Network Security Analyst

LUNA DATA SOLUTIONS
Austin, TX, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$104,000.0 - $124,800.0
Working hours
Regular working hours
Job source

Tech stack

JIRA Network Analysis Cyber Security Data Normalization Issue Tracking Systems Intrusion Detection and Prevention Intrusion Detection Systems Network Security Packet Analyzer Security Information and Event Management Mitre Att&ck Cyber Threat Analysis
+4 more
Microsoft Sentinel Firepower SentinelOne Expertise Cisco

Job description

Engineer, maintain, and tune SIEM platforms (Google SecOps, Gravwell), including correlation rules, dashboards, enrichment logic, and detection content. Configure, tune, and optimize IDS/IPS technologies (Corelight, Tipping Point, Cisco Firepower), including signature development and false-positive reduction. Perform packet capture (pcap) analysis to validate alerts, identify malicious traffic, and support investigations using Netwitness or Corelight. Conduct network traffic analysis to detect anomalies, lateral movement, and command-and-control activity. Strong understanding of network security architecture, including distributed sensors (Corelight), packet capture systems (NetWitness), and log pipelines (CRIBL, Gravwell, Google SecOps). Operationalize threat intelligence feeds within SOC platforms and customers, converting indicators into detection logic, correlation rules, and automated enrichment workflows. Continuously tune detection content based on intelligence-driven insights, improving alert fidelity and reducing false positives across statewide monitoring. Develop and maintain orchestration playbooks within Cyware, integrating SIEM, EDR, threat intelligence, and ticketing systems to support statewide monitoring expansion and rapid incident handling. Support SOC operations by providing detection engineering, log onboarding, and data normalization. Develop and maintain network security monitoring infrastructure, including sensors, collectors, and log pipelines. Collaborate with Incident Responders to provide network-level evidence, context, and threat validation. Produce engineering reports, tuning documentation, and platform health assessments. Implement detection logic aligned with MITRE ATT&CK, threat intelligence, and emerging adversary behaviors. Produce engineering documentation, tuning reports, platform health assessments, and detection coverage maps using data from Firepower, TippingPoint, Corelight, NetWitness, Microsoft Sentinel, and Google SecOps

Requirements

Do you have experience in Threat intelligence?, SOC operations experience Hands-on experience with IDS/IPS platforms, specifically Cisco Firepower and TippingPoint, including signature tuning, false-positive reduction, and threat-driven detection improvements. Advanced packet capture (pcap) and network analysis skills using Corelight, NetWitness, and CRIBL pipelines to identify anomalies, malicious traffic, and lateral movement. Experience maintaining and tuning EDR platforms, including CrowdStrike Falcon and SentinelOne, and integrating EDR telemetry into SIEM and orchestration workflows. Threat intelligence application expertise Develop detection logic aligned with adversary TTPs

Preferred Skills: Experience operationalizing threat intelligence by converting indicators and TTPs from Recorded Future, ThreatMon, GreyNoise, Google Threat Intelligence, VirusTotal, and Mandiant into SIEM rules, IPS signatures, and automated enrichment logic. Experience operationalizing threat intelligence by converting indicators and TTPs from Recorded Future, ThreatMon, GreyNoise, Google Threat Intelligence, VirusTotal, and Mandiant into SIEM rules, IPS signatures, and automated enrichment logic. Perform packet-level analysis to validate alerts and identify malicious activity Serves as an escalation SOC analysts to support other SOC analyst and incident responders with enriched network-level intelligence Proficiency with Google SecOps and Cyware (SOAR) orchestration, including building automated workflows that integrate SIEM, IDS/IPS, EDR (CrowdStrike, SentinelOne), threat intelligence, and Jira ticketing for SOC automation Security Certifications Preferred (CISSP, CEH, GISF, GSEC, CySA+, Sec+)

Benefits & conditions

4.54.5 out of 5 stars Austin, TX 78744 $50 - $60 an hour - Contract, Pulled from the full job description

  • Health insurance
  • Vision insurance
  • Dental insurance
  • Life insurance
  • Disability insurance, Work on a highly innovative team with cutting-edge technology Great opportunity to make a big impact and take ownership of technology initiatives Altruistic work Competitive compensation and benefits including health, dental, vision, life and accident insurance, short-term disability insurance, and more!

Luna Data Solutions, Inc. (LDS) provides equal employment opportunities to all employees. All applicants will be considered for employment. LDS prohibits discrimination and harassment of any type regarding age, race, color, religion, sexual orientation, gender identity, sex, national origin, genetics, protected veteran status, and/or disability status.

Pay: $50.00 - $60.00 per hour

Benefits:

  • Dental insurance
  • Health insurance
  • Life insurance
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

4:23 min

Boosting security operations center productivity with intelligent data analysis

Chris Wysopal Chris Wysopal +2 · WWC 2024

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

Videos

See all

Related articles

See all