure accurate tracking and reporting.
  • Assists with incident containment, eradication, and recovery efforts by coordinating with technical teams and stakeholders.
  • Reports and escalates to the CSOC Team Lead and/or SOC Manager.
  • Supports the continuous improvement of threat detection capabilities through alert tuning, process refinement, threat intelligence integration, and identification of false-positive trends.
  • Performs vulnerability assessment reviews and evaluates identified vulnerabilities for potential risk and remediation prioritization.
  • Supports development and maintenance of operational procedures, playbooks, workflows, and knowledge base articles related to threat detection and incident response.
  • Researches emerging cyber threats, attack techniques, tactics, and procedures (TTPs) to improve detection and response effectiveness.

Knowledge, Skills, and Abilities

Knowledge of:

  • Cybersecurity Operations Center (CSOC/SOC) operations and best practices.
  • Security incident triage, analysis, investigation, and escalation procedures.
  • Security monitoring technologies, including SIEM, EDR/XDR, IDS/IPS, firewalls, endpoint security solutions, and cloud security platforms.
  • Common cyber threats, attack vectors, malware, phishing campaigns, insider threats, and advanced persistent threat (APT) techniques.
  • Threat intelligence concepts, indicators of compromise (IOCs), indicators of attack (IOAs), and MITRE ATT&CK methodologies.
  • Windows, Linux, networking protocols, Active Directory, Microsoft Entra ID, cloud environments, and enterprise security controls.
  • Incident response lifecycle and cybersecurity frameworks such as NIST Cybersecurity Framework, NIST Incident Response guidance, and PICERL.

Skill in:

Security event analysis and threat triage.

Correlating and interpreting data from multiple cybersecurity tools.

Investigating suspicious activity and identifying indicators of compromise.

Using SIEM, EDR/XDR, threat intelligence, vulnerability management, and case management platforms.

Producing clear documentation, incident reports, and technical communications.

Prioritizing and managing multiple investigations in a fast-paced operational environment for a large organization.

Knowledge of and experience with query languages such as KQL, Lucene, SPL, ESQL, etc.

Knowledge of and experience with scripting languages such as PowerShell, Python, Bash, etc.

Ability to:

Analyze complex security events and distinguish legitimate threats from false positives.

Make risk-based decisions during incident investigations.

Execute established incident response and escalation procedures.

Collaborate effectively with security engineers, incident responders, system administrators, CISO leadership, and business stakeholders.

Communicate technical information clearly to both technical and non-technical audiences.

Work independently and as part of a 24x7 cybersecurity operations team.

Preferred Education and Certifications

  • Graduation from an accredited four-year college or university with major coursework in cybersecurity, information security, computer science, computer information systems, management information systems, or a related field is preferred. Relevant education and experience may be substituted for one another.
  • One or more of the following certifications are preferred:
  • CompTIA Security+
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • Certified SOC Analyst (CSA)
  • Microsoft Cybersecurity Analyst (SC-200)
  • Other GIAC or SOC-related certifications

Skills Needed

Years

Required/Preferred

Experience

3

Required

Experience triaging security alerts

3

Required

Experience analyzing security events

3

Required

Experience documenting incident investigations

3

Required

Experience with cybersecurity frameworks

3

Required

Experience with incident response processes

3

Required

Experience with threat detection methodologies

3

Required

Experience in cybersecurity operations

3

Required

Experience in security monitoring

3

Required

Experience in incident response

3

Required

Experience in threat detection

3

Required

Experience in security investigations

3

Required

Experience in related cybersecurity disciplines

5

Preferred

Please See Job Description Section for more specific Preferred and Required Skills.

Similar jobs