Network Security Analyst

ACS Consultancy Services

Austin (TX)

On-site

USD 100,000 - 150,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

ACS Consultancy Services in Austin, TX seeks a Network Security Analyst to monitor, analyze, and respond to cyber threats on enterprise networks.

The role requires hands-on experience with SIEM, EDR, cloud security, and incident response, plus strong collaboration with IT and security teams. Onsite work with potential after-hours support focused on safeguarding critical infrastructure and data. Candidates should understand NIST/ATT&CK and contribute to playbooks and vulnerability reviews.

Qualifications

  • Experience in cybersecurity operations, monitoring, incident response, threat detection, and investigations.
  • Knowledge of CSOC/SOC operations and incident triage processes.
  • Familiarity with MITRE ATT&CK, IOCs/IOAs, and common cyber threats.
  • Ability to document investigations and coordinate with multiple teams.

Responsibilities

  • Monitor, analyze, and triage cybersecurity alerts from SIEM, EDR, cloud security, and network security platforms.
  • Conduct initial investigations to determine severity, scope, and impact on operations.
  • Escalate threats to Incident Response teams according to procedures.
  • Correlate events from endpoints, networks, and cloud services; review IOCs/IOAs.
  • Document findings, assist with containment, eradication, and recovery efforts.
  • Support threat detection improvements, playbooks, and knowledge base updates.

Skills

Cybersecurity concepts
Threat triage
Incident analysis
Data correlation
Communication to diverse audiences
Team collaboration
Independent work

Education

Bachelor's degree in CS/IS/CYBER
Related field expected

Tools

SIEM
EDR/XDR
Threat intel
Vulnerability management tools
Firewalls/IDS/IPS

Job description

Job Title: Network Security Analyst

Location: Austin, TX (Onsite)( Local candidates only)

We are currently seeking candidates who meet the following qualifications:

Required Qualifications
  • Knowledge of commonly used concepts, practices, and procedures within cybersecurity and network security.
  • Ability to maintain the security and integrity of critical infrastructure systems by preventing unauthorized access and ensuring compliance with laws and regulations related to national security and foreign ownership restrictions.
  • Experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines.
  • Experience triaging security alerts, analyzing security events, and documenting incident investigations.
  • Experience with cybersecurity frameworks, incident response processes, and threat detection methodologies.
  • Experience working with one or more of the following technologies:
    • SIEM platforms such as NetWitness, Microsoft Sentinel, Splunk, QRadar, ArcSight, and LogRhythm.
    • Microsoft Security, including Microsoft 365 Defender XDR and Microsoft Sentinel.
    • Endpoint Detection and Response (EDR) solutions such as Microsoft Defender for Endpoint, CrowdStrike, and SentinelOne.
    • IDS/IPS technologies such as Trellix/FireEye and Corelight.
    • Threat intelligence platforms such as VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, and MISP.
    • Vulnerability management tools such as Tenable, Qualys, and Rapid7.
    • Email security platforms such as IronPort ESA, Abnormal.ai, and Proofpoint.
    • Cloud security monitoring solutions such as Google Wiz, MDCA, Cortex Cloud, and Sysdig.
    • Secure Access Service Edge (SASE) solutions such as Zscaler, Prisma, and Netskope.
  • Knowledge of Cybersecurity Operations Center (CSOC/SOC) operations and best practices.
  • Knowledge of security incident triage, analysis, investigation, and escalation procedures.
  • Knowledge of common cyber threats, attack vectors, malware, phishing campaigns, insider threats, and advanced persistent threat (APT) techniques.
  • Knowledge of threat intelligence concepts, indicators of compromise (IOCs), indicators of attack (IOAs), and MITRE ATT&CK methodologies.
  • Knowledge of Windows, Linux, networking protocols, Active Directory, Microsoft Entra ID, cloud environments, and enterprise security controls.
  • Knowledge of incident response lifecycle and cybersecurity frameworks such as NIST Cybersecurity Framework, NIST Incident Response guidance, and PICERL.
  • Skill in security event analysis and threat triage.
  • Skill in correlating and interpreting data from multiple cybersecurity tools.
  • Skill in investigating suspicious activity and identifying indicators of compromise.
  • Skill in using SIEM, EDR/XDR, threat intelligence, vulnerability management, and case management platforms.
  • Skill in producing clear documentation, incident reports, and technical communications.
  • Knowledge of and experience with query languages such as KQL, Lucene, SPL, and ESQL.
  • Knowledge of and experience with scripting languages such as PowerShell, Python, and Bash.
  • Ability to analyze complex security events and distinguish legitimate threats from false positives.
  • Ability to make risk-based decisions during incident investigations.
  • Ability to execute established incident response and escalation procedures.
  • Ability to collaborate effectively with security engineers, incident responders, system administrators, CISO leadership, and business stakeholders.
  • Ability to communicate technical information clearly to both technical and non-technical audiences.
  • Ability to work independently and as part of a 24x7 cybersecurity operations team.
  • Must be able to participate in incident response, escalation, and after-action review activities as needed.
  • Must be able to support enterprise security monitoring for systems that process, store, or transmit sensitive information.
  • Must follow HHSC policies, procedures, standards, and applicable state and federal security requirements.
  • Must maintain accurate operational documentation, investigation notes, metrics, and leadership-ready summaries.
  • Must be able to provide support outside of normal business hours during high-priority security incidents, as approved by the SOC Manager.
  • Candidates will be subject to a pre-employment security review to determine employment eligibility.
Preferred Qualifications
  • Graduation from an accredited four-year college or university with major coursework in:
    • Cybersecurity
    • Information Security
    • Computer Science
    • Computer Information Systems
    • Management Information Systems
    • Related field
  • Relevant education and experience may be substituted for one another.
  • One or more of the following certifications:
    • CompTIA Security+
    • GIAC Certified Incident Handler (GCIH)
    • GIAC Certified Intrusion Analyst (GCIA)
    • Certified SOC Analyst (CSA)
    • Microsoft Cybersecurity Analyst (SC-200)
    • Other GIAC or SOC-related certifications
Responsibilities
  • Monitor, analyze, and triage cybersecurity alerts generated by SIEM, EDR, cloud security, email security, identity protection, and network security platforms.
  • Conduct initial investigations of detected and reported security events to determine severity, scope, impact, and potential risk to agency operations.
  • Identify, validate, and prioritize potential cybersecurity incidents.
  • Escalate confirmed threats to Incident Response, Threat Hunting, or SOC Engineering teams according to established procedures.
  • Correlate security events from multiple data sources, including endpoints, EDR, firewalls, IDS, IPS, cloud services, authentication systems, and threat intelligence feeds.
  • Review and analyze indicators of compromise, suspicious network activity, phishing emails, malware detections, and anomalous user behavior.
  • Document investigations, findings, and response actions in ticketing and case management systems.
  • Assist with incident containment, eradication, and recovery efforts by coordinating with technical teams and stakeholders.
  • Report and escalation security incidents to the CSOC Team Lead and/or SOC Manager.
  • Support continuous improvement of threat detection capabilities through alert tuning, process refinement, threat intelligence integration, and identification of false-positive trends.
  • Perform vulnerability assessment reviews and evaluate identified vulnerabilities for potential risk and remediation prioritization.
  • Support the development and maintenance of operational procedures, playbooks, workflows, and knowledge base articles related to threat detection and incident response.
  • Research emerging cyber threats, attack techniques, tactics, and procedures (TTPs) to improve detection and response effectiveness.
  • Investigate security breaches and develop strategies to address security issues.Identify vulnerabilities in computer networks and provide recommendations to minimize those vulnerabilities.
  • Utilize firewalls, antivirus software, and other security technologies to maintain network and information system security.
  • Monitor network traffic and server logs for unusual or suspicious activity.
  • Protect agency information systems, networks, and data from cybersecurity threats.
  • Serve as a primary point of contact for security event analysis, threat identification, and incident escalation.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Network Security Analyst
Network Security Analyst

Intone Networks Inc • Town of Texas (WI)

On-site
USD 85,000 - 125,000
Network Security Analyst
Network Security Analyst

InnoSoul, Inc. • Austin (TX)

On-site
USD 95,000 - 130,000
Network Security Analyst 1
Network Security Analyst 1

My3tech • Austin (TX)

On-site
USD 60,000 - 90,000
Sr. Network Analyst
Sr. Network Analyst

MY HR • Austin (TX)

On-site
USD 110,000 - 150,000
Network Security Analyst 2
Network Security Analyst 2

Ampcus, Inc • Austin (TX)

On-site
USD 90,000 - 130,000
Network Security Analyst
Network Security Analyst

vTech Solution • Washington

On-site
USD 75,000 - 110,000
Network Security
Network Security

Akaasa Technologies • Austin (TX)

On-site
USD 90,000 - 140,000
Network Security Analyst
Network Security Analyst

Akaasa Technologies • Austin (TX)

On-site
USD 95,000 - 125,000
Network Security Analyst 2
Network Security Analyst 2

Intone Networks Inc • Town of Texas (WI)

On-site
USD 90,000 - 130,000
Senior Cybersecurity Analyst – Network Security #3369
Senior Cybersecurity Analyst – Network Security #3369

Genius Road, LLC • Austin (TX)

On-site
USD 120,000 - 180,000