SOC/Cybersecurity Analyst

Air InfoSec

Austin, Northern (TX, KY)

Hybrid

USD 95,000 - 135,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Air InfoSec is seeking a SOC/Cybersecurity Analyst to support the Texas HHSC CSOC from its Austin office. The role involves advanced threat triage, alert validation, incident escalation, and collaboration with technical teams to contain and recover from incidents.

You will document investigations and help improve detection capabilities. The position requires 5 years of experience in security operations, monitoring, and incident response, with a strong background in cybersecurity frameworks.

Qualifications

  • 5 years of experience triaging security alerts.
  • 5 years of experience analyzing security events.
  • 5 years of experience documenting incident investigations.
  • 5 years of experience with cybersecurity frameworks.
  • 5 years of experience with incident response processes.
  • 5 years of experience with threat detection methodologies.
  • 5 years of experience in security monitoring.
  • 5 years of experience in security investigations.

Responsibilities

  • Monitor, analyze, and triage cybersecurity alerts generated by SIEM, EDR, cloud security, email security, identity protection, and network security platforms.
  • Conduct initial investigations of detected and reported security events to determine severity, scope, and impact.
  • Identify, validate, and prioritize potential cybersecurity incidents, escalating confirmed threats according to established procedures.
  • Correlate security events from multiple data sources, including endpoints, firewalls, intrusion detection and prevention systems, cloud services, and threat intelligence feeds.
  • Review and analyze indicators of compromise, suspicious network activity, phishing emails, malware detections, and anomalous user behavior.
  • Document investigations, findings, and response actions in ticketing and case management systems.
  • Assist with incident containment, eradication, and recovery efforts by coordinating with technical teams and stakeholders.
  • Report and elevate findings to the CSOC Team Lead and/or SOC Manager.
  • Support continuous improvement of threat detection capabilities through alert tuning, process refinement, and threat intelligence integration.
  • Perform vulnerability assessment reviews and support development of operational procedures, playbooks, and knowledge base articles.

Skills

Security operations
Threat detection
Security monitoring
Documentation
Vulnerability assessment

Education

Bachelor's degree in cybersecurity or related field

Tools

Microsoft Sentinel
Splunk
CrowdStrike
Tenable
Qualys
Zscaler
Prisma

Job description

Job Description

The SOC/Cybersecurity Analyst will support the Texas Health and Human Services Commission on the Cybersecurity Operations Center (CSOC). This role performs advanced cybersecurity analysis and threat triage within the CSOC, monitoring and investigating security alerts across enterprise platforms to protect agency information systems, networks, and data. The analyst serves as a primary point of contact for security event analysis, threat identification, and incident escalation. Work includes correlating data from multiple security tools, validating potential incidents, and coordinating response activities with technical teams. The analyst also documents investigations, supports continuous improvement of detection capabilities, and contributes to operational procedures and playbooks. This position requires the ability to work independently and as part of a 24x7 cybersecurity operations team.

Responsibilities:

  • Monitor, analyze, and triage cybersecurity alerts generated by SIEM, EDR, cloud security, email security, identity protection, and network security platforms.
  • Conduct initial investigations of detected and reported security events to determine severity, scope, and impact.
  • Identify, validate, and prioritize potential cybersecurity incidents, escalating confirmed threats according to established procedures.
  • Correlate security events from multiple data sources, including endpoints, firewalls, intrusion detection and prevention systems, cloud services, and threat intelligence feeds.
  • Review and analyze indicators of compromise, suspicious network activity, phishing emails, malware detections, and anomalous user behavior.
  • Document investigations, findings, and response actions in ticketing and case management systems.
  • Assist with incident containment, eradication, and recovery efforts by coordinating with technical teams and stakeholders.
  • Report and elevate findings to the CSOC Team Lead and/or SOC Manager.
  • Support continuous improvement of threat detection capabilities through alert tuning, process refinement, and threat intelligence integration.
  • Perform vulnerability assessment reviews and support development of operational procedures, playbooks, and knowledge base articles.
Requirements

Minimum Qualifications:

  • 5 years of experience triaging security alerts.
  • 5 years of experience analyzing security events.
  • 5 years of experience documenting incident investigations.
  • 5 years of experience with cybersecurity frameworks.
  • 5 years of experience with incident response processes.
  • 5 years of experience with threat detection methodologies.
  • 5 years of experience in cybersecurity operations.
  • 5 years of experience in security monitoring.
  • 5 years of experience in incident response.
  • 5 years of experience in threat detection.
  • 5 years of experience in security investigations.
  • 5 years of experience in related cybersecurity disciplines.

Preferred Qualifications:

  • Experience with one or more Texas state agencies.
  • Bachelor's degree in cybersecurity, information security, computer science, computer information systems, management information systems, or a related field (relevant education and experience may be substituted).
  • A security certification such as CompTIA Security+, GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), Certified SOC Analyst (CSA), Microsoft Cybersecurity Analyst (SC-200), or another GIAC or SOC-related certification.
  • Experience with enterprise SOC tools and technologies such as Microsoft Sentinel, Splunk, CrowdStrike, Tenable, Qualys, Zscaler, or Prisma.

Additional Requirements:

  • Candidates are subject to a pre-employment security review and criminal background check to determine employment eligibility.
  • Candidates must currently reside in Texas and be local to the Austin area. Candidates who reside out of state, including those planning to relocate, will not be accepted.
  • May be required to work outside normal business hours, including weekends, evenings, and holidays, during high-priority security incidents, as approved by the SOC Manager.

Work Location and Schedule:

  • Location: 701 W 51st Street, Austin, TX 78751.
  • Schedule: Monday through Friday, 8:00 a.m. to 5:00 p.m., excluding Texas state holidays. May require work outside normal business hours during high-priority incidents.
  • Work Arrangement: Onsite.

Air InfoSec, LLC is an Equal Opportunity Employer and does not discriminate on the basis of race or ethnicity, religion, sex, national origin, age, veteran disability or genetic information or any other reason prohibited by law in employment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Security Analyst 1769
Network Security Analyst 1769

Sistema Technologies Inc. • Austin (TX)

On-site
USD 120,000 - 180,000
Network Security Analyst – Level 1
Network Security Analyst – Level 1

Jobtailor • Austin (TX)

On-site
USD 95,000 - 130,000
Senior SOC Analyst: Threat Detection & IR (Austin)
Senior SOC Analyst: Threat Detection & IR (Austin)

Air InfoSec • Austin (TX), Northern (KY)

Hybrid
USD 95,000 - 135,000
SOC Analyst II / Cybersecurity Operations Analyst
SOC Analyst II / Cybersecurity Operations Analyst

Socket.dev • Austin (TX)

On-site
USD 80,000 - 120,000
Cybersecurity Operations Center Engineer
Cybersecurity Operations Center Engineer

Texas Health and Human Services • Austin (TX)

On-site
USD 78,000 - 132,000
Health insurance
Pension plan
Time off
+1
Cybersecurity Operations Center Analyst
Cybersecurity Operations Center Analyst

FALL CREEK FARM & NURSERY • Austin (TX)

On-site
USD 78,000 - 132,000
Full health insurance
Defined benefit pension
Generous leave
Senior SOC Analyst: Threat Detection & Incident Response
Senior SOC Analyst: Threat Detection & Incident Response

FALL CREEK FARM & NURSERY • Austin (TX)

On-site
USD 78,000 - 132,000
Full health insurance
Defined benefit pension
Generous leave
Network Security Analyst New Austin, TX
Network Security Analyst New Austin, TX

ASSYST, Inc. • Austin (TX), Northern (KY)

Hybrid
USD 95,000 - 125,000
Cybersecurity Operations Center Analyst
Cybersecurity Operations Center Analyst

Texas Health and Human Services • Austin (TX)

On-site
USD 78,000 - 132,000
Health insurance
Pension plan
Paid time off
+1
Network Security Analyst
Network Security Analyst

ArnAmy, Inc. • Austin (TX)

On-site
USD 85,000 - 120,000