Quick Overview
Job Description
ASSYST is seeking a Network Security Analyst for a State client in Austin, TX to support the cybersecurity operations, security monitoring, threat detection, and incident response activities for a client. The role will focus on monitoring and triaging security alerts, analyzing suspicious activity and security events, identifying potential threats, and supporting incident investigation and response activities.
The ideal candidate will have experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines, along with experience working with security monitoring and cybersecurity tools and frameworks.
Job Title: Network Security Analyst
Location: Austin, TX
Position is ONSITE at the location listed above (NO REMOTE WORK). Program will only accept LOCAL ONLY candidates for this position.
Roles & Responsibilities:
- Monitor, analyze, and triage cybersecurity alerts from security monitoring and detection platforms.
- Investigate security events and suspicious activity to determine severity, scope, impact, and potential risk.
- Identify, validate, and prioritize potential cybersecurity incidents and escalate confirmed threats as appropriate.
- Correlate security events from multiple sources, including endpoints, firewalls, IDS/IPS, cloud services, authentication systems, and threat intelligence feeds.
- Analyze indicators of compromise (IOCs), phishing activity, malware detections, suspicious network activity, and anomalous user behavior.
- Document security investigations, findings, and response actions in ticketing and case management systems.
- Support incident containment, eradication, and recovery activities.
- Perform vulnerability assessment reviews and support risk-based remediation prioritization.
- Assist with alert tuning, threat intelligence integration, detection improvements, and false-positive analysis.
- Support the development and maintenance of security procedures, playbooks, workflows, and knowledge base documentation.
- Research emerging cyber threats, attack techniques, tactics, and procedures (TTPs).
- Participate in incident response, escalation, and after-action review activities.
- Maintain accurate investigation documentation, metrics, and technical reports.
- Provide support outside normal business hours during high-priority security incidents as required.
Required Skills:
- Experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines.
- Experience triaging security alerts and analyzing security events.
- Experience documenting incident investigations and response activities.
- Experience with cybersecurity frameworks, incident response processes, and threat detection methodologies.
- Experience working with SIEM, EDR/XDR, IDS/IPS, firewalls, endpoint security, cloud security, and threat intelligence platforms.
- Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, or NetWitness.
- Experience with Microsoft Security / Microsoft 365 Defender XDR.
- Experience with EDR solutions such as Microsoft Defender for Endpoint, CrowdStrike, or SentinelOne.
- Knowledge of MITRE ATT&CK, IOCs, IOAs, malware, phishing, and common cyber threats.
- Experience with vulnerability management tools such as Tenable, Qualys, or Rapid7.
- Knowledge of Windows, Linux, networking protocols, Active Directory, Microsoft Entra ID, and cloud environments.
- Experience with query languages such as KQL, SPL, Lucene, or ESQL.
- Experience with scripting languages such as PowerShell, Python, or Bash.
- Knowledge of NIST Cybersecurity Framework, NIST Incident Response guidance, and PICERL.
- Strong analytical, investigative, documentation, communication, and problem-solving skills.
- Ability to distinguish legitimate threats from false positives and make risk-based decisions.
- Ability to work independently and collaboratively within a 24x7 cybersecurity operations environment.
Preferred Certifications: CompTIA Security+, GCIH, GCIA, Certified SOC Analyst (CSA), Microsoft SC-200, or other GIAC/SOC-related certifications.
ASSYST is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, disability, military status, national origin or any other characteristic protected under federal, state, or applicable local law.
Similar jobs
- JM
Lead Security Engineer - Threat Modeling
NewJ.P. Morgan
Plano, Texas🇺🇸On-site28 minutes agoGCPAWSMachine LearningTechnology - VE
Director of Security
NewVectra
San Jose🇺🇸YesterdaySOC 2ComplianceGDPR+2 - TI
Senior Security Operations Engineer
NewTines
United States (Remote)🇺🇸Remote4 hours agoDockerAWSAzure+6Technology - SS
Information Systems Security Officer (ISSO) with Security Clearance
NewSTEM Solutions & Consultants LLC
Tysons, VA🇺🇸Hybrid19 hours agoAWSAzureGCP+1Technology - 2C
Information Security Analyst 2 with Security Clearance
New22nd Century Technologies, Inc.
Carson City, NV🇺🇸Remote19 hours agoAWSPenetration TestingTechnology - IS
Information Systems Security Engineer (ISSE) with Security Clearance
INFORMATION SYSTEMS SOLUTIONS, INC
Suitland, MD🇺🇸$130k - $140k/yrOn-site3 days agoDockerMicroservicesAWS+5Technology