Senior Information Security Analyst

INSPYR Solutions

Houston (TX)

Hybrid

USD 110,000 - 165,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

INSPYR Solutions is seeking a Senior Information Security Analyst to join our clients' global Security Operations (SOC) team. You will lead monitoring, detection and response activities, drive threat hunting, and improve detection capabilities across endpoints, cloud, identity, email and network telemetry.

The role focuses on incident response, detection engineering, and proactive threat hunting, reporting to the Information Security Manager.

Qualifications

  • Bachelor's degree in IT or Information Security, or equivalent experience.
  • At least 5 years in security operations or related field.
  • Proven expertise with Microsoft 365 Defender and Microsoft Sentinel.
  • Strong knowledge of SIEM, EDR, firewalls and incident response.

Responsibilities

  • Operate and manage security incidents and requests to SLA guidelines, acting as an intermediate escalation point for complex investigations.
  • Monitor, triage and investigate alerts across endpoints, cloud, identity, email and network telemetry, reviewing and escalating unusual event behavior.
  • Lead structured incident response aligned to a recognized lifecycle, including containment, eradication, recovery, evidence preservation and digital forensic analysis as authorized.
  • Triage and remediate phishing, vishing and impersonation attacks in a timely and efficient manner as the risk dictates.
  • Configure and tune appropriate security parameters in monitoring systems and act as a technical point of escalation for alerted issues.
  • Conduct proactive threat hunting and design/double-check detection rules mapped to MITRE ATT&CK.

Skills

Azure Sentinel
Security Operations
Incident management
Threat investigations

Education

Bachelor's degree in IT or Information Security

Tools

Microsoft 365 Defender
Microsoft Sentinel
Sigma
KQL

Job description

Title

Senior Information Security Analyst


Location

Hybrid in either Houston or Austin, TX (Primarily remote with in-office visits as needed)


Duration

Permanent, Direct-Hire


Work Requirements

US Citizens, GC Holders or Authorized to Work in the US.


Top Skills Required


  • Strong experience in Azure Sentinel is a requirement for this position

  • Strong skills in Security Operations is critical, including incident management and response, threat investigations, etc.


Job Description

This is a role with our external client, who is a global lawfirm. The Senior Information Security Analyst is one of several senior analyst roles within the firm's global Security Operations (SOC) team. Each Senior Analyst provides technical leadership in the SOC's day-to-day monitoring, detection and response activities, hunts for emerging adversary activity, and continuously improves the firm's ability to detect and respond to threats at speed.


The role is part of a worldwide team empowered to operate the activities within its assigned function. Daily activities focus on security monitoring, event and incident triage, incident response, request management, detection engineering and proactive threat hunting, with direction provided by the Information Security Manager.


Key responsibilities include, but are not limited to

Security Monitoring, Detection & Response


  • Operate and manage security incidents and requests to SLA guidelines, acting as an intermediate escalation point for complex investigations.

  • Monitor, triage and investigate alerts across endpoints, cloud, identity, email and network telemetry, reviewing and escalating unusual event behavior.

  • Lead structured incident response aligned to a recognized lifecycle, including containment, eradication, recovery, evidence preservation and digital forensic analysis as authorized.

  • Triage and remediate phishing, vishing and impersonation attacks in a timely and efficient manner as the risk dictates.

  • Configure and tune appropriate security parameters in monitoring systems and act as a technical point of escalation for alerted issues.


Detection Engineering & Threat Hunting


  • Conduct proactive, hypothesis-driven threat hunting on a scheduled basis to identify adversary activity not surfaced by existing detections.

  • Design, test, tune and maintain detection rules and use cases (e.g. Sigma / KQL), and map detection coverage to the MITRE ATT&CK framework to identify and close detection gaps.

  • Maintain technical awareness of adversary tradecraft, emerging attack techniques and threat intelligence relevant to the legal sector, translating these into new or improved detections.

  • Automation & AI-Enabled Operations

  • Develop and maintain security automation and orchestration (SOAR) playbooks to streamline incident response and automate repetitive operational tasks.

  • Use AI-assisted detection, triage and investigation tooling effectively, and critically validate, tune and quality-assure AI-generated findings and recommendations


Governance, Improvement & Leadership


  • Act as a technical mentor for junior and peer analysts, supporting skills development and succession planning within the region.

  • Take ownership of one or more SOC processes, functions or technologies globally, ensuring their continued maintenance and improvement.

  • Assist with development and maintenance of SOC playbooks, runbooks, monitoring configuration and standard operating procedures, identifying improvements and reporting on incidents


Required Experience and Skills


  • Technical bachelor's degree or equivalent IT / Information Security experience (required).

  • At least 5 years' experience working within security operations or Information Security infrastructure, or a strong vocation and demonstrable transferable experience from another technical discipline.

  • Proven ability to adapt quickly to emerging threats or new information, shifting focus as needed.

  • Demonstrated expertise in Microsoft 365 Defender and Microsoft Sentinel for detecting, investigating and responding to suspicious and anomalous activity.

  • Strong knowledge of core security technologies (firewalls, IDS/IPS, EDR, SIEM) and of structured incident-response methodologies (e.g. NIST).

  • Working knowledge of endpoint security and monitoring infrastructure (EDR, DLP, removable-media encryption) and of cloud-based web and email security solutions (e.g. Zscaler, Mimecast, Proofpoint, Cisco).

  • Ability to triage and remediate phishing and impersonation attacks in a timely and efficient manner as the risk dictates.

  • Experience working with a service management tool (e.g. ServiceNow).


In addition to the core foundation above, the Senior Analyst must bring demonstrable, in-depth expertise in at least one of the following domains, with solid working knowledge across the remainder:


  • Identity & Access — deep experience detecting and responding to identity-based attacks across Active Directory and Entra ID / Azure AD, including conditional access, privileged access, authentication protocols and identity threat detection and response (ITDR).

  • Cloud Security — deep experience monitoring and responding to threats across a major cloud platform (Azure, AWS or GCP), including cloud logging and telemetry, posture signals, and cloud-native detection and response.

  • Windows & Linux Operating Systems — deep host-level investigation and forensic capability across both Windows and Linux, including event log and audit analysis, process and memory investigation, and OS hardening.

  • Security Automation & Detection Engineering — advanced scripting (PowerShell and/or Python) and SOAR playbook development, and/or detection engineering (Sigma / KQL) to automate response and expand detection coverage at scale.


Preferred Certifications


  • Security Operations / SIEM: Microsoft SC-200 (Security Operations Analyst), GIAC GSOC

  • Incident Handling & Response: GIAC GCIH, Blue Team Level 1 (BTL1)

  • Specialist Technical Certifications: AZ-500 (Azure Security Engineer), SC-300 (Microsoft Identity and Access Administrator), GCFA (GIAC Certified Forensic Analyst), GCFE (GIAC Certified Forensic Examiner), GIAC GPYC (Python Coder)

  • Foundational / Broad Security Certifications: CompTIA Security+, GIAC GSEC, CISSP, CCSP


The Team

The Security Operations (SOC) team is a dedicated sub-team of Global Information Security responsible for near-24x7 monitoring, detection and response to security incidents. Operating in shifts across time zones, the team is the firm's first line of defense against cyber threats, triaging alerts from multiple sources and acting swiftly to contain and remediate when a threat is confirmed, collaborating with regional IT teams to prevent recurrence.


The wider Information Security function is responsible for ensuring the overall effectiveness of the control framework and managing security incidents. The team works with unified principles and processes around the world while maintaining regional stakeholder relationships. It adheres to the international standard ISO/IEC 27001 and reports to the Firm's Global CISO.


About INSPYR Solutions

Technology is our focus and quality is our commitment. As a national expert in delivering flexible technology and talent solutions, we strategically align industry and technical expertise with our clients' business objectives and cultural needs. Our solutions are tailored to each client and include a wide variety of professional services, project, and talent solutions. By always striving for excellence and focusing on the human aspect of our business, we work seamlessly with our talent and clients to match the right solutions to the right opportunities. Learn more about us at inspyrsolutions.com.


INSPYR Solutions provides Equal Employment Opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, or genetics. In addition to federal law requirements, INSPYR Solutions complies with applicable state and local laws governing nondiscrimination in employment in every location in which the company has facilities.


Information collected and processed through your application with INSPYR Solutions (including any job applications you choose to submit) is subject to INSPYR Solutions’ Privacy Policy and INSPYR Solutions’ AI and Automated Employment Decision Tool Policy: https://www.inspyrsolutions.com/policies/. By submitting an application, you are consenting to being contacted by INSPYR Solutions through phone, email, or text.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior IT Compliance & Audit Analyst
Senior IT Compliance & Audit Analyst

INSPYR Solutions • Fort Worth (TX)

Hybrid
USD 83,000 - 124,000
Comprehensive medical benefits
401(k) retirement plan
Information Security Senior Associate
Information Security Senior Associate

INSPYR Solutions • San Antonio (TX)

On-site
USD 115,000 - 125,000
SQL DBA
SQL DBA

INSPYR Solutions • Houston (TX)

On-site
USD 110,000 - 150,000
Comprehensive medical benefits
401(k) retirement plan
…and much more!
Information Security Analyst (Microsoft Security)
Information Security Analyst (Microsoft Security)

INSPYR Solutions • Las Vegas (NV)

On-site
USD 55,000 - 61,000
Comprehensive medical benefits
Competitive pay
401(k) retirement plan
IT Operator / Asset Management
IT Operator / Asset Management

INSPYR Solutions • Merrifield (VA)

On-site
USD 52,000
Comprehensive medical benefits
Competitive pay
401(k) retirement plan
Server Operations Specialist III
Server Operations Specialist III

INSPYR Solutions • Houston (TX)

On-site
USD 80,000 - 100,000
Comprehensive medical benefits
Competitive pay
401(k)
+1
Cybersecurity Incident Response Lead
Cybersecurity Incident Response Lead

INSPYR Solutions • California (MO)

Remote
USD 100,000 - 130,000
Security Compliance Analyst II
Security Compliance Analyst II

INSPYR Global Solutions • United States

On-site
USD 120,000 - 180,000
Competitive pay
Sr. Data Solutions Analyst (SQL)
Sr. Data Solutions Analyst (SQL)

INSPYR Solutions • Deerfield Beach (FL)

Hybrid
USD 103,000 - 110,000
Comprehensive medical benefits
Competitive pay, 401(k)
Retirement plan
+1
Senior Technical Manager - Edge Software
Senior Technical Manager - Edge Software

INSPYR Solutions • Houston (TX)

On-site
USD 140,000 - 200,000