AI Jobs Map

InstantServe LLC · Austin, Texas Metropolitan Area

Network Security Engineer

seniorcontractPosted 2 days ago
Apply on LinkedInLinkedInOpens the original posting. AI Jobs Map never asks for your details.

Stack mentioned

cybersecuritysiemhipaaazurecisspsplunknetwork-securitythreat-intelligenceincident-response

We are seeking an experienced Network Security Analyst II to support enterprise cybersecurity and security operations. The selected professional will monitor, detect, investigate, and respond to security events across network, endpoint, identity, cloud, and on-premises environments.

The ideal candidate will have strong hands-on experience with Microsoft Sentinel, SIEM, SOAR, EDR, XDR, NDR, threat intelligence, detection engineering, incident response, and security-query languages such as KQL and SPL.

Key Responsibilities

- Monitor security alerts, server and network logs, endpoint telemetry, threat-intelligence feeds, and security events.

- Investigate suspicious activity, malware indicators, anomalous network behavior, endpoint detections, and SIEM correlation events.

- Determine the scope, impact, severity, and appropriate response to cybersecurity incidents.

- Perform incident triage, investigation, escalation, containment coordination, and documentation.

- Develop, tune, and maintain SIEM detection rules, alerts, dashboards, workbooks, queries, automation, and response playbooks.

- Support threat-hunting activities using KQL, SPL, packet and session analysis, endpoint telemetry, and other investigative techniques.

- Analyze network traffic using NDR tools to identify threats and support incident investigations.

- Perform endpoint alert triage, device investigations, advanced hunting, and response actions using EDR tools.

- Support vulnerability, risk, and control assessments for network infrastructure and enterprise information systems.

- Identify indicators of compromise, suspicious network patterns, attacker tactics, and endpoint-based threats.

- Prepare incident reports, document findings, track corrective actions, and communicate recommendations.

- Collaborate with network, infrastructure, cloud, endpoint, identity, and application teams to validate events and mitigate risks.

- Support compliance, audit, and security-reporting activities by providing evidence, metrics, and operational documentation.

- Maintain awareness of emerging threats, attack techniques, and cybersecurity best practices relevant to healthcare and public-sector environments.

- Participate in incident-response escalation and after-action review activities.

Required Qualifications

- At least seven years of experience in cybersecurity, network security, security operations, incident response, or a closely related information-security role.

- Seven years of experience with SIEM, SOAR, EDR, XDR, and NDR technologies.

- Seven years of experience with security-log collection, management, analysis, and monitoring.

- Seven years of experience applying threat-intelligence concepts.

- Seven years of experience writing and interpreting KQL, SPL, or similar security queries.

- Seven years of experience supporting SIEM platforms and architecture.

- Seven years of experience with detection-engineering methodologies and implementation.

- Hands-on Microsoft Sentinel experience, including:

- Incident management

- Analytics rules

- Workbooks and dashboards

- Automation

- Data connectors

- Kusto Query Language

- Experience using SIEM platforms for log analysis, alert investigation, correlation searches, security monitoring, and reporting.

- Experience with NDR tools for network-traffic analysis, packet or session investigation, threat detection, and incident support.

- Experience with EDR tools for endpoint-alert triage, advanced hunting, device investigation, and response.

- Strong knowledge of firewalls, IDS/IPS, proxy logs, DNS, VPN, TCP/IP, network segmentation, and secure network architecture.

- Ability to correlate complex security data across multiple sources and produce clear findings and recommendations.

- Familiarity with NIST, CIS Controls, HIPAA, and applicable state information-security requirements.

- Strong analytical, problem-solving, communication, and collaboration skills.

Preferred Qualifications

- Ten or more years of experience with:

- SIEM, SOAR, EDR, XDR, and NDR

- Security-log collection and management

- Threat intelligence

- KQL, SPL, and security-query development

- SIEM platform and architecture support

- Detection-engineering methodology and implementation

- Bachelor’s degree in cybersecurity, computer science, information systems, information technology, or a related discipline. Relevant experience may be considered in place of education.

- Previous cybersecurity experience in healthcare, government, or another regulated environment.

Preferred Certifications

Microsoft security certifications are strongly preferred, including:

- Microsoft Certified: Security Operations Analyst Associate

- Microsoft Certified: Cybersecurity Architect Expert

- Microsoft Certified: Azure Security Engineer Associate

- Microsoft 365 Defender-related certifications

Additional preferred certifications include:

- CISSP

- CISM

- CISA

- CompTIA Security+

- CompTIA CySA+

- GIAC security certifications

- Splunk Core Certified Power User

- Splunk Enterprise Security Certified Admin

- SentinelOne product certifications

More jobs at InstantServe LLC