> Markdown version of [/jobs/ext/2240882-senior-analyst-information-security](https://www.wearedevelopers.com/jobs/ext/2240882-senior-analyst-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Analyst, Information Security - **Company:** Norton Rose Fulbright - **Location:** Austin, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Windows, Active Directory, Artificial Intelligence, Amazon Web Services, Authentication Protocols, Microsoft Azure, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Core Foundation, Linux, Digital Forensics, Event Logging, Monitoring of Systems, Identity and Access Management, Information Security Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Windows PowerShell, Azure Active Directory, Phishing, Kusto Query Language, Security Information and Event Management, Data Logging, Scripting, Cloud Platform System, In-Plane Switching (IPS), Mitre Att&ck, Firewalls (Computer Science), Cybercrime, Microsoft Sentinel, Cisco, Blue Team (Cyber Security), Security Orchestration, Automation & Response, Servicenow - **Published:** August 26, 2026 - **Apply:** https://justjobs.com/main/sendform/8/8/28176/1/18069635?backUrl=%2Fcareer%2F18069635%2FSenior-Analyst-Information-Security-Texas-Austin ## About the Role * Technical bachelor's degree or equivalent IT / Information Security experience (required). * At least 5 years' experience working within security operations or Information Security infrastructure, or a strong vocation and demonstrable transferable experience from another technical discipline. * Proven ability to adapt quickly to emerging threats or new information, shifting focus as needed. * Demonstrated expertise in Microsoft 365 Defender and Microsoft Sentinel for detecting, investigating and responding to suspicious and anomalous activity. * Strong knowledge of core security technologies (firewalls, IDS/IPS, EDR, SIEM) and of structured incident-response methodologies (e.g. NIST). * Working knowledge of endpoint security and monitoring infrastructure (EDR, DLP, removable-media encryption) and of cloud-based web and email security solutions (e.g. Zscaler, Mimecast, Proofpoint, Cisco). * Ability to triage and remediate phishing and impersonation attacks in a timely and efficient manner as the risk dictates. * Experience working with a service management tool (e.g. ServiceNow). In addition to the core foundation above, the Senior Analyst must bring demonstrable, in-depth expertise in at least one of the following domains, with solid working knowledge across the remainder: * Identity & Access - deep experience detecting and responding to identity-based attacks across Active Directory and Entra ID / Azure AD, including conditional access, privileged access, authentication protocols and identity threat detection and response (ITDR). * Cloud Security - deep experience monitoring and responding to threats across a major cloud platform (Azure, AWS or GCP), including cloud logging and telemetry, posture signals, and cloud-native detection and response. * Windows & Linux Operating Systems - deep host-level investigation and forensic capability across both Windows and Linux, including event log and audit analysis, process and memory investigation, and OS hardening. * Security Automation & Detection Engineering - advanced scripting (PowerShell and/or Python) and SOAR playbook development, and/or detection engineering (Sigma / KQL) to automate response and expand detection coverage at scale. ## Description Security Monitoring, Detection & Response * Operate and manage security incidents and requests to SLA guidelines, acting as an intermediate escalation point for complex investigations. * Monitor, triage and investigate alerts across endpoints, cloud, identity, email and network telemetry, reviewing and escalating unusual event behavior. * Lead structured incident response aligned to a recognized lifecycle, including containment, eradication, recovery, evidence preservation and digital forensic analysis as authorized. * Triage and remediate phishing, vishing and impersonation attacks in a timely and efficient manner as the risk dictates. * Configure and tune appropriate security parameters in monitoring systems and act as a technical point of escalation for alerted issues. Detection Engineering & Threat Hunting * Conduct proactive, hypothesis-driven threat hunting on a scheduled basis to identify adversary activity not surfaced by existing detections. * Design, test, tune and maintain detection rules and use cases (e.g. Sigma / KQL), and map detection coverage to the MITRE ATT&CK framework to identify and close detection gaps. * Maintain technical awareness of adversary tradecraft, emerging attack techniques and threat intelligence relevant to the legal sector, translating these into new or improved detections. * Automation & AI-Enabled Operations * Develop and maintain security automation and orchestration (SOAR) playbooks to streamline incident response and automate repetitive operational tasks. * Use AI-assisted detection, triage and investigation tooling effectively, and critically validate, tune and quality-assure AI-generated findings and recommendations Governance, Improvement & Leadership * Act as a technical mentor for junior and peer analysts, supporting skills development and succession planning within the region. * Take ownership of one or more SOC processes, functions or technologies globally, ensuring their continued maintenance and improvement. * Assist with development and maintenance of SOC playbooks, runbooks, monitoring configuration and standard operating procedures, identifying improvements and reporting on incidents, * Security Operations / SIEM: Microsoft SC-200 (Security Operations Analyst), GIAC GSOC * Incident Handling & Response: GIAC GCIH, Blue Team Level 1 (BTL1) * Specialist Technical Certifications: AZ-500 (Azure Security Engineer), SC-300 (Microsoft Identity and Access Administrator), GCFA (GIAC Certified Forensic Analyst), GCFE (GIAC Certified Forensic Examiner), GIAC GPYC (Python Coder) * Foundational / Broad Security Certifications: CompTIA Security+, GIAC GSEC, CISSP, CCSP The Team: The Security Operations (SOC) team is a dedicated sub-team of Global Information Security responsible for near-24x7 monitoring, detection and response to security incidents. Operating in shifts across time zones, the team is the Firm's first line of defense against cyber threats, triaging alerts from multiple sources and acting swiftly to contain and remediate when a threat is confirmed, collaborating with regional IT teams to prevent recurrence. The wider Information Security function is responsible for ensuring the overall effectiveness of the control framework and managing security incidents. The team works with unified principles and processes around the world while maintaining regional stakeholder relationships. It adheres to the international standard ISO/IEC 27001 and reports to the Firm's Global CISO. ## Related Videos - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)