Security Operations / Detection Engineering analyst.

Socket.dev

Austin (TX)

On-site

USD 120,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

ASSYST is seeking an experienced Network Security Analyst II to support enterprise security operations across network, endpoint, cloud, and on-premises environments.

The candidate will monitor, detect, investigate, and respond to security events, with hands-on work in SIEM, SOAR, EDR/XDR, and NDR. Strong KQL/SPL skills and threat intelligence are required, along with collaboration with cross-functional teams for risk mitigation.

Qualifications

  • 7+ years in cybersecurity, network security, security operations, incident response, or related roles.
  • 7+ years with SIEM, SOAR, EDR, XDR, and NDR technologies.
  • Experience with security log collection and SIEM architecture support.
  • Threat intelligence and detection engineering experience.
  • Hands-on with Microsoft Sentinel analytics rules, workbooks, automation, data connectors, incident management, and KQL.
  • Experience with NDR and traffic analysis, endpoint investigation, and response actions.
  • Knowledge of firewall, IDS/IPS, DNS, VPN, TCP/IP, and secure network architecture.
  • Familiarity with NIST/CIS controls, HIPAA, and security requirements.
  • Strong analytical, communication, and documentation skills.
  • Bachelor’s degree preferred.

Responsibilities

  • Monitor and analyze security alerts, logs, traffic, and threat intel feeds.
  • Perform incident triage, investigation, escalation, containment, and documentation.
  • Investigate suspicious activity, malware indicators, and anomalous network behavior.
  • Develop and tune SIEM rules, alerts, dashboards, queries, and playbooks.
  • Conduct threat hunting using KQL, SPL, and telemetry.
  • Support vulnerability, risk, and security control assessments.
  • Analyze and correlate events across network, endpoints, identity, and cloud.
  • Coordinate with teams to validate incidents and implement risk mitigation.
  • Identify IOCs and attacker tactics, and prepare incident reports.

Skills

SIEM/SOAR/XDR
Threat hunting
KQL
Incident response
Network security
Endpoint security
Cloud security
Detection engineering
Malware analysis
TLS/IDS/IPS

Education

Bachelor’s degree in Cybersecurity or related field

Tools

Microsoft Sentinel
Splunk
EDR/XDR tools

Job description

Assyst is seeking an experienced Network Security Analyst II to support the client’s enterprise security operations. The role is responsible for monitoring, detecting, investigating, and responding to security events across network, endpoint, cloud, and on-premises environments.

The ideal candidate will have strong hands-on experience with SIEM, SOAR, EDR/XDR, NDR, threat intelligence, detection engineering, and incident response, with the ability to independently analyze complex security events and recommend appropriate mitigation actions.

Roles & Responsibilities:

  • Monitor and analyze security alerts, logs, network traffic, endpoint telemetry, and threat intelligence feeds.
  • Perform incident triage, investigation, escalation, containment, and documentation.
  • Investigate suspicious activity, malware indicators, anomalous network behavior, and security breaches.
  • Develop and tune SIEM detection rules, alerts, dashboards, queries, and playbooks.
  • Conduct threat hunting using KQL, SPL, packet/session analysis, and endpoint telemetry.
  • Support vulnerability, risk, and security control assessments.
  • Analyze and correlate security events across network, endpoint, identity, and cloud environments.
  • Work with network, infrastructure, cloud, endpoint, and application teams to validate incidents and implement risk mitigation.
  • Identify IOCs, attacker tactics, suspicious network patterns, and endpoint threats.
  • Prepare incident reports, investigation documentation, metrics, and security recommendations.
  • Support security compliance, audit, reporting, and after-action review activities.
  • Stay current with emerging threats, attack techniques, and security best practices.
  • Provide after-hours support for high-priority security incidents or planned maintenance when required.

Required Skills:

  • 7+ years of experience in cybersecurity, network security, security operations, incident response, or related information security roles.
  • 7+ years of experience with SIEM, SOAR, EDR, XDR, and NDR technologies.
  • Strong experience with security log collection and management and SIEM platform/architecture support.
  • Strong experience with threat intelligence and detection engineering methodologies.
  • Hands-on experience with Microsoft Sentinel, including analytics rules, workbooks, automation, data connectors, incident management, and KQL.
  • Strong ability to write and interpret KQL, SPL, and security queries for investigations and reporting.
  • Experience with NDR/network traffic analysis, packet/session investigation, and threat detection.
  • Experience with EDR alert triage, endpoint investigation, advanced hunting, and response actions.
  • Strong knowledge of firewalls, IDS/IPS, DNS, VPN, TCP/IP, proxy logs, network segmentation, and secure network architecture.
  • Knowledge of NIST, CIS Controls, HIPAA, and applicable information security requirements.
  • Strong analytical, problem-solving, communication, documentation, and incident-prioritization skills.
  • Ability to work independently in a fast-paced security operations environment.
  • 10+ years of relevant experience is preferred.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, IT, or a related field is preferred.

Preferred Certifications:Microsoft Security certifications, including Security Operations Analyst Associate, Cybersecurity Architect Expert, Azure Security Engineer Associate, or Microsoft 365 Defender certifications are preferred.

Additional preferred certifications include Security+, CySA+, GIAC, CISSP, CISM, CISA, Splunk certifications, and SentinelOne certifications.

ASSYST is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, disability, military status, national origin or any other characteristic protected under federal, state, or applicable local law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Operations & Detection Engineer
Senior Security Operations & Detection Engineer

Socket.dev • Austin (TX)

On-site
USD 120,000 - 150,000
SOC Analyst II / Cybersecurity Operations Analyst
SOC Analyst II / Cybersecurity Operations Analyst

Socket.dev • Austin (TX)

On-site
USD 80,000 - 120,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Network Security Analyst 2
Network Security Analyst 2

Ampcus, Inc • Austin (TX)

On-site
USD 90,000 - 130,000
Security Operations Analyst
Security Operations Analyst

NextGenEnergyJobs • Vienna (VA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Health benefits
401(k) and profit-sharing
Paid holidays
+1
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Senior SOC Analyst
Senior SOC Analyst

Allied Consultants, Inc. • Austin (TX)

On-site
USD 90,000 - 130,000
Medical insurance
Life insurance
401K match
+1
Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Cyber Security Analyst
Cyber Security Analyst

Request Technology, LLC • Chicago (IL)

Hybrid
USD 90,000 - 130,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000