Quick Overview
Job Description
Job Title: Network Security Analyst (Onsite)
Location: Austin, TX
Duration: 11 Months with possible extension
Job Description:
The Network Security Analyst I performs advanced cybersecurity analysis and threat triage activities within the Cybersecurity Operations Center. Work involves continuously monitoring, triaging, analyzing, and prioritizing cybersecurity alerts; investigating suspicious activity; identifying potential threats; and coordinating incident response activities to protect agency information systems, networks, and data. Serves as a primary point of contact for security event analysis, threat identification, and incident escalation.
Essential Job Functions:
- Monitors, analyzes, and triages cybersecurity alerts generated by Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), cloud security, email security, identity protection, and network security platforms.
- Conducts initial investigations of detected and reported security events to determine severity, scope, impact, and potential risk to agency operations.
- Identifies, validates, and prioritizes potential cybersecurity incidents, escalating confirmed threats to Incident Response, Threat Hunting, or SOC Engineering teams according to established procedures.
- Correlates security events from multiple data sources, including endpoints (EDR), firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), cloud services, authentication systems, and threat intelligence feeds.
- Reviews and analyzes indicators of compromise (IOCs), suspicious network activity, phishing emails, malware detections, and anomalous user behavior.
- Documents investigations, findings, and response actions in ticketing and case management systems to ensure accurate tracking and reporting.
- Assists with incident containment, eradication, and recovery efforts by coordinating with technical teams and stakeholders.
- Reports and escalates to the CSOC Team Lead and/or SOC Manager.
- Supports the continuous improvement of threat detection capabilities through alert tuning, process refinement, threat intelligence integration, and identification of false-positive trends.
- Performs vulnerability assessment reviews and evaluates identified vulnerabilities for potential risk and remediation prioritization.
- Supports development and maintenance of operational procedures, playbooks, workflows, and knowledge base articles related to threat detection and incident response.
- Researches emerging cyber threats, attack techniques, tactics, and procedures (TTPs) to improve detection and response effectiveness.
Knowledge, Skills, and Abilities:
Knowledge of:
- Cybersecurity Operations Center (CSOC/SOC) operations and best practices.
- Security incident triage, analysis, investigation, and escalation procedures.
- Security monitoring technologies, including SIEM, EDR/XDR, IDS/IPS, firewalls, endpoint security solutions, and cloud security platforms.
- Common cyber threats, attack vectors, malware, phishing campaigns, insider threats, and advanced persistent threat (APT) techniques.
- Threat intelligence concepts, indicators of compromise (IOCs), indicators of attack (IOAs), and MITRE ATT&CK methodologies.
- Windows, Linux, networking protocols, Active Directory, Microsoft Entra ID, cloud environments, and enterprise security controls.
- Incident response lifecycle and cybersecurity frameworks such as NIST Cybersecurity Framework, NIST Incident Response guidance, and PICERL.
Skill in:
- Security event analysis and threat triage.
- Correlating and interpreting data from multiple cybersecurity tools.
- Investigating suspicious activity and identifying indicators of compromise.
- Using SIEM, EDR/XDR, threat intelligence, vulnerability management, and case management platforms.
- Producing clear documentation, incident reports, and technical communications.
- Prioritizing and managing multiple investigations in a fast-paced operational environment for a large organization.
- Knowledge of and experience with query languages such as KQL, Lucene, SPL, ESQL, etc.
- Knowledge of and experience with scripting languages such as PowerShell, Python, Bash, etc.
Ability to:
- Analyze complex security events and distinguish legitimate threats from false positives.
- Make risk-based decisions during incident investigations.
- Execute established incident response and escalation procedures.
- Collaborate effectively with security engineers, incident responders, system administrators, CISO leadership, and business stakeholders.
- Communicate technical information clearly to both technical and non-technical audiences.
- Work independently and as part of a 24x7 cybersecurity operations team.
Preferred Education and Certifications:
- Graduation from an accredited four-year college or university with major coursework in cybersecurity, information security, computer science, computer information systems, management information systems, or a related field is preferred. Relevant education and experience may be substituted for one another.
- One or more of the following certifications are preferred:
- CompTIA Security+
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Intrusion Analyst (GCIA)
- Certified SOC Analyst (CSA)
- Microsoft Cybersecurity Analyst (SC-200)
- Other GIAC or SOC-related certifications
Required Qualifications:
- Minimum of five (5) years of experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines.
- Experience working with one or more of the following technologies: SIEM platforms (NetWitness, Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, etc.)
- Microsoft Security (Microsoft 365 Defender XDR, Microsoft Sentinel)
- Endpoint Detection and Response (Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, etc.)
- IDS/IPS technologies (Trellix/FireEye, Corelight)
- Threat intelligence platforms (VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, MISP)
- Vulnerability management tools (Tenable, Qualys, Rapid7)
- Email security platforms (IronPort ESA, Abnormal.ai, Proofpoint)
- Cloud security monitoring solutions (Google Wiz, MDCA, Cortex Cloud, Sysdig)
- Secure Access Service Edge (Zscaler, Prisma, Netskope)
- Experience triaging security alerts, analyzing security events, and documenting incident investigations.
- Experience with cybersecurity frameworks, incident response processes, and threat detection methodologies.
Work Expectations:
- Participate in incident response, escalation, and after-action review activities as needed.
- Support enterprise security monitoring for systems that process, store, or transmit sensitive information.
- Follow the Client policies, procedures, standards, and applicable state and federal security requirements.
- Maintain accurate operational documentation, investigation notes, metrics, and leadership-ready summaries.
- Must be able to provide support outside of normal business hours during high-priority security incidents, as approved by the SOC Manager.
Similar jobs
- RD
Software Security Engineer
NewRandstad Digital
New York, NY🇺🇸$48 - $86/hrRemoteYesterdayOWASPTechnology - GO
Cyber Security Analyst
NewGovCIO
United States🇺🇸$143.2k - $160k/yrOn-site2 days agoEncryptionTechnology - EN
Information Systems Security Manager (ISSM) with Security Clearance
NewEntarian
Colorado Springs, CO🇺🇸$130k - $180k/yrOn-siteYesterdayTechnology - TO
network Security analyst
NewTOPSYSIT
Austin, TX🇺🇸On-siteYesterdayPythonPowerShellBash+3Technology - PG
Network Security Analyst
NewPROLIM Global Corporation
Austin, TX🇺🇸HybridYesterdayPythonPowerShellBash+2Technology - EN
Security Engineer - Zscaler with Security Clearance
NewEntarian
Arlington, VA🇺🇸HybridYesterdayJiraVMwareTechnology