Haystack
← Back to Jobs
Technology
SE

Network Security Analyst (Onsite)

SerigorAustin, TX🇺🇸United StatesPosted 10 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Austin, TX, United States
Posted
Yesterday
PythonPowerShellBashPrismaSplunkActive Directory

Job Description

Job Title: Network Security Analyst  (Onsite)

Location: Austin, TX

Duration: 11 Months with possible extension

 

Job Description:

The Network Security Analyst I performs advanced cybersecurity analysis and threat triage activities within the Cybersecurity Operations Center. Work involves continuously monitoring, triaging, analyzing, and prioritizing cybersecurity alerts; investigating suspicious activity; identifying potential threats; and coordinating incident response activities to protect agency information systems, networks, and data. Serves as a primary point of contact for security event analysis, threat identification, and incident escalation. 

 

Essential Job Functions:

  • Monitors, analyzes, and triages cybersecurity alerts generated by Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), cloud security, email security, identity protection, and network security platforms. 
  • Conducts initial investigations of detected and reported security events to determine severity, scope, impact, and potential risk to agency operations. 
  • Identifies, validates, and prioritizes potential cybersecurity incidents, escalating confirmed threats to Incident Response, Threat Hunting, or SOC Engineering teams according to established procedures. 
  • Correlates security events from multiple data sources, including endpoints (EDR), firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), cloud services, authentication systems, and threat intelligence feeds. 
  • Reviews and analyzes indicators of compromise (IOCs), suspicious network activity, phishing emails, malware detections, and anomalous user behavior. 
  • Documents investigations, findings, and response actions in ticketing and case management systems to ensure accurate tracking and reporting. 
  • Assists with incident containment, eradication, and recovery efforts by coordinating with technical teams and stakeholders. 
  • Reports and escalates to the CSOC Team Lead and/or SOC Manager. 
  • Supports the continuous improvement of threat detection capabilities through alert tuning, process refinement, threat intelligence integration, and identification of false-positive trends. 
  • Performs vulnerability assessment reviews and evaluates identified vulnerabilities for potential risk and remediation prioritization. 
  • Supports development and maintenance of operational procedures, playbooks, workflows, and knowledge base articles related to threat detection and incident response. 
  • Researches emerging cyber threats, attack techniques, tactics, and procedures (TTPs) to improve detection and response effectiveness. 

 

Knowledge, Skills, and Abilities:

 

Knowledge of: 

  • Cybersecurity Operations Center (CSOC/SOC) operations and best practices. 
  • Security incident triage, analysis, investigation, and escalation procedures. 
  • Security monitoring technologies, including SIEM, EDR/XDR, IDS/IPS, firewalls, endpoint security solutions, and cloud security platforms. 
  • Common cyber threats, attack vectors, malware, phishing campaigns, insider threats, and advanced persistent threat (APT) techniques. 
  • Threat intelligence concepts, indicators of compromise (IOCs), indicators of attack (IOAs), and MITRE ATT&CK methodologies. 
  • Windows, Linux, networking protocols, Active Directory, Microsoft Entra ID, cloud environments, and enterprise security controls. 
  • Incident response lifecycle and cybersecurity frameworks such as NIST Cybersecurity Framework, NIST Incident Response guidance, and PICERL. 

 

Skill in: 

  • Security event analysis and threat triage. 
  • Correlating and interpreting data from multiple cybersecurity tools. 
  • Investigating suspicious activity and identifying indicators of compromise. 
  • Using SIEM, EDR/XDR, threat intelligence, vulnerability management, and case management platforms. 
  • Producing clear documentation, incident reports, and technical communications. 
  • Prioritizing and managing multiple investigations in a fast-paced operational environment for a large organization. 
  • Knowledge of and experience with query languages such as KQL, Lucene, SPL, ESQL, etc. 
  • Knowledge of and experience with scripting languages such as PowerShell, Python, Bash, etc. 

 

Ability to: 

  • Analyze complex security events and distinguish legitimate threats from false positives. 
  • Make risk-based decisions during incident investigations. 
  • Execute established incident response and escalation procedures. 
  • Collaborate effectively with security engineers, incident responders, system administrators, CISO leadership, and business stakeholders. 
  • Communicate technical information clearly to both technical and non-technical audiences. 
  • Work independently and as part of a 24x7 cybersecurity operations team. 

 

Preferred Education and Certifications:

  • Graduation from an accredited four-year college or university with major coursework in cybersecurity, information security, computer science, computer information systems, management information systems, or a related field is preferred. Relevant education and experience may be substituted for one another. 
  • One or more of the following certifications are preferred: 
    • CompTIA Security+ 
    • GIAC Certified Incident Handler (GCIH) 
    • GIAC Certified Intrusion Analyst (GCIA) 
    • Certified SOC Analyst (CSA) 
    • Microsoft Cybersecurity Analyst (SC-200) 
    • Other GIAC or SOC-related certifications 

 

Required Qualifications:

  • Minimum of five (5) years of experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines. 
  • Experience working with one or more of the following technologies: SIEM platforms (NetWitness, Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, etc.) 
  • Microsoft Security (Microsoft 365 Defender XDR, Microsoft Sentinel) 
  • Endpoint Detection and Response (Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, etc.) 
  • IDS/IPS technologies (Trellix/FireEye, Corelight) 
  • Threat intelligence platforms (VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, MISP) 
  • Vulnerability management tools (Tenable, Qualys, Rapid7) 
  • Email security platforms (IronPort ESA, Abnormal.ai, Proofpoint) 
  • Cloud security monitoring solutions (Google Wiz, MDCA, Cortex Cloud, Sysdig) 
  • Secure Access Service Edge (Zscaler, Prisma, Netskope) 
  • Experience triaging security alerts, analyzing security events, and documenting incident investigations. 
  • Experience with cybersecurity frameworks, incident response processes, and threat detection methodologies. 

 

Work Expectations:

  • Participate in incident response, escalation, and after-action review activities as needed. 
  • Support enterprise security monitoring for systems that process, store, or transmit sensitive information. 
  • Follow the Client policies, procedures, standards, and applicable state and federal security requirements. 
  • Maintain accurate operational documentation, investigation notes, metrics, and leadership-ready summaries. 
  • Must be able to provide support outside of normal business hours during high-priority security incidents, as approved by the SOC Manager. 

 

 

Similar jobs