Haystack
← Back to Jobs
Technology
AS

Network Security Analyst - SOC , Cybersecurity , SIEM

ALIS SoftwareAustin, TX🇺🇸United StatesPosted 15 Sept 2026

Why This Role Stands Out

This role offers a fantastic opportunity to deepen your expertise in network security and threat analysis within a dynamic SOC environment, contributing directly to safeguarding critical information systems. You'll thrive here if you possess a keen eye for detail, a proactive approach to cybersecurity challenges, and a desire to grow your skills in a collaborative setting. Apply today to join a reputable company and make a significant impact in protecting against cyber threats.

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Austin, TX, United States
Posted
Yesterday
SplunkPrisma

Job Description

JOB DESCRIPTION
POSITION: Network Security Analyst - SOC , Cybersecurity , SIEM 
DURATION: Long term
Location: Austin, TX - Onsite


Job Description
A network security analyst ensures that information systems and computer networks are secure. This includes protecting the company against hackers and cyber-attacks, as well as monitoring network traffic and server logs for activity that seems unusual. Additionally, these analysts are responsible for finding vulnerabilities in the computer networks and creating recommendations for how to minimize these vulnerabilities. The network security analyst investigates security breaches, develops strategies for any security issues that arise, and utilizes the help of firewalls and antivirus software to maintain security. DISCLAIMER: Candidates for this position will be subject to a pre-employment security review to determine employment eligibility.
 
Job Summary 
The Network Security Analyst I performs advanced cybersecurity analysis and threat triage activities within the Cybersecurity Operations Center (CSOC). Work involves continuously monitoring, triaging, analyzing, and prioritizing cybersecurity alerts; investigating suspicious activity; identifying potential threats; and coordinating incident response activities to protect agency information systems, networks, and data. Serves as a primary point of contact for security event analysis, threat identification, and incident escalation. 
Essential Job Functions 
  • Monitors, analyzes, and triages cybersecurity alerts generated by Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), cloud security, email security, identity protection, and network security platforms. 
  • Conducts initial investigations of detected and reported security events to determine severity, scope, impact, and potential risk to agency operations. 
  • Identifies, validates, and prioritizes potential cybersecurity incidents, escalating confirmed threats to Incident Response, Threat Hunting, or SOC Engineering teams according to established procedures. 
  • Correlates security events from multiple data sources, including endpoints (EDR), firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), cloud services, authentication systems, and threat intelligence feeds. 
  • Reviews and analyzes indicators of compromise (IOCs), suspicious network activity, phishing emails, malware detections, and anomalous user behavior. 
  • Documents investigations, findings, and response actions in ticketing and case management systems to ensure accurate tracking and reporting. 
  • Assists with incident containment, eradication, and recovery efforts by coordinating with technical teams and stakeholders. 
  • Reports and escalates to the CSOC Team Lead and/or SOC Manager. 
  • Supports the continuous improvement of threat detection capabilities through alert tuning, process refinement, threat intelligence integration, and identification of false-positive trends. 
  • Performs vulnerability assessment reviews and evaluates identified vulnerabilities for potential risk and remediation prioritization. 
  • Supports development and maintenance of operational procedures, playbooks, workflows, and knowledge base articles related to threat detection and incident response. 
  • Researches emerging cyber threats, attack techniques, tactics, and procedures (TTPs) to improve detection and response effectiveness. 
Required Qualifications 
  • Minimum of five (5) years of experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines. 
  • Experience working with one or more of the following technologies: 
  • SIEM platforms (NetWitness, Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, etc.) 
  • Microsoft Security (Microsoft 365 Defender XDR, Microsoft Sentinel) 
  • Endpoint Detection and Response (Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, etc.) 
  • IDS/IPS technologies (Trellix/FireEye, Corelight) 
  • Threat intelligence platforms (VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, MISP) 
  • Vulnerability management tools (Tenable, Qualys, Rapid7) 
  • Email security platforms (IronPort ESA, Abnormal.ai, Proofpoint) 
  • Cloud security monitoring solutions (Google Wiz, MDCA, Cortex Cloud, Sysdig) 
  • Secure Access Service Edge (Zscaler, Prisma, Netskope) 
  • Experience triaging security alerts, analyzing security events, and documenting incident investigations. 
  • Experience with cybersecurity frameworks, incident response processes, and threat detection methodologies. 
Work Expectations 
  • Participate in incident response, escalation, and after-action review activities as needed. 
  • Support enterprise security monitoring for systems that process, store, or transmit sensitive information. 
  • Follow HHSC policies, procedures, standards, and applicable state and federal security requirements. 
  • Maintain accurate operational documentation, investigation notes, metrics, and leadership-ready summaries. 
  • Must be able to provide support outside of normal business hours during high-priority security incidents, as approved by the SOC Manager. 
II.  CANDIDATE SKILLS AND QUALIFICATIONS
Minimum Requirements:
Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity.
Years
Required/Preferred
Experience
3
Required
Experience triaging security alerts
3
Required
Experience analyzing security events
3
Required
Experience documenting incident investigations
3
Required
Experience with cybersecurity frameworks
3
Required
Experience with incident response processes
3
Required
Experience with threat detection methodologies
3
Required
Experience in cybersecurity operations
3
Required
Experience in security monitoring
3
Required
Experience in incident response
3
Required
Experience in threat detection
3
Required
Experience in security investigations
3
Required
Experience in related cybersecurity disciplines
5
Preferred
Please See Job Description Section for more specific Preferred and Required Skills.
 
 

Similar jobs