Quick Overview
Job Description
Assyst is seeking an experienced Network Security Analyst II to support the client’s enterprise security operations. The role is responsible for monitoring, detecting, investigating, and responding to security events across network, endpoint, cloud, and on-premises environments.
The ideal candidate will have strong hands-on experience with SIEM, SOAR, EDR/XDR, NDR, threat intelligence, detection engineering, and incident response, with the ability to independently analyze complex security events and recommend appropriate mitigation actions.
Roles & Responsibilities:
- Monitor and analyze security alerts, logs, network traffic, endpoint telemetry, and threat intelligence feeds.
- Perform incident triage, investigation, escalation, containment, and documentation.
- Investigate suspicious activity, malware indicators, anomalous network behavior, and security breaches.
- Develop and tune SIEM detection rules, alerts, dashboards, queries, and playbooks.
- Conduct threat hunting using KQL, SPL, packet/session analysis, and endpoint telemetry.
- Support vulnerability, risk, and security control assessments.
- Analyze and correlate security events across network, endpoint, identity, and cloud environments.
- Work with network, infrastructure, cloud, endpoint, and application teams to validate incidents and implement risk mitigation.
- Identify IOCs, attacker tactics, suspicious network patterns, and endpoint threats.
- Prepare incident reports, investigation documentation, metrics, and security recommendations.
- Support security compliance, audit, reporting, and after-action review activities.
- Stay current with emerging threats, attack techniques, and security best practices.
- Provide after-hours support for high-priority security incidents or planned maintenance when required.
Required Skills:
- 7+ years of experience in cybersecurity, network security, security operations, incident response, or related information security roles.
- 7+ years of experience with SIEM, SOAR, EDR, XDR, and NDR technologies.
- Strong experience with security log collection and management and SIEM platform/architecture support.
- Strong experience with threat intelligence and detection engineering methodologies.
- Hands-on experience with Microsoft Sentinel, including analytics rules, workbooks, automation, data connectors, incident management, and KQL.
- Strong ability to write and interpret KQL, SPL, and security queries for investigations and reporting.
- Experience with NDR/network traffic analysis, packet/session investigation, and threat detection.
- Experience with EDR alert triage, endpoint investigation, advanced hunting, and response actions.
- Strong knowledge of firewalls, IDS/IPS, DNS, VPN, TCP/IP, proxy logs, network segmentation, and secure network architecture.
- Knowledge of NIST, CIS Controls, HIPAA, and applicable information security requirements.
- Strong analytical, problem-solving, communication, documentation, and incident-prioritization skills.
- Ability to work independently in a fast-paced security operations environment.
- 10+ years of relevant experience is preferred.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, IT, or a related field is preferred.
Preferred Certifications:
Microsoft Security certifications, including Security Operations Analyst Associate, Cybersecurity Architect Expert, Azure Security Engineer Associate, or Microsoft 365 Defender certifications are preferred.
Additional preferred certifications include Security+, CySA+, GIAC, CISSP, CISM, CISA, Splunk certifications, and SentinelOne certifications.
ASSYST is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, disability, military status, national origin or any other characteristic protected under federal, state, or applicable local law.
Similar jobs
- AD
Security Hardware Engineer, Infrastructure Security - Security Products and Solutions
NewAmazon Data Services, Inc.
Herndon, Virginia🇺🇸Hybrid13 minutes agoAWSTechnology - ZS
Threat Response Engineer (TRE) - Day Shift (10am-6pm MT)
NewZscaler
USA - Update Location🇺🇸10 hours agoAgileArticulateMental Health+2Engineering - TA
Senior Security Engineer, Customer Transparency
NewTanium
Remote🇺🇸$191k - $293k/yrRemote12 hours agoEncryptionGitTriageTechnology - ID
Senior Threat Intelligence Analyst
NewID.me
McLean🇺🇸10 hours agoSQLPythonTechnology - FL
Staff Security Engineer, Application Security
NewFomo Labs
New York City🇺🇸11 hours agoGCPAWSOWASP+4Technology - CL
Security Engineer
NewClera
San Francisco🇺🇸14 hours agoAWSSOC 2Compliance+1Technology