Network Security Analyst – Level 1

Jobtailor

Austin (TX)

On-site

USD 95,000 - 130,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Jobtailor in Austin, TX is seeking a cybersecurity analyst to perform advanced analysis and threat triage within the CSOC. You will monitor alerts from SIEM, EDR, cloud, and identity tools; investigate incidents; and collaborate with IR and SOC teams to support containment and remediation.

Ideal candidates have 3+ years of experience, strong knowledge of NIST frameworks, and proven ability to produce concise reports. The role may require on-site work in Austin and occasional after-hours coverage.

Qualifications

  • 3+ years of experience triaging security alerts and investigating incidents.
  • Experience with SIEM/XDR platforms and incident response.
  • Strong knowledge of NIST frameworks and CSOC processes.
  • Ability to produce clear, concise reports and summaries.
  • Must reside in the Austin area; capable of working on-site as needed.

Responsibilities

  • Perform advanced cybersecurity analysis and threat triage in the CSOC.
  • Monitor and triage alerts from SIEM, EDR, cloud, and identity platforms.
  • Investigate alerts to assess severity, scope, and risk.
  • Coordinate with Incident Response and SOC teams for containment and recovery.
  • Correlate events from firewalls, IDS/IPS, and threat intel feeds.
  • Document investigations and findings in ticketing systems.
  • Assist containment, eradication, and recovery efforts with stakeholders.
  • Improve threat detection via alert tuning and threat intel integration.
  • Produce high-quality investigation summaries for CSOC leadership.
  • Report activities to CSOC leadership and guidance to peers.

Skills

Incident response
Threat triage
Security analysis
Documentation
Communication
Independent work

Education

Bachelor’s degree in Cybersecurity or related field
Equivalent experience accepted

Tools

NetWitness
Microsoft Sentinel
Splunk
QRadar
ArcSight
Tenable
Qualys
Proofpoint
CrowdStrike
Microsoft Defender for Endpoint
Zscaler
Cisco Talos
Google Threat Intelligence

Job description

  • Perform advanced cybersecurity analysis and threat triage within the Cybersecurity Operations Center (CSOC)
  • Continuously monitor, analyze, and triage alerts from SIEM, EDR, cloud security, email security, identity protection, and network security platforms
  • Investigate cybersecurity alerts to assess severity, scope, impact, and operational risk
  • Identify, validate, prioritize, and escrow confirmed incidents to Incident Response, Threat Hunting, and SOC Engineering teams
  • Correlate events from firewalls, IDS/IPS, cloud services, authentication systems, and threat intelligence feeds
  • Analyze IOCs, IOAs, suspicious network activity, malware, phishing emails, and anomalous user behavior
  • Document investigations, findings, incidents, and response activities in ticketing and case management systems
  • Assist with incident containment, eradication, and recovery by coordinating mitigations with technical teams and stakeholders
  • Improve threat detection through alert tuning, incident response process refinement, and threat intelligence integration
  • Research cybersecurity technologies, attack vectors, and evolving TTPs
  • Conduct vulnerability assessments and evaluate remediation efforts
  • Collaborate with internal teams, communicate findings to CISO leadership, and report activities to CSOC leadership
  • Ensure compliance with internal policies and state and federal cybersecurity regulations
  • Perform other duties as assigned
Requirements
  • Minimum three (3) years of experience triaging security alerts, analyzing cybersecurity events, documenting findings and incident response actions, utilizing cybersecurity frameworks, managing incident response and threat detection activities, and conducting security investigations
  • Strong technical expertise with SIEM platforms such as NetWitness, Microsoft Sentinel, Splunk, QRadar, ArcSight, or LogRhythm
  • Experience with Microsoft 365 Defender XDR and Microsoft Sentinel
  • Experience with EDR tools such as Microsoft Defender for Endpoint, CrowdStrike, or SentinelOne
  • Experience with IDS/IPS technologies such as Trellix/FireEye or Corelight
  • Experience with threat intelligence platforms such as VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, or MISP
  • Experience with vulnerability management tools such as Tenable, Qualys, or Rapid7
  • Experience with email security tools such as IronPort ESA, Abnormal.ai, or Proofpoint
  • Experience with cloud security monitoring tools such as Google Wiz, MDCA, Cortex Cloud, or Sysdig
  • Experience with SASE tools such as Zscaler, Prisma, or Netskope
  • Knowledge of CSOC/SOC processes and best practices
  • Knowledge of incident response lifecycle and cybersecurity frameworks, including NIST Cybersecurity Framework and NIST Incident Response Guidance (PICERL)
  • Knowledge of SIEM, EDR/XDR, IDS/IPS, firewalls, common cyber threats, threat intelligence, Windows/Linux, networking protocols, and enterprise security controls
  • Skilled in analyzing and triaging cybersecurity incidents and threats
  • Skilled in investigating suspicious activities, including IOCs, IOAs, suspicious emails, and network anomalies
  • Skilled in query languages such as KQL, Lucene, SPL, or ESQL
  • Skilled in scripting and automation using PowerShell, Python, or Bash
  • Ability to produce high-quality reports and investigation summaries
  • Exceptional interpersonal, verbal, and written communication skills
  • Excellent organizational, analytical, problem-solving, multitasking, and attention-to-detail skills
  • Ability to work independently and on a multifunctional team
  • Ability to handle sensitive and confidential information appropriately
  • Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Management Information Systems, or a related field is preferred; equivalent experience may substitute
  • Relevant certification preferred, such as CompTIA Security+, GCIH, GCIA, CSA, Microsoft SC-200, or other GIAC/SOC-specific certifications
  • Must reside in the Austin area
  • Must be physically and mentally able to perform duties for extended periods
  • Ability to use computers and office productivity tools effectively
  • Must be able to establish a productive and professional workspace
  • Must be able to sit for long periods while looking at a computer screen
  • May be asked to work flexible schedules, including holidays, and outside normal business hours
  • May be asked to travel for business or professional development purposes
Core Competencies

Demonstrates expertise in advanced cybersecurity analysis, incident response, and threat detection, utilizing a variety of security tools and frameworks. Proficient in documenting findings and collaborating with teams to enhance security posture and compliance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Security Analyst
Network Security Analyst

ArnAmy, Inc. • Austin (TX)

On-site
USD 85,000 - 120,000
Network Security Analyst
Network Security Analyst

Allied Consultants, Inc. • Austin (TX)

On-site
USD 90,000 - 130,000
Medical insurance
Life insurance
401(K) plan with company match
+2
Network Security Analyst 1769
Network Security Analyst 1769

Sistema Technologies Inc. • Austin (TX)

On-site
USD 120,000 - 180,000
Senior Advanced Cyber Security Architect
Senior Advanced Cyber Security Architect

Jobtailor • Duluth (GA)

On-site
USD 120,000 - 160,000
SOC/Cybersecurity Analyst
SOC/Cybersecurity Analyst

Air InfoSec • Austin (TX), Northern (KY)

Hybrid
USD 95,000 - 135,000
Network Security Analyst 0056A
Network Security Analyst 0056A

Sistema Technologies Inc. • San Antonio (TX)

On-site
USD 90,000 - 140,000
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000
SOC Analyst 2
SOC Analyst 2

Mbi Llc • Harrisburg

On-site
USD 60,000 - 90,000
Network Security Analyst 2
Network Security Analyst 2

Ampcus, Inc • Austin (TX)

On-site
USD 90,000 - 130,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000