> Markdown version of [/jobs/ext/726995-network-security-analyst](https://www.wearedevelopers.com/jobs/ext/726995-network-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Network Security Analyst - **Company:** LUNA DATA SOLUTIONS - **Location:** Austin, TX, United States - **Salary:** $104,000.0 - $124,800.0 - **Contract:** Permanent contract - **Skills:** JIRA, Network Analysis, Cyber Security, Data Normalization, Issue Tracking Systems, Intrusion Detection and Prevention, Intrusion Detection Systems, Network Security, Packet Analyzer, Security Information and Event Management, Mitre Att&ck, Cyber Threat Analysis, Microsoft Sentinel, Firepower, SentinelOne Expertise, Cisco - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=40eda3005798d342 ## About the Role Do you have experience in Threat intelligence?, SOC operations experience Hands-on experience with IDS/IPS platforms, specifically Cisco Firepower and TippingPoint, including signature tuning, false-positive reduction, and threat-driven detection improvements. Advanced packet capture (pcap) and network analysis skills using Corelight, NetWitness, and CRIBL pipelines to identify anomalies, malicious traffic, and lateral movement. Experience maintaining and tuning EDR platforms, including CrowdStrike Falcon and SentinelOne, and integrating EDR telemetry into SIEM and orchestration workflows. Threat intelligence application expertise Develop detection logic aligned with adversary TTPs Preferred Skills: Experience operationalizing threat intelligence by converting indicators and TTPs from Recorded Future, ThreatMon, GreyNoise, Google Threat Intelligence, VirusTotal, and Mandiant into SIEM rules, IPS signatures, and automated enrichment logic. Experience operationalizing threat intelligence by converting indicators and TTPs from Recorded Future, ThreatMon, GreyNoise, Google Threat Intelligence, VirusTotal, and Mandiant into SIEM rules, IPS signatures, and automated enrichment logic. Perform packet-level analysis to validate alerts and identify malicious activity Serves as an escalation SOC analysts to support other SOC analyst and incident responders with enriched network-level intelligence Proficiency with Google SecOps and Cyware (SOAR) orchestration, including building automated workflows that integrate SIEM, IDS/IPS, EDR (CrowdStrike, SentinelOne), threat intelligence, and Jira ticketing for SOC automation Security Certifications Preferred (CISSP, CEH, GISF, GSEC, CySA+, Sec+) ## Description Engineer, maintain, and tune SIEM platforms (Google SecOps, Gravwell), including correlation rules, dashboards, enrichment logic, and detection content. Configure, tune, and optimize IDS/IPS technologies (Corelight, Tipping Point, Cisco Firepower), including signature development and false-positive reduction. Perform packet capture (pcap) analysis to validate alerts, identify malicious traffic, and support investigations using Netwitness or Corelight. Conduct network traffic analysis to detect anomalies, lateral movement, and command-and-control activity. Strong understanding of network security architecture, including distributed sensors (Corelight), packet capture systems (NetWitness), and log pipelines (CRIBL, Gravwell, Google SecOps). Operationalize threat intelligence feeds within SOC platforms and customers, converting indicators into detection logic, correlation rules, and automated enrichment workflows. Continuously tune detection content based on intelligence-driven insights, improving alert fidelity and reducing false positives across statewide monitoring. Develop and maintain orchestration playbooks within Cyware, integrating SIEM, EDR, threat intelligence, and ticketing systems to support statewide monitoring expansion and rapid incident handling. Support SOC operations by providing detection engineering, log onboarding, and data normalization. Develop and maintain network security monitoring infrastructure, including sensors, collectors, and log pipelines. Collaborate with Incident Responders to provide network-level evidence, context, and threat validation. Produce engineering reports, tuning documentation, and platform health assessments. Implement detection logic aligned with MITRE ATT&CK, threat intelligence, and emerging adversary behaviors. Produce engineering documentation, tuning reports, platform health assessments, and detection coverage maps using data from Firepower, TippingPoint, Corelight, NetWitness, Microsoft Sentinel, and Google SecOps ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)