Quick Overview
Seniority
Mid Senior
Work mode
On Site
Location
Austin, TX, United States
Posted
2 days ago
SplunkTCP/IPAzureDNSHIPAA
Job Description
Job Title: Network Security Analyst
Location: Onsite -Austin, TX
Duration: 12 Months Contract
Duration: 12 Months Contract
Required Qualifications
- Minimum of seven years of experience in cybersecurity, network security, security operations, incident response, or a closely related information security role.
- Hands-on experience with Microsoft Sentinel, including incident management, analytics rules, workbooks, automation, data connectors, and Kusto Query Language.
- Experience using SIEM for log analysis, alert investigation, dashboarding, correlation searches, and security monitoring.
- Experience with NDR for network traffic analysis, packet/session investigation, threat detection, and incident support.
- Experience with EDR tools, including endpoint alert triage, device investigation, advanced hunting, and response actions.
- Working knowledge of network security concepts, including firewalls, IDS/IPS, proxy logs, DNS, VPN, TCP/IP, segmentation, and secure network architecture.
- Ability to analyze complex security events, correlate data across multiple sources, and produce clear written documentation and recommendations.
- Knowledge of security frameworks, standards, and regulatory considerations such as NIST, CIS Controls, HIPAA, and state information security requirements.
- Strong communication, collaboration, problem-solving, and analytical skills.
Preferred Education and any one or Two Certifications
- Bachelor’s degree in cybersecurity, computer science, information systems, information technology, or a related field. Relevant experience may be considered in place of education where applicable.
- Microsoft security certifications are strongly preferred, such as
- Microsoft Certified: Security Operations Analyst Associate,
- Microsoft Certified: Cybersecurity Architect Expert,
- Microsoft Certified: Azure Security Engineer Associate, or Microsoft 365 Defender-related certifications.
- Additional preferred certifications include CompTIA Security+, CySA+, GIAC security certifications, CISSP, CISM, CISA, Splunk Core Certified Power User, Splunk Enterprise Security Certified Admin, or SentinelOne product certifications.
Knowledge, Skills, and Abilities
- Knowledge of SIEM, SOAR, EDR, XDR, network detection and response, log management, and threat intelligence concepts.
- Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting.
- Skill in identifying indicators of compromise, attacker tactics, suspicious network patterns, and endpoint-based threats.
- Ability to prioritize alerts, document investigative steps, and escalate incidents based on severity and business impact.
- Ability to work independently and collaboratively in a security operations environment with shifting priorities and time-sensitive incidents.
- Ability to communicate cybersecurity risks, findings, and recommended actions to both technical and non-technical audiences.
Years Required/Preferred Experience
- 7 Required Knowledge of SIEM, SOAR, EDR, XDR, NDR
- 7 Required Experience with security log collection and management
- 7 Required Experience with threat intelligence concepts
- 7 Required Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting
- 7 Required Experience in SIEM platform/architecture support
- 7 Required Experience in detection engineering methodology and implementation
- 10 Preferred Knowledge of SIEM, SOAR, EDR, XDR, NDR
- 10 Preferred Experience with security log collection and management
- 10 Preferred Experience with threat intelligence concepts
- 10 Preferred Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting
- 10 Preferred Experience in SIEM platform/architecture support
- 10 Preferred Experience in detection engineering methodology and implementation
Similar jobs
- RA
Systems Administrator (VDI) — TS/SCI with Security Clearance
NewRackner
Dayton, OH🇺🇸On-site12 hours agoTechnology - HS
Systems Engineer with Security Clearance
NewHonu Services
Arlington, VA🇺🇸$165k - $175k/yrOn-site12 hours agoTechnology - SA
Deskside Support Technician
NewSAIC
Washington, DC🇺🇸$40.0k - $80k/yrRemoteYesterdayMFAActive DirectoryAzure+1Technology - BL
Sr. Network Engineer with Security Clearance
NewBy Light
Macdill AFB, FL🇺🇸Hybrid2 days agoTechnology - WY
System Administrator 3 with Security Clearance
NewWyetech, LLC
Bluffdale, UT🇺🇸$49 - $118/hrOn-site2 days agoTechnology - WY
Software Engineer (Hybrid) with Security Clearance
NewWyetech, LLC
Columbia, MD🇺🇸$52 - $140/hrHybrid2 days agoDockerFlaskMicroservices+11Technology