SOC Analyst II - Cybersecurity Operations & IR

ASSYST

Austin (TX)

On-site

USD 90,000 - 120,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

ASSYST is seeking a Network Security Analyst for a State client in Austin, TX to support the cybersecurity operations, security monitoring, threat detection, and incident response activities for a client.

The role will focus on monitoring and triaging security alerts, analyzing suspicious activity and security events, identifying potential threats, and supporting incident investigation and response activities.

Qualifications

  • Experience in cybersecurity operations, security monitoring, incident response, threat detection, or related cybersecurity disciplines.
  • Experience triaging security alerts and analyzing security events.
  • Experience documenting incident investigations and response activities.
  • Experience with cybersecurity frameworks, incident response processes, and threat detection methodologies.
  • Experience working with SIEM, EDR/XDR, IDS/IPS, firewalls, endpoint security, cloud security, and threat intelligence platforms.
  • Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, or NetWitness.
  • Experience with Microsoft Security / Microsoft 365 Defender XDR.
  • Experience with EDR solutions such as Microsoft Defender for Endpoint, CrowdStrike, or SentinelOne.
  • Knowledge of MITRE ATT&CK, IOCs, IOAs, malware, phishing, and common cyber threats.
  • Experience with vulnerability management tools such as Tenable, Qualys, or Rapid7.
  • Knowledge of Windows, Linux, networking protocols, Active Directory, Microsoft Entra ID, and cloud environments.
  • Experience with query languages such as KQL, SPL, Lucene, or ESQL.
  • Experience with scripting languages such as PowerShell, Python, or Bash.
  • Knowledge of NIST Cybersecurity Framework, NIST Incident Response guidance, and PICERL.
  • Strong analytical, investigative, documentation, communication, and problem-solving skills.
  • Ability to distinguish legitimate threats from false positives and make risk-based decisions.
  • Ability to work independently and collaboratively within a 24x7 cybersecurity operations environment.

Responsibilities

  • Monitor, analyze, and triage cybersecurity alerts from security monitoring and detection platforms.
  • Investigate security events and suspicious activity to determine severity, scope, impact, and potential risk.
  • Identify, validate, and prioritize potential cybersecurity incidents and escalated confirmed threats as appropriate.
  • Correlate security events from multiple sources, including endpoints, firewalls, IDS/IPS, cloud services, authentication systems, and threat intelligence feeds.
  • Analyze indicators of compromise (IOCs), phishing activity, malware detections, suspicious network activity, and anomalous user behavior.
  • Document security investigations, findings, and response actions in ticketing and case management systems.
  • Support incident containment, eradication, and recovery activities.
  • Perform vulnerability assessment reviews and support risk-based remediation prioritization.
  • Assist with alert tuning, threat intelligence integration, detection improvements, and false-positive analysis.
  • Support the development and maintenance of security procedures, playbooks, workflows, and knowledge base documentation.
  • Research emerging cyber threats, attack techniques, tactics, and procedures (TTPs).
  • Participate in incident response, escalation, and after-action review activities.
  • Maintain accurate investigation documentation, metrics, and technical reports.
  • Provide support outside normal business hours during high-priority security incidents as required.

Skills

Cybersecurity operations
Security monitoring
Incident response
Threat detection
Security investigations
Documentation
Communication
Problem-solving

Tools

Microsoft Sentinel
Splunk
QRadar
ArcSight
LogRhythm
NetWitness
Microsoft Defender for Endpoint
CrowdStrike
SentinelOne
Tenable
Qualys
Rapid7

Job description

ASSYST is seeking a Network Security Analyst for a State client in Austin, TX to support the cybersecurity operations, security monitoring, threat detection, and incident response activities for a client.

The role will focus on monitoring and triaging security alerts, analyzing suspicious activity and security events, identifying potential threats, and supporting incident investigation and response activities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst II / Cybersecurity Operations Analyst
SOC Analyst II / Cybersecurity Operations Analyst

ASSYST • Austin (TX)

On-site
USD 90,000 - 120,000
Senior Security Operations & Detection Engineer
Senior Security Operations & Detection Engineer

Socket.dev • Austin (TX)

On-site
USD 120,000 - 150,000
Senior Network Security Analyst - Threat Detection & IR
Senior Network Security Analyst - Threat Detection & IR

Ampcus, Inc • Austin (TX)

On-site
USD 90,000 - 130,000
Security Operations / Detection Engineering analyst.
Security Operations / Detection Engineering analyst.

Socket.dev • Austin (TX)

On-site
USD 120,000 - 150,000
SOC Network Security Analyst – 24/7 Threat Defense (Austin)
SOC Network Security Analyst – 24/7 Threat Defense (Austin)

KPG99 INC • Austin (TX)

On-site
USD 90,000 - 120,000
Security Operations Analyst II — On-Site Austin
Security Operations Analyst II — On-Site Austin

Digerati Systems Inc. • Austin (TX)

On-site
USD 110,000 - 165,000
SOC Analyst, Onsite - 70051
SOC Analyst, Onsite - 70051

PRIMUS Global Services • Town of Texas (WI)

On-site
USD 90,000 - 120,000
Senior Cyber Defense Analyst: Armis & SOC Lead
Senior Cyber Defense Analyst: Armis & SOC Lead

Saic • Austin (TX)

On-site
USD 110,000 - 160,000
Incident Response Analyst I — Data Center Security
Incident Response Analyst I — Data Center Security

Astreya • Austin (TX), Northern (KY)

Hybrid
USD 60,000 - 94,000
Medical benefits
Dental benefits
Vision benefits
+3
SOC Analyst I–II: Incident Detection & Response
SOC Analyst I–II: Incident Detection & Response

Optimalsemi • Irving (TX)

On-site
USD 95,000 - 125,000