Senior Analyst, Information Security

Phase2 Technology

Austin (TX)

On-site

USD 120,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
401(k) plan
Paid time off
Fertility benefits
Commuter benefits
Student loan assistance
Firm holidays

Job summary

Norton Rose Fulbright US LLP is seeking a Senior Information Security Analyst to join its global Security Operations team. The role focuses on 24x7 monitoring, detection and response, threat hunting and analytics to strengthen threat detection and incident response across endpoints, cloud, email and identity systems.

The Senior Analyst will lead investigations, improve detection capabilities, and mentor junior staff while collaborating with regional IT teams and adhering to NIST incident

Qualifications

  • Technical bachelor's degree in IT / Information Security or equivalent experience
  • 5+ years in security operations or related infrastructure
  • Proven ability to adapt to emerging threats and information
  • Expertise with Microsoft 365 Defender and Microsoft Sentinel for detection and response
  • Strong knowledge of core security technologies (firewalls, IDS/IPS, EDR, SIEM) and incident-response (NIST)
  • Working knowledge of EDR, DLP, removable-media encryption; cloud-based security (Zscaler, Mimecast, Proofpoint, Cisco)
  • Experience with ServiceNow or similar service management tools

Responsibilities

  • Operate and manage security incidents and requests to SLA guidelines
  • Monitor, triage and investigate alerts across endpoints, cloud, identity, email and network telemetry
  • Lead structured incident response aligned to a recognized lifecycle
  • Triage and remediate phishing, vishing and impersonation attacks
  • Configure and tune security parameters in monitoring systems
  • Conduct proactive threat hunting and maintain detection rules (Sigma/KQL) and MITRE ATT&CK mappings
  • Develop and maintain SOAR playbooks to automate response
  • Use AI-assisted detection tooling and validate AI findings
  • Mentor junior analysts and own SOC processes
  • Maintain SOC playbooks, runbooks, and monitoring configuration

Skills

Microsoft 365 Defender
Microsoft Sentinel
Firewalls
IDS/IPS
EDR
SIEM
NIST
Active Directory
Entra ID / Azure AD
PowerShell
Python
SOAR
Sigma / KQL
Threat hunting
Cloud platforms (Azure/AWS/GCP)

Education

Technical bachelor’s degree in IT / Information Security
Security certifications (e.g., CISSP, GIAC GSOC, GCIH, AZ-500)

Tools

Microsoft 365 Defender
Microsoft Sentinel
ZT/Zscaler
Mimecast
Proofpoint
Cisco security solutions
ServiceNow

Job description

Job Description

At Norton Rose Fulbright, people thrive because of a shared commitment to quality, unity and integrity. The highly regarded law firm consistently receives recognition from Great Place to Work and Top Workplaces, two companies that specialize in assessing organizational culture. Teams collaborate across regions, value new ideas and deliver meaningful client solutions, supported by a culture that embraces ambition, development and shared success. With more than 3,000 lawyers and 3,000 business services professionals working together across 50 offices worldwide, this global law firm provides a full range of legal services to leading corporations and financial institutions operating in key markets and sectors.

The Senior Information Security Analyst is one of several senior analyst roles within the Firm's global Security Operations (SOC) team. Each Senior Analyst provides technical leadership in the SOC's day-to-day monitoring, detection and response activities, hunts for emerging adversary activity, and continuously improves the Firm's ability to detect and respond to threats at speed.

The role is part of a worldwide team empowered to operate the activities within its assigned function. daily activities focus on security monitoring, event and incident triage, incident response, request management, detection engineering and proactive threat hunting, with direction provided by the Information Security Manager.

Key responsibilities include, but are not limited to:
Security Monitoring, Detection & Response
  • Operate and manage security incidents and requests to SLA guidelines, acting as an intermediate escalation point for complex investigations.
  • Monitor, triage and investigate alerts across endpoints, cloud, identity, email and network telemetry, reviewing and escalating unusual event behavior.
  • Lead structured incident response aligned to a recognized lifecycle, including containment, eradication, recovery, evidence preservation and digital forensic analysis as authorized.
  • Triage and remediate phishing, vishing and impersonation attacks in a timely and efficient manner as the risk dictates.
  • Configure and tune appropriate security parameters in monitoring systems and act as a technical point of escalation for alerted issues.
Detection Engineering & Threat Hunting
  • Conduct proactive, hypothesis-driven threat hunting on a scheduled basis to identify adversary activity not surfaced by existing detections.
  • Design, test, tune and maintain detection rules and use cases (e.g. Sigma / KQL), and map detection coverage to the MITRE ATT&CK framework to identify and close detection gaps.
  • Maintain technical awareness of adversary tradecraft, emerging attack techniques and threat intelligence relevant to the legal sector, translating these into new or improved detections.
  • Automation & AI-Enabled Operations
  • Develop and maintain security automation and orchestration (SOAR) playbooks to streamline incident response and automate repetitive operational tasks.
  • Use AI-assisted detection, triage and investigation tooling effectively, and critically validate, tune and quality-assure AI-generated findings and recommendations
Governance, Improvement & Leadership
  • Act as a technical mentor for junior and peer analysts, supporting skills development and succession planning within the region.
  • Take ownership of one or more SOC processes, functions or technologies globally, ensuring their continued maintenance and improvement.
  • Assist with development and maintenance of SOC playbooks, runbooks, monitoring configuration and standard operating procedures, identifying improvements and reporting on incidents
Required experience and skills:
  • Technical bachelor's degree or equivalent IT / Information Security experience (required).
  • At least 5 years' experience working within security operations or Information Security infrastructure, or a strong vocation and demonstrable transferable experience from another technical discipline.
  • Proven ability to adapt quickly to emerging threats or new information, shifting focus as needed.
  • Demonstrated expertise in Microsoft 365 Defender and Microsoft Sentinel for detecting, investigating and responding to suspicious and anomalous activity.
  • Strong knowledge of core security technologies (firewalls, IDS/IPS, EDR, SIEM) and of structured incident-response methodologies (e.g. NIST).
  • Working knowledge of endpoint security and monitoring infrastructure (EDR, DLP, removable-media encryption) and of cloud-based web and email security solutions (e.g. Zscaler, Mimecast, Proofpoint, Cisco).
  • Ability to triage and remediate phishing and impersonation attacks in a timely and efficient manner as the risk dictates.
  • Experience working with a service management tool (e.g. ServiceNow).

In addition to the core foundation above, the Senior Analyst must bring demonstrable, in-depth expertise in at least one of the following domains, with solid working knowledge across the remainder:

  • Identity & Access - deep experience detecting and responding to identity-based attacks across Active Directory and Entra ID / Azure AD, including conditional access, privileged access, authentication protocols and identity threat detection and response (ITDR).
  • Cloud Security - deep experience monitoring and responding to threats across a major cloud platform (Azure, AWS or GCP), including cloud logging and telemetry, posture signals, and cloud-native detection and response.
  • Windows & Linux Operating Systems - deep host-level investigation and forensic capability across both Windows and Linux, including event log and audit analysis, process and memory investigation, and OS hardening.
  • Security Automation & Detection Engineering - advanced scripting (PowerShell and/or Python) and SOAR playbook development, and/or detection engineering (Sigma / KQL) to automate response and expand detection coverage at scale.
Preferred Certifications

One or more of the following certifications are preferred:

  • Security Operations / SIEM: Microsoft SC-200 (Security Operations Analyst), GIAC GSOC
  • Incident Handling & Response: GIAC GCIH, Blue Team Level 1 (BTL1)
  • Specialist Technical Certifications: AZ-500 (Azure Security Engineer), SC-300 (Microsoft Identity and Access Administrator), GCFA (GIAC Certified Forensic Analyst), GCFE (GIAC Certified Forensic Examiner), GIAC GPYC (Python Coder)
  • Foundational / Broad Security Certifications: CompTIA Security+, GIAC GSEC, CISSP, CCSP
The Team:

The Security Operations (SOC) team is a dedicated sub-team of Global Information Security responsible for near-24x7 monitoring, detection and response to security incidents. Operating in shifts across time zones, the team is the Firm's first line of defense against cyber threats, triaging alerts from multiple sources and acting swiftly to contain and remediate when a threat is confirmed, collaborating with regional IT teams to prevent recurrence.

The wider Information Security function is responsible for ensuring the overall effectiveness of the control framework and managing security incidents. The team works with unified principles and processes around the world while maintaining regional stakeholder relationships. It adheres to the international standard ISO/IEC 27001 and reports to the Firm's Global CISO.

Norton Rose Fulbright US LLP is committed to providing employees with a comprehensive and competitive benefits package that supports you, your health, and your family. Benefit packages include access to three medical insurance plans, dental insurance, vision insurance, life insurance, and disability insurance. Employees can also access pre-tax benefits such as health savings and flexible spending accounts. Norton Rose Fulbright helps provide financial security by allowing employees to participate in a 401(k) savings plan and profit-sharing plans if eligible. Full- time employees are eligible to access fertility benefits designed to support fertility and family-forming journeys. Employees may also access commuter benefits where applicable and student loan assistance refinancing options.

In addition to the Firm's health and welfare benefits above, we offer a competitive paid time off plan, which provides a minimum of 20 days off based on your role and tenure with the firm. The firm offers a generouspaid maternity leave and paid paternity leave (parental leave) benefit allowing parents to take a minimum of 14 weeks of paid leave to bond with your newborn or adopted child(ren). Employees may also access child care support through a back-up care program. Employees are also entitled to 11 Firm holidays.

Norton Rose Fulbright US LLP is an Equal Opportunity Employer and complies with all applicable federal laws and their implementing regulations that require the collection and recording of certain data and information. The information we receive will not be used to make any decision regarding employment and will be kept separate from your application. Similarly, self-identification information is kept confidential and used only in accordance with applicable federal laws and regulations. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status.Norton Rose Fulbright is committed to providing reasonable accommodation as an Equal Opportunity Employer to applicants with disabilities. If you require assistance or accommodation to complete your application, please contact us.hr@nortonrosefulbright.com. Please provide your contact information and a description of your accessibility issue. We will make a determination on your request for reasonable accommodation on a case-by-case basis.

E-Verify is a registered trademark of the U.S. Department of Homeland Security. This business uses E-Verify in its hiring practices to achieve a lawful workforce.

Equal Employment Opportunity

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Analyst, Information Security
Senior Analyst, Information Security

Phase2 Technology • Houston (TX)

On-site
USD 120,000 - 170,000
Medical insurance plans
Dental insurance
Vision insurance
+1
Senior Analyst, Information Security
Senior Analyst, Information Security

Norton Rose Fulbright • Austin (TX)

On-site
USD 110,000 - 170,000
Medical insurance
401(k) plan
Paid time off
Senior Analyst, Information Security
Senior Analyst, Information Security

Norton Rose Fulbright • Town of Texas (WI)

On-site
USD 110,000 - 170,000
Senior Security Operations Analyst & Threat Hunter
Senior Security Operations Analyst & Threat Hunter

Norton Rose Fulbright • Town of Texas (WI)

On-site
USD 110,000 - 170,000
Senior Analyst, HR Technology
Senior Analyst, HR Technology

NRF United Kingdom • Houston (TX)

Hybrid
USD 120,000 - 190,000
401(k) match
Profit sharing
Fertility benefits
+4
Senior Information Security Analyst: Threat Hunting & IR
Senior Information Security Analyst: Threat Hunting & IR

Phase2 Technology • Houston (TX)

On-site
USD 120,000 - 170,000
Medical insurance plans
Dental insurance
Vision insurance
+1
Senior Analyst, HR Technology
Senior Analyst, HR Technology

Phase2 Technology • Dallas (TX)

Hybrid
USD 110,000 - 140,000
Health insurance
Dental insurance
Vision insurance
+5
Manager, Information Governance Operations
Manager, Information Governance Operations

Norton Rose Fulbright • Houston (TX)

Hybrid
USD 120,000 - 180,000
Medical insurance options
Dental insurance
Vision insurance
+9
Manager, Information Governance Operations
Manager, Information Governance Operations

Norton Rose Fulbright • Austin (TX)

Hybrid
USD 110,000 - 170,000
Medical insurance plans
Dental & vision insurance
401(k) with employer match
+2
Senior Information Security Analyst – Threat Hunt
Senior Information Security Analyst – Threat Hunt

Norton Rose Fulbright • Austin (TX)

On-site
USD 110,000 - 170,000
Medical insurance
401(k) plan
Paid time off