AI Jobs Map

BuzzClan · Austin, TX

Network Security Analyst

seniorcontractPosted 3 days ago
Apply on LinkedInLinkedInOpens the original posting. AI Jobs Map never asks for your details.

Stack mentioned

network-securitycybersecurityincident-responsesiemthreat-intelligencevulnerability-managementlinuxidentity-and-access-managementpowershellpythonbashsplunkcrowdstrike

The Network Security Analyst I performs advanced cybersecurity analysis and threat triage activities within the Cybersecurity Operations Center (CSOC). Work involves continuously monitoring, triaging, analyzing, and prioritizing cybersecurity alerts; investigating suspicious activity; identifying potential threats; and coordinating incident response activities to protect agency information systems, networks, and data. Serves as a primary point of contact for security event analysis, threat identification, and incident escalation.

Essential Job Functions

• Monitors, analyzes, and triages cybersecurity alerts generated by Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), cloud security, email security, identity protection, and network security platforms.

• Conducts initial investigations of detected and reported security events to determine severity, scope, impact, and potential risk to agency operations.

• Identifies, validates, and prioritizes potential cybersecurity incidents, escalating confirmed threats to Incident Response, Threat Hunting, or SOC Engineering teams according to established procedures.

• Correlates security events from multiple data sources, including endpoints (EDR), firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), cloud services, authentication systems, and threat intelligence feeds.

• Reviews and analyzes indicators of compromise (IOCs), suspicious network activity, phishing emails, malware detections, and anomalous user behavior.

• Documents investigations, findings, and response actions in ticketing and case management systems to ensure accurate tracking and reporting.

• Assists with incident containment, eradication, and recovery efforts by coordinating with technical teams and stakeholders.

• Reports and escalates to the CSOC Team Lead and/or SOC Manager.

• Supports the continuous improvement of threat detection capabilities through alert tuning, process refinement, threat intelligence integration, and identification of false-positive trends.

• Performs vulnerability assessment reviews and evaluates identified vulnerabilities for potential risk and remediation prioritization.

• Supports development and maintenance of operational procedures, playbooks, workflows, and knowledge base articles related to threat detection and incident response.

• Researches emerging cyber threats, attack techniques, tactics, and procedures (TTPs) to improve detection and response effectiveness.

Knowledge, Skills, and Abilities

Knowledge of:

• Cybersecurity Operations Center (CSOC/SOC) operations and best practices.

• Security incident triage, analysis, investigation, and escalation procedures.

• Security monitoring technologies, including SIEM, EDR/XDR, IDS/IPS, firewalls, endpoint security solutions, and cloud security platforms.

• Common cyber threats, attack vectors, malware, phishing campaigns, insider threats, and advanced persistent threat (APT) techniques.

• Threat intelligence concepts, indicators of compromise (IOCs), indicators of attack (IOAs), and MITRE ATT&CK methodologies.

• Windows, Linux, networking protocols, Active Directory, Microsoft Entra ID, cloud environments, and enterprise security controls.

• Incident response lifecycle and cybersecurity frameworks such as NIST Cybersecurity Framework, NIST Incident Response guidance, and PICERL.

Skill in:

• Security event analysis and threat triage.

• Correlating and interpreting data from multiple cybersecurity tools.

• Investigating suspicious activity and identifying indicators of compromise.

• Using SIEM, EDR/XDR, threat intelligence, vulnerability management, and case management platforms.

• Producing clear documentation, incident reports, and technical communications.

• Prioritizing and managing multiple investigations in a fast-paced operational environment for a large organization.

• Knowledge of and experience with query languages such as KQL, Lucene, SPL, ESQL, etc.

• Knowledge of and experience with scripting languages such as PowerShell, Python, Bash, etc.

Ability to:

• Analyze complex security events and distinguish legitimate threats from false positives.

• Make risk-based decisions during incident investigations.

• Execute established incident response and escalation procedures.

• Collaborate effectively with security engineers, incident responders, system administrators, CISO leadership, and business stakeholders.

• Communicate technical information clearly to both technical and non-technical audiences.

• Work independently and as part of a 24x7 cybersecurity operations team.

Preferred Education and Certifications

• Graduation from an accredited four-year college or university with major coursework in cybersecurity, information security, computer science, computer information systems, management information systems, or a related field is preferred. Relevant education and experience may be substituted for one another.

• One or more of the following certifications are preferred:

• CompTIA Security+

• GIAC Certified Incident Handler (GCIH)

• GIAC Certified Intrusion Analyst (GCIA)

• Certified SOC Analyst (CSA)

• Microsoft Cybersecurity Analyst (SC-200)

• Other GIAC or SOC-related certifications

Required Qualifications

• Minimum of five (5) years of experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines.

• Experience working with one or more of the following technologies:

• SIEM platforms (NetWitness, Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, etc.)

• Microsoft Security (Microsoft 365 Defender XDR, Microsoft Sentinel)

• Endpoint Detection and Response (Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, etc.)

• IDS/IPS technologies (Trellix/FireEye, Corelight)

• Threat intelligence platforms (VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, MISP)

• Vulnerability management tools (Tenable, Qualys, Rapid7)

• Email security platforms (IronPort ESA, Abnormal.ai, Proofpoint)

• Cloud security monitoring solutions (Google Wiz, MDCA, Cortex Cloud, Sysdig)

• Secure Access Service Edge (Zscaler, Prisma, Netskope)

• Experience triaging security alerts, analyzing security events, and documenting incident investigations.

• Experience with cybersecurity frameworks, incident response processes, and threat detection methodologies.

Work Expectations

• Participate in incident response, escalation, and after-action review activities as needed.

• Support enterprise security monitoring for systems that process, store, or transmit sensitive information.

• Follow HHSC policies, procedures, standards, and applicable state and federal security requirements.

• Maintain accurate operational documentation, investigation notes, metrics, and leadership-ready summaries.

• Must be able to provide support outside of normal business hours during high-priority security incidents, as approved by the SOC Manager.

More jobs at BuzzClan

Similar roles in Austin