Network Security Analyst

ASSYST, Inc.
Austin, TX, United States
22 days ago
Apply on www.austinjobsite.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Bash Shell Cloud Computing Security Apache Lucene CompTIA Security+ Cyber Security Query Languages Linux Embedded SQL Identity and Access Management Intrusion Detection and Prevention
+29 more
Intrusion Detection Systems Python (Programming Language) Network Security Microsoft Security Essentials Network Protocols Windows PowerShell Azure Active Directory ArcSight SIEM Tool Cloud Services Anti-Phishing Kusto Query Language Security Software Security Information and Event Management Software Vulnerability Management Scripting Cloud Platform System In-Plane Switching (IPS) Mitre Att&ck QRadar Malware Cyber Threat Analysis Firewalls (Computer Science) Azure Security Center Cybercrime Microsoft Sentinel Splunk SentinelOne Expertise Qualys Vulnerability Analysis

Job description

  • Monitor, analyze, and triage cybersecurity alerts from security monitoring and detection platforms.
  • Investigate security events and suspicious activity to determine severity, scope, impact, and potential risk.
  • Identify, validate, and prioritize potential cybersecurity incidents and escalate confirmed threats as appropriate.
  • Correlate security events from multiple sources, including endpoints, firewalls, IDS/IPS, cloud services, authentication systems, and threat intelligence feeds.
  • Analyze indicators of compromise (IOCs), phishing activity, malware detections, suspicious network activity, and anomalous user behavior.
  • Document security investigations, findings, and response actions in ticketing and case management systems.
  • Support incident containment, eradication, and recovery activities.
  • Perform vulnerability assessment reviews and support risk-based remediation prioritization.
  • Assist with alert tuning, threat intelligence integration, detection improvements, and false-positive analysis.
  • Support the development and maintenance of security procedures, playbooks, workflows, and knowledge base documentation.
  • Research emerging cyber threats, attack techniques, tactics, and procedures (TTPs).
  • Participate in incident response, escalation, and after-action review activities.
  • Maintain accurate investigation documentation, metrics, and technical reports.
  • Provide support outside normal business hours during high-priority security incidents as required.

Requirements

The ideal candidate will have experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines, along with experience working with security monitoring and cybersecurity tools and frameworks., * Experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines.

  • Experience triaging security alerts and analyzing security events.
  • Experience documenting incident investigations and response activities.
  • Experience with cybersecurity frameworks, incident response processes, and threat detection methodologies.
  • Experience working with SIEM, EDR/XDR, IDS/IPS, firewalls, endpoint security, cloud security, and threat intelligence platforms.
  • Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, or NetWitness.
  • Experience with Microsoft Security / Microsoft 365 Defender XDR.
  • Experience with EDR solutions such as Microsoft Defender for Endpoint, CrowdStrike, or SentinelOne.
  • Knowledge of MITRE ATT&CK, IOCs, IOAs, malware, phishing, and common cyber threats.
  • Experience with vulnerability management tools such as Tenable, Qualys, or Rapid7.
  • Knowledge of Windows, Linux, networking protocols, Active Directory, Microsoft Entra ID, and cloud environments.
  • Experience with query languages such as KQL, SPL, Lucene, or ESQL.
  • Experience with scripting languages such as PowerShell, Python, or Bash.
  • Knowledge of NIST Cybersecurity Framework, NIST Incident Response guidance, and PICERL.
  • Strong analytical, investigative, documentation, communication, and problem-solving skills.
  • Ability to distinguish legitimate threats from false positives and make risk-based decisions.
  • Ability to work independently and collaboratively within a 24x7 cybersecurity operations environment.

Preferred Certifications: CompTIA Security+, GCIH, GCIA, Certified SOC Analyst (CSA), Microsoft SC-200, or other GIAC/SOC-related certifications.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.austinjobsite.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all