Network Security

Akaasa Technologies

Austin (TX)

On-site

USD 90,000 - 140,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

The Network Security Analyst II at HHSC is responsible for advanced cybersecurity and network security analysis, monitoring, detection, investigation, and response across on‑premises, cloud, and endpoint environments. You will bring hands-on experience with SIEM, SOAR, EDR, and incident response to protect Texans’ data and services.

Ideal candidates have strong technical depth, collaboration skills, and the ability to translate complex findings into actionable guidance for leadership and

Qualifications

  • Minimum of seven years of experience in cybersecurity, network security, security operations, incident response, or a closely related information security role.
  • Hands-on experience with Microsoft Sentinel, including incident management, analytics rules, workbooks, automation, data connectors, and Kusto Query Language.
  • Experience using SIEM for log analysis, alert investigation, dashboarding, correlation searches, and security monitoring.
  • Experience with NDR for network traffic analysis, packet/session investigation, threat detection, and incident support.
  • Experience with EDR tools, including endpoint alert triage, device investigation, advanced hunting, and response actions.
  • Working knowledge of network security concepts, including firewalls, IDS/IPS, proxy logs, DNS, VPN, TCP/IP, segmentation, and secure network architecture.
  • Ability to analyze complex security events, correlate data across multiple sources, and produce clear written documentation and recommendations.
  • Knowledge of security frameworks, standards, and regulatory considerations such as NIST, CIS Controls, HIPAA, and state information security requirements.
  • Strong communication, collaboration, problem-solving, and analytical skills.

Responsibilities

  • Monitor security alerts, logs, network events, endpoint telemetry, and threat intelligence feeds.
  • Analyze suspicious activity, anomalous network behavior, malware indicators, endpoint detections, and SIEM correlation events to determine scope, impact, and required response actions.
  • Perform incident triage, investigation, escalation, containment coordination, and documentation in alignment with HHSC security operations procedures.
  • Develop, tune, and maintain detection rules, dashboards, alerts, playbooks, and queries to improve visibility across network, endpoint, identity, and cloud environments.
  • Support threat hunting activities using KQL, SPL, packet/session analysis, endpoint telemetry, and other investigative techniques.
  • Assist with vulnerability, risk, and control assessments for network security infrastructure and enterprise information systems.
  • Document findings, prepare incident reports, track corrective actions, and communicate technical information to security leadership and business stakeholders.
  • Collaborate with network, infrastructure, cloud, endpoint, and application teams to validate security events and implement risk mitigation measures.
  • Maintain awareness of emerging cyber threats, attack techniques, indicators of compromise, and security best practices relevant to healthcare and public-sector environments.
  • Support compliance, audit, and reporting activities by providing evidence, metrics, and security operations documentation as requested.

Skills

SIEM
SOAR
EDR
XDR
NDR
Threat intel
KQL/SPL
Security logs
SIEM architecture
Detection engineering

Education

Bachelor's degree
Security certifications

Tools

Microsoft Sentinel
KQL
SPL
Data connectors

Job description

Most visas are fine just no OPT

Job Description
MUST HAVE
  • 7 Years Required Knowledge of SIEM, SOAR, EDR, XDR, NDR
  • 7 Years Required Experience with security log collection and management
  • 7 Years Required Experience with threat intelligence concepts
  • 7 Years Required Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting
  • 7 Years Required Experience in SIEM platform/architecture support
  • 7 Years Required Experience in detection engineering methodology and implementation
PREFERRED
  • 10 Years Preferred Knowledge of SIEM, SOAR, EDR, XDR, NDR
  • 10 Years Preferred Experience with security log collection and management
  • 10 Years Preferred Experience with threat intelligence concepts
  • 10 Years Preferred Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting
  • 10 Years Preferred Experience in SIEM platform/architecture support
  • 10 Years Preferred Experience in detection engineering methodology and implementation

Familiar with standard concepts, practices, and procedures within a particular field. Relies on limited experience and judgment to plan and accomplish goals. A certain degree of creativity and latitude is required. Works under limited supervision with considerable latitude for the use of initiative and independent judgement. Ability to maintain the security and integrity of critical infrastructure systems by preventing unauthorized access and ensuring compliance with laws and regulations related to national security and foreign ownership restrictions. A network security analyst ensures that information systems and computer networks are secure. This includes protecting the company against hackers and cyber-attacks, as well as monitoring network traffic and server logs for activity that seems unusual. Additionally, these analysts are responsible for finding vulnerabilities in the computer networks and creating recommendations for how to minimize these vulnerabilities. The network security analyst investigates security breaches, develops strategies for any security issues that arise, and utilizes the help of firewalls and antivirus software to maintain security. DISCLAIMER: Candidates for this position will be subject to a pre-employment security review to determine employment eligibility.

Job Summary

The Network Security Analyst II performs advanced cybersecurity and network security analysis work in support of HHSC's enterprise security operations. This role is responsible for monitoring, detecting, investigating, and responding to security events across on-premises, cloud, and endpoint environments. The ideal candidate is a hands-on security operations professional with strong experience across SIEM, SOAR, EDR, network detection, and incident response platforms. This role requires sound judgment, technical depth, attention to detail, and a strong commitment to protecting HHSC systems, data, and services that support the health and well-being of Texans.

Essential Job Functions
  • Monitor security alerts, logs, network events, endpoint telemetry, and threat intelligence feeds.
  • Analyze suspicious activity, anomalous network behavior, malware indicators, endpoint detections, and SIEM correlation events to determine scope, impact, and required response actions.
  • Perform incident triage, investigation, escalation, containment coordination, and documentation in alignment with HHSC security operations procedures.
  • Develop, tune, and maintain detection rules, dashboards, alerts, playbooks, and queries to improve visibility across network, endpoint, identity, and cloud environments.
  • Support threat hunting activities using KQL, SPL, packet/session analysis, endpoint telemetry, and other investigative techniques.
  • Assist with vulnerability, risk, and control assessments for network security infrastructure and enterprise information systems.
  • Document findings, prepare incident reports, track corrective actions, and communicate technical information to security leadership and business stakeholders.
  • Collaborate with network, infrastructure, cloud, endpoint, and application teams to validate security events and implement risk mitigation measures.
  • Maintain awareness of emerging cyber threats, attack techniques, indicators of compromise, and security best practices relevant to healthcare and public-sector environments.
  • Support compliance, audit, and reporting activities by providing evidence, metrics, and security operations documentation as requested.
Required Qualifications
  • Minimum of seven years of experience in cybersecurity, network security, security operations, incident response, or a closely related information security role.
  • Hands-on experience with Microsoft Sentinel, including incident management, analytics rules, workbooks, automation, data connectors, and Kusto Query Language.
  • Experience using SIEM for log analysis, alert investigation, dashboarding, correlation searches, and security monitoring.
  • Experience with NDR for network traffic analysis, packet/session investigation, threat detection, and incident support.
  • Experience with EDR tools, including endpoint alert triage, device investigation, advanced hunting, and response actions.
  • Working knowledge of network security concepts, including firewalls, IDS/IPS, proxy logs, DNS, VPN, TCP/IP, segmentation, and secure network architecture.
  • Ability to analyze complex security events, correlate data across multiple sources, and produce clear written documentation and recommendations.
  • Knowledge of security frameworks, standard, and regulatory considerations such as NIST, CIS Controls, HIPAA, and state information security requirements.
  • Strong communication, collaboration, problem-solving, and analytical skills.
Preferred Education and Certifications
  • Bachelor's degree in cybersecurity, computer science, information systems, information technology, or a related field. Relevant experience may be considered in place of education where applicable.
  • Microsoft security certifications are strongly preferred, such as Microsoft Certified: Security Operations Analyst Associate, Microsoft Certified: Cybersecurity Architect Expert, Microsoft Certified: Azure Security Engineer Associate, or Microsoft 365 Defender-related certifications.
  • Additional preferred certifications include CompTIA Security+, CySA+, GIAC security certifications, CISSP, CISM, CISA, Splunk Core Certified Power User, Splunk Enterprise Security Certified Admin, or SentinelOne product certifications.
KNOWLEDGE, SKILLS, AND ABILITIES
  • Knowledge of SIEM, SOAR, EDR, XDR, network detection and response, log management, and threat intelligence concepts.
  • Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting.
  • Skill in identifying indicators of compromise, attacker tactics, suspicious network patterns, and endpoint-based threats.
  • Ability to prioritize alerts, document investigative steps, and escape incidents based on severity and business impact.
  • Ability to work independently and collaboratively in a security operations environment with shifting priorities and time-sensitive incidents.
  • Ability to communicate cybersecurity risks, findings, and recommended actions to both technical and non-technical audiences.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Security Analyst 2
Network Security Analyst 2

Digerati Systems Inc. • Austin (TX)

On-site
USD 110,000 - 165,000
Network Security Analyst 2
Network Security Analyst 2

Ampcus, Inc • Austin (TX)

On-site
USD 90,000 - 130,000
Sr. Network Analyst
Sr. Network Analyst

MY HR • Austin (TX)

On-site
USD 110,000 - 150,000
Network Security Analyst
Network Security Analyst

My3Tech • Austin (TX)

On-site
USD 90,000 - 120,000
Senior Network Security Analyst – SIEM & Threat Hunting
Senior Network Security Analyst – SIEM & Threat Hunting

Akaasa Technologies • Austin (TX)

On-site
USD 90,000 - 140,000
Cybersecurity Operations Center Analyst
Cybersecurity Operations Center Analyst

FALL CREEK FARM & NURSERY • Austin (TX)

On-site
USD 78,000 - 132,000
Full health insurance
Defined benefit pension
Generous leave
Security Analyst
Security Analyst

Novalink Solutions LLC • West Columbia (TX)

On-site
USD 70,000 - 95,000
Cybersecurity Operations Center Engineer
Cybersecurity Operations Center Engineer

FALL CREEK FARM & NURSERY • Austin (TX)

On-site
USD 78,000 - 132,000
100% paid employee health insurance
Defined benefit pension
Generous time off benefits
Cybersecurity Operations Center Engineer
Cybersecurity Operations Center Engineer

Texas Health and Human Services • Austin (TX)

On-site
USD 78,000 - 132,000
Health insurance
Pension plan
Time off
+1
Network Security Analyst
Network Security Analyst

Tech Army, LLC • Columbia (SC)

On-site
USD 70,000 - 110,000