Job Description
Job Description
Network Security Analyst (SOC Operations, SIEM & Incident Response):Required Experience in Years:10+ Years
Mode of Work: 100% Onsite Austin, TX Metropolitan Area Locals Only
The Network Security Analyst will perform advanced cybersecurity monitoring, threat analysis, security-event triage, and incident investigation within a Cybersecurity Operations Center (CSOC). The analyst will continuously monitor security alerts, investigate suspicious activities, identify potential threats, distinguish legitimate incidents from false positives, and coordinate incident-response activities.
The position requires strong SOC operations expertise across SIEM, EDR/XDR, network security, cloud security, identity protection, email security, vulnerability management, and threat-intelligence technologies.
Key Responsibilities:
-
Continuously monitor, triage, analyze, and prioritize cybersecurity alerts.
-
Investigate suspicious network, endpoint, cloud, email, and user activity.
-
Determine incident severity, scope, impact, and risk.
-
Validate potential security incidents and distinguish threats from false positives.
-
Escalate confirmed threats to Incident Response, Threat Hunting, or SOC Engineering teams.
-
Correlate security events across:
-
Endpoints
-
Firewalls
-
IDS/IPS
-
Cloud Services
-
Authentication Systems
-
Threat Intelligence Feeds
-
-
Analyze Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
-
Investigate phishing emails, malware detections, suspicious network traffic, and anomalous user behavior.
-
Document investigations, findings, and response activities in case-management systems.
-
Assist with containment, eradication, and recovery activities.
-
Escalate critical findings to SOC/CSOC leadership.
Additional Responsibilities:
-
Tune security alerts and improve threat-detection capabilities.
-
Identify and reduce false-positive trends.
-
Integrate threat intelligence into SOC monitoring and investigations.
-
Review vulnerability-assessment results and remediation priorities.
-
Maintain incident-response procedures, playbooks, workflows, and knowledge-base documentation.
-
Research emerging cyber threats, attack techniques, and TTPs.
-
Support 24x7 cybersecurity operations when required.
-
Participate in high-priority incident response outside normal business hours.
-
Communicate security findings to technical and non-technical stakeholders.
Required Skills:
-
Minimum 5+ years of overall experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines.
-
Minimum 3+ years of security alert triage experience.
-
Minimum 3+ years analyzing cybersecurity events.
-
Minimum 3+ years documenting security incident investigations.
-
Minimum 3+ years working with cybersecurity frameworks.
-
Minimum 3+ years with incident-response processes.
-
Minimum 3+ years with threat-detection methodologies.
-
Minimum 3+ years in cybersecurity/SOC operations.
-
Minimum 3+ years of security-monitoring experience.
-
Minimum 3+ years of incident-response experience.
-
Minimum 3+ years of threat-detection experience.
-
Minimum 3+ years conducting security investigations.
-
Strong understanding of SIEM, EDR/XDR, IDS/IPS, firewalls, endpoint security, and cloud-security platforms.
-
Strong understanding of malware, phishing, insider threats, and APTs.
-
Knowledge of MITRE ATT&CK methodologies.
-
Knowledge of IOCs, IOAs, and threat intelligence.
-
Knowledge of the incident-response lifecycle, NIST Cybersecurity Framework, NIST Incident Response guidance, and PICERL.
-
Understanding of Windows, Linux, Active Directory, Microsoft Entra ID, and networking protocols.
-
Experience correlating data across multiple cybersecurity platforms.
-
Experience with query languages including KQL, SPL, Lucene, and ESQL.
-
Experience with scripting languages including PowerShell, Python, and Bash.
Preferred Skills:
-
SIEM platforms:
-
Microsoft Sentinel
-
Splunk
-
NetWitness
-
QRadar
-
ArcSight
-
LogRhythm
-
-
EDR/XDR:
-
Microsoft 365 Defender XDR
-
Microsoft Defender for Endpoint
-
CrowdStrike
-
SentinelOne
-
-
IDS/IPS:
-
Trellix / FireEye
-
Corelight
-
-
Threat Intelligence:
-
VirusTotal
-
Google Threat Intelligence
-
Cisco Talos
-
Recorded Future
-
MISP
-
-
Vulnerability Management:
-
Tenable
-
Qualys
-
Rapid7
-
-
Email Security:
-
IronPort ESA
-
Abnormal.ai
-
Proofpoint
-
-
Cloud Security:
-
Wiz
-
Microsoft Defender for Cloud Apps (MDCA)
-
Cortex Cloud
-
Sysdig
-
-
SASE:
-
Zscaler
-
Prisma
-
Netskope
-
-
Experience operating within a 24x7 SOC/CSOC environment.
Qualifications:
-
Must currently reside in the Austin metropolitan area.
-
Must be willing to work 100% onsite in Austin, TX.
-
Strong analytical and cybersecurity investigation capabilities.
-
Ability to distinguish genuine threats from false positives.
-
Strong risk-based decision-making skills.
-
Ability to follow incident-response and escalation procedures.
-
Ability to work independently and within a 24x7 cybersecurity team.
-
Strong written and verbal communication skills.
-
Ability to communicate with security engineers, incident responders, system administrators, leadership, and business stakeholders.
-
Must be available for occasional evening, weekend, and holiday support during critical security incidents.
Education:
-
Four-year degree in Cybersecurity, Information Security, Computer Science, Computer Information Systems, Management Information Systems, or related field Preferred.
-
Relevant education and professional experience may substitute where permitted.
Certifications:
-
CompTIA Security+ Preferred
-
GIAC Certified Incident Handler (GCIH) Preferred
-
GIAC Certified Intrusion Analyst (GCIA) Preferred
-
Certified SOC Analyst (CSA) Preferred
-
Microsoft Certified: Security Operations Analyst Associate (SC-200) Preferred
-
Other GIAC/SOC-related cybersecurity certifications Preferred
