Job Summary:
The Network Security Analyst I is responsible for performing advanced cybersecurity analysis and threat triage within a Cybersecurity Operations Center (CSOC). This role involves continuous monitoring, investigation, and prioritization of cybersecurity alerts to protect organizational information systems, networks, and data. The analyst serves as a key point of contact for security event analysis, threat identification, and incident escalation, ensuring timely and effective incident response.
Responsibilities:
- Monitor, analyze, and triage cybersecurity alerts from SIEM, EDR, cloud security, email security, identity protection, and network security platforms.
- Conduct initial investigations of security events to assess severity, scope, impact, and risk.
- Identify, validate, and prioritize cybersecurity incidents, escalating confirmed threats as required.
- Correlate security events across multiple data sources including endpoints, firewalls, IDS/IPS, cloud services, and threat intelligence feeds.
- Review indicators of compromise, suspicious network activity, phishing attempts, malware detections, and anomalous user behavior.
- Document investigations, findings, and response actions in ticketing and case management systems.
- Assist with incident containment, eradication, and recovery by coordinating with technical teams and stakeholders.
- Report and elevate incidents to CSOC Team Lead and SOC Manager.
- Support continuous improvement of threat detection through alert tuning, process refinement, and threat intelligence integration.
- Perform vulnerability assessments and evaluate remediation priorities.
- Develop and maintain operational procedures, playbooks, workflows, and knowledge base articles.
- Research emerging cyber threats and tactics to enhance detection and response capabilities.
Required Skills & Certifications:
- Minimum five (5) years of experience in cybersecurity operations, security monitoring, incident response, threat detection, or related disciplines.
- Experience with SIEM platforms (e.g., NetWitness, Microsoft Sentinel, Splunk, QRadar).
- Experience with Endpoint Detection and Response tools (e.g., Microsoft Defender for Endpoint, CrowdStrike).
- Knowledge of IDS/IPS technologies, threat intelligence platforms, vulnerability management, email security, and cloud security monitoring.
- Proficiency in security event triage, analysis, incident documentation, and cybersecurity frameworks.
- Familiarity with incident response processes and threat detection methodologies.
- Skill in using query languages (KQL, Lucene, SPL, ESQL) and scripting languages (PowerShell, Python, Bash).
- Ability to analyze complex security events, make risk-based decisions, and execute incident response procedures.
- Strong communication skills for technical and non-technical audiences.
- Pre-employment security review clearance required.
Preferred Skills & Certifications:
- Bachelor's degree in cybersecurity, information security, computer science, or related field preferred.
- Certifications such as CompTIA Security+, GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), Certified SOC Analyst (CSA), or Microsoft Cybersecurity Analyst (SC-200).
- Experience with Microsoft Security solutions including Microsoft 365 Defender XDR and Microsoft Sentinel.
- Additional GIAC or SOC-related certifications.
Special Considerations:
- Must comply with all applicable state and federal security policies and procedures.
- May be required to provide support outside normal business hours during high-priority security incidents.
- Work involves handling sensitive information and requires strict adherence to security protocols.
Scheduling:
- Position operates within a 24x7 cybersecurity operations environment.
- Shift patterns may include nights, weekends, and holidays as required to support incident response and monitoring.