Haystack
← Back to Jobs
Technology
CG

Network Security Analyst 2

CCS Global TechAustin, TX🇺🇸United StatesPosted 14 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Austin, TX, United States
Posted
21 hours ago
AzureSplunkHIPAATCP/IPDNS

Job Description

CCS Global Tech is a rapidly growing Information Technology company with a diverse portfolio of technology products and services and a large network of industry partnerships. With over 22 years of being a successful business with a global talent pool and presence, CCS is a certified Microsoft Gold Partner and specializes in delivering expert Microsoft based solutions for technical and business needs. We have been recognized by Inc. 500 Magazine as one of the fastest growing small companies in the Unites States.
we are a Tier 1 vendor for the City and County of San Francisco for Cloud Services, Staffing Services and Training Services. For this multi-year opportunity with a diverse set of needs to address, we are currently focusing on establishing partnerships with individuals as well as companies who can help us enhance our overall service portfolio, cut lead times, and ultimately help us deliver successfully. We currently hold sizable Government accounts in the San Francisco bay area including City and County of San Francisco, San Mateo County, and Santa Clara County.
We take great pride in our global reach and local influence. Your experience alongside our highly skilled and talented internal team who guide you along the way, offers key insights into what helps you stand out in a competitive job market.
If you are a partner company, please submit resumes with contact information of your own W2 Consultants only. Submitted consultants are expected to have excellent communication skills.

Mandatory Skills:

  1. Minimum of seven years of experience in cybersecurity, network security, security operations, incident response, or a closely related information security role.
  2. Hands-on experience with Microsoft Sentinel, including incident management, analytics rules, workbooks, automation, data connectors, and Kusto Query Language.
  3. Experience using SIEM for log analysis, alert investigation, dashboarding, correlation searches, and security monitoring.
  4. Experience with NDR for network traffic analysis, packet/session investigation, threat detection, and incident support.
  5. Experience with EDR tools, including endpoint alert triage, device investigation, advanced hunting, and response actions.
  6. Working knowledge of network security concepts, including firewalls, IDS/IPS, proxy logs, DNS, VPN, TCP/IP, segmentation, and secure network architecture.
  7. Ability to analyze complex security events, correlate data across multiple sources, and produce clear written documentation and recommendations.
  8. Knowledge of security frameworks, standards, and regulatory considerations such as NIST, CIS Controls, HIPAA, and state information security requirements.
  9. Strong communication, collaboration, problem-solving, and analytical skills.
  10. 7 years of Knowledge of SIEM, SOAR, EDR, XDR, NDR
  11. 7 years of Experience with security log collection and management
  12. 7 years of Experience with threat intelligence concepts
  13. 7 years of Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting
  14. 7 years of Experience in SIEM platform/architecture support
  15. 7 years of Experience in detection engineering methodology and implementation

Desirable Skills:

  1. Bachelor's degree in cybersecurity, computer science, information systems, information technology, or a related field. Relevant experience may be considered in place of education where applicable.
  2. Microsoft security certifications are strongly preferred, such as Microsoft Certified: Security Operations Analyst Associate, Microsoft Certified: Cybersecurity Architect Expert, Microsoft Certified: Azure Security Engineer Associate, or Microsoft 365 Defender-related certifications.
  3. Additional preferred certifications include CompTIA Security+, CySA+, GIAC security certifications, CISSP, CISM, CISA, Splunk Core Certified Power User, Splunk Enterprise Security Certified Admin, or SentinelOne product certifications.
  4. 10 years of Knowledge of SIEM, SOAR, EDR, XDR, NDR
  5. 10 years of Experience with security log collection and management
  6. 10 years of Experience with threat intelligence concepts
  7. 10 years of Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting
  8. 10 years of Experience in SIEM platform/architecture support
  9. 10 years of Experience in detection engineering methodology and implementation

Knowledge, Skills, and Abilities

  • Knowledge of SIEM, SOAR, EDR, XDR, network detection and response, log management, and threat intelligence concepts.
  • Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting.
  • Skill in identifying indicators of compromise, attacker tactics, suspicious network patterns, and endpoint-based threats.
  • Ability to prioritize alerts, document investigative steps, and escalate incidents based on severity and business impact.
  • Ability to work independently and collaboratively in a security operations environment with shifting priorities and time-sensitive incidents.
  • Ability to communicate cybersecurity risks, findings, and recommended actions to both technical and non-technical audiences.

Similar jobs