openqareer

Network Security Analyst

Smart Tech Skills LLC · Austin, TX 78751

# Network Security Analyst **Smart Tech Skills LLC** · Austin, TX 78751 · `On-site` 🕒 **Статус:** *Опубликовано: вчера* · *Источник: Indeed* --- ### About the Role Benefits: Competitive salary Location Onsite in Austin, TX. Experience Level Entry–Mid Level (3–5+ years of experience). Role Overview We are seeking a Network Security Analyst to perform cybersecurity analysis and threat triage within a Cybersecurity Operations Center (CSOC). This role involves continuously monitoring, investigating, and prioritizing security alerts, identifying potential threats, and coordinating incident response activities to protect information systems, networks, and data. The analyst serves as a key point of contact for security event analysis, threat identification, and incident escalation within a 24x7 operations environment. Key Responsibilities Security Monitoring & Alert Triage Monitor, analyze, and triage cybersecurity alerts generated by SIEM, EDR, cloud security, email security, identity protection, and network security platforms. Conduct initial investigations of detected and reported security events to determine severity, scope, impact, and potential risk. Identify, validate, and prioritize potential cybersecurity incidents, escalating confirmed threats according to established procedures. Correlate security events from multiple data sources, including endpoints, firewalls, IDS/IPS, cloud services, authentication systems, and threat intelligence feeds. Threat Investigation & Incident Response Review and analyze indicators of compromise (IOCs), suspicious network activity, phishing emails, malware detections, and anomalous user behavior. Assist with incident containment, eradication, and recovery efforts by coordinating with technical teams and stakeholders. Report and escalate findings to CSOC/SOC leadership as needed. Perform vulnerability assessment reviews and evaluate identified vulnerabilities for risk and remediation prioritization. Documentation & Process Improvement Document investigations, findings, and response actions in ticketing and case management systems to ensure accurate tracking and reporting. Support continuous improvement of threat detection capabilities through alert tuning, process refinement, and identification of false-positive trends. Support development and maintenance of operational procedures, playbooks, workflows, and knowledge base articles. Threat Research & Collaboration Research emerging cyber threats, attack techniques, tactics, and procedures (TTPs) to improve detection and response effectiveness. Collaborate with security engineers, incident responders, system administrators, and business stakeholders. Communicate technical findings clearly to both technical and non-technical audiences. Required Qualifications 3+ years of experience in cybersecurity operations, security monitoring, incident response, threat detection, or security investigations. Experience triaging security alerts and analyzing security events. Experience documenting incident investigations. Experience with cybersecurity frameworks, incident response processes, and threat detection methodologies. Experience with one or more SIEM platforms (e.g., Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, NetWitness). Experience with Endpoint Detection and Response tools (e.g., Microsoft Defender for Endpoint, CrowdStrike, SentinelOne). Experience with IDS/IPS technologies, threat intelligence platforms, vulnerability management tools, email security platforms, cloud security monitoring, or SASE solutions. Knowledge of CSOC/SOC operations, security incident triage, and escalation procedures. Knowledge of common cyber threats, attack vectors, malware, phishing, and advanced persistent threats (APTs). Knowledge of Windows, Linux, networking protocols, Active Directory, Microsoft Entra ID, cloud environments, and enterprise security controls. Knowledge of incident response lifecycle and frameworks such as NIST Cybersecurity Framework and PICERL. Ability to analyze complex security events and distinguish legitimate threats from false positives. Ability to work independently and as part of a 24x7 cybersecurity operations team. Preferred Qualifications Bachelor's degree in cybersecurity, information security, computer science, or a related field (relevant experience may substitute). One or more relevant certifications, such as CompTIA Security+, GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), Certified SOC Analyst (CSA), or Microsoft Cybersecurity Analyst (SC-200). Experience with query languages such as KQL, Lucene, SPL, or ESQL. Experience with scripting languages such as PowerShell, Python, or Bash. 5+ years of experience across the required technical areas listed above. Core Skills & Attributes Strong analytical and investigative mindset with sound risk-based decision-making. Ability to prioritize and manage multiple investigations in a fast-paced operational environment. Clear written and verbal communication skills across technical and non-technical audiences. Collaborative team player comfortable working within a 24x7 operations model. Detail-oriented with strong documentation discipline. Adaptable and able to support incident response outside normal business hours when needed.

Наблюдалась 2026-09-15, впервые 2026-09-14, источник — Indeed.

Открыть у работодателя