Turn this role into an interview — a resume and cover letter built around what this employer wants.
COOLSOFT in Austin, TX is seeking a Network Security Analyst I to join our Cybersecurity Operations Center on-site at 701 W 51st Street, Austin, TX. You will monitor, triage, and analyze cybersecurity alerts and coordinate incident response to protect agency information systems, networks, and data.
The role requires 1-3 years of experience, knowledge of SIEM, EDR, and network security concepts, and the ability to work with cross-functional teams to minimize risk.
Cybersecurity Threat Detection Analyst
(Jobs in Austin, TX)
1-3 years of experience in the field or in a related area. Has knowledge of commonly used concepts, practices, and procedures within a particular field. Relies on instructions and pre-established guidelines to perform the functions of the job. Primary job functions do not typically require exercising independent judgment. Ability to maintain the security and integrity of critical infrastructure systems by preventing unauthorized access and ensuring compliance with laws and regulations related to national security and foreign ownership restrictions.
A network security analyst ensures that information systems and computer networks are secure. This includes protecting the company against hackers and cyber-attacks, as well as monitoring network traffic and server logs for activity that seems unusual. Additionally, these analysts are responsible for finding vulnerabilities in the computer networks and creating recommendations for how to minimize these vulnerabilities. The network security analyst investigates security breaches, develops strategies for any security issues that arise, and utilizes the help of firewalls and antivirus software to maintain security. DISCLAIMER: Candidates for this position will be subject to a pre-employment security review to determine employment eligibility.
The Network Security Analyst I performs advanced cybersecurity analysis and threat triage activities within the Cybersecurity Operations Center (CSOC). Work involves continuously monitoring, triaging, analyzing, and prioritizing cybersecurity alerts; investigating suspicious activity; identifying potential threats; and coordinating incident response activities to protect agency information systems, networks, and data. Serves as a primary point of contact for security event analysis, threat identification, and incident escalation.
Monitors, analyzes, and triages cybersecurity alerts generated by Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), cloud security, email security, identity protection, and network security platforms.
Conducts initial investigations of detected and reported security events to determine severity, scope, impact, and potential risk to agency operations.
Identifies, validates, and prioritizes potential cybersecurity incidents, escalating confirmed threats to Incident Response, Threat Hunting, or SOC Engineering teams according to established procedures.
Correlates security events from multiple data sources, including endpoints (EDR), firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), cloud services, authentication systems, and threat intelligence feeds.
Reviews and analyzes indicators of compromise (IOCs), suspicious network activity, phishing emails, malware detections, and anomalous user behavior.
Documents investigations, findings, and response actions in ticketing and case management systems to ensure accurate tracking and reporting.
Assists with incident containment, eradication, and recovery efforts by coordinating with technical teams and stakeholders.
Reports and escalates to the CSOC Team Lead and/or SOC Manager.
Supports the continuous improvement of threat detection capabilities through alert tuning, process refinement, threat
EOE Protected Veterans/Disability