Haystack
← Back to Jobs
Technology
PR

Security Operations Centre (SCO) Analyst - W2 - Only TX candidates

Promantis IncAustin, TX🇺🇸United StatesPosted Sep 29, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Austin, TX, United States
Posted
19 hours ago

Job Description

Role Overview

Client is integrating its DSHS applications into Google SecOps (SIEM/SOAR). We need a hands-on security operations analyst to support that project by monitoring, investigating, and responding to security events across network, endpoint, identity, and cloud environments. You'll protect systems and data that support the health and well-being of Texans.

Key Responsibilities

  • Monitor alerts, logs, network events, endpoint telemetry, and threat intelligence feeds
  • Triage and investigate suspicious activity; determine scope and impact and lead escalation and containment coordination
  • Build and tune detection rules, dashboards, alerts, playbooks, and automation workflows
  • Conduct threat hunting using KQL, SPL, packet/session analysis, and endpoint telemetry
  • Support vulnerability, risk, and control assessments
  • Write incident reports, track corrective actions, and brief security leadership and business stakeholders
  • Work with network, infrastructure, cloud, and application teams to validate events and reduce risk
  • Provide evidence and metrics for compliance and audit requests
  • Be available occasionally outside business hours for high-priority incidents or planned maintenance

Required Qualifications

  • 7+ years in cybersecurity, network security, security operations, or incident response
  • Hands-on Microsoft Sentinel experience (incident management, analytics rules, workbooks, automation, data connectors, KQL)
  • SIEM experience: log analysis, alert investigation, correlation searches, dashboarding
  • Experience with NDR (network traffic and packet/session analysis) and EDR (alert triage, device investigation, advanced hunting, response actions)
  • Solid understanding of firewalls, IDS/IPS, proxy logs, DNS, VPN, TCP/IP, and network segmentation
  • Familiarity with NIST, CIS Controls, HIPAA, and state information security requirements
  • Strong analytical, written, and verbal communication skills, with the ability to explain risk to technical and non-technical audiences
  • Google SecOps or Wiz experience

Preferred Qualifications

  • Bachelor's degree in cybersecurity, computer science, IT, or a related field (relevant experience may substitute)
  • Google SecOps or Wiz certification
  • Microsoft certifications (e.g., SC-200, AZ-500, SC-100)
  • Other certifications: Security+, CySA+, GIAC, CISSP, CISM, CISA, Splunk Core Certified Power User or ES Admin, SentinelOne
  • Splunk (SPL) experience
  • Experience mentoring junior analysts
  • Healthcare or public-sector background

Similar jobs