| Location | Austin, TX |
| Salary | $70 Per Hour |
Location: Austin, TX 78751
Work Arrangement: Onsite
Start Date: October 5, 2026
Expected End Date: August 31, 2027
Business Hours: Monday through Friday, 8:00 AM to 5:00 PM
Our client is seeking a Network Security Analyst 1 to support enterprise cybersecurity monitoring, threat detection, security investigations, and incident response activities.
This is a hands-on security operations role responsible for monitoring and triaging cybersecurity alerts, investigating suspicious activity, identifying potential threats, and coordinating appropriate escalation and response activities.
The ideal candidate will have strong experience within a Security Operations Center, SOC, environment and hands-on exposure to technologies including SIEM, EDR/XDR, IDS/IPS, threat intelligence, vulnerability management, cloud security, and endpoint security platforms.
Monitor, analyze, and triage cybersecurity alerts generated by SIEM, EDR/XDR, cloud security, email security, identity protection, and network security platforms.
Conduct initial investigations of security events to determine severity, scope, potential impact, and risk.
Identify, validate, and prioritize potential cybersecurity incidents.
Escalate confirmed threats to appropriate incident response, threat hunting, or security engineering teams.
Correlate security events across multiple data sources, including endpoints, firewalls, IDS/IPS, cloud services, authentication systems, and threat intelligence feeds.
Review and analyze Indicators of Compromise, IOCs, suspicious network activity, phishing attempts, malware detections, and anomalous user behavior.
Investigate potential security breaches and suspicious activity.
Document investigations, findings, response actions, and escalation activities in ticketing and case management systems.
Assist with incident containment, eradication, and recovery activities.
Support vulnerability assessment reviews and evaluate identified vulnerabilities for risk and remediation priority.
Assist with improving threat detection capabilities through alert tuning, process refinement, threat intelligence integration, and identification of false-positive trends.
Support the development and maintenance of security procedures, playbooks, workflows, and knowledge-base documentation.
Research emerging cybersecurity threats, attack techniques, tactics, and procedures.
Maintain accurate operational documentation, investigation notes, metrics, and incident summaries.
Participate in incident response, escalation, and post-incident review activities.
Collaborate with security engineers, incident responders, system administrators, technical teams, and business stakeholders.
Candidates should have strong professional experience in:
Cybersecurity operations
Security monitoring
Incident response
Threat detection
Security investigations
Security alert triage
Security event analysis
Incident investigation documentation
Cybersecurity frameworks
Threat detection methodologies
The detailed job requirements call for 5 years of cybersecurity operations or related experience, while the skills matrix identifies 3 years as required across the core security disciplines. Candidates with 5+ years of directly relevant experience are preferred.
Strong knowledge of:
Security Operations Center, SOC, environments
Security incident triage and investigation
Incident escalation procedures
Security event correlation
Threat intelligence
Indicators of Compromise, IOCs
Indicators of Attack, IOAs
Malware analysis concepts
Phishing investigations
Insider threats
Advanced Persistent Threats, APTs
MITRE ATT&CK
Incident response lifecycle
NIST Cybersecurity Framework
NIST incident response guidance
PICERL
Experience with one or more technologies within the following categories is desired:
SIEM
Microsoft Sentinel
Splunk
QRadar
ArcSight
LogRhythm
NetWitness
Endpoint Security & EDR/XDR
Microsoft Defender XDR
Microsoft Defender for Endpoint
CrowdStrike
SentinelOne
Network Security & IDS/IPS
Firewalls
IDS/IPS technologies
Corelight
Trellix/FireEye
Threat Intelligence
VirusTotal
Google Threat Intelligence
Cisco Talos
Recorded Future
MISP
Vulnerability Management
Tenable
Qualys
Rapid7
Email Security
Proofpoint
Abnormal Security
Secure email gateway technologies
Cloud & Enterprise Security
Wiz
Microsoft Defender for Cloud Apps
Cortex Cloud
Sysdig
Zscaler
Prisma
Netskope
Knowledge or experience with security query languages such as:
KQL
SPL
Lucene
ESQL
Knowledge or experience with scripting languages such as:
PowerShell
Python
Bash
Candidates should have familiarity with:
Windows and Linux environments
TCP/IP and networking protocols
Active Directory
Microsoft Entra ID
Cloud environments
Enterprise security controls
Endpoint security
Network traffic analysis
Authentication and identity security
Vulnerability management
Case management and incident tracking systems
Bachelor's degree in:
Cybersecurity
Information Security
Computer Science
Computer Information Systems
Management Information Systems
A related technical discipline
Relevant education and professional experience may be considered in combination where appropriate.
One or more of the following certifications is preferred:
CompTIA Security+
GIAC Certified Incident Handler, GCIH
GIAC Certified Intrusion Analyst, GCIA
Certified SOC Analyst, CSA
Microsoft Security Operations Analyst, SC-200
Other GIAC or SOC-related cybersecurity certifications
Strong analytical and investigative skills.
Ability to distinguish legitimate cybersecurity threats from false positives.
Ability to make risk-based decisions during security investigations.
Strong documentation and technical writing skills.
Ability to prioritize multiple security investigations in a fast-paced enterprise environment.
Strong written and verbal communication skills.
Ability to communicate cybersecurity issues to both technical and non-technical audiences.
Ability to follow established incident response and escalation procedures.
Strong teamwork and collaboration skills.
Ability to work independently while contributing effectively within a cybersecurity operations team.
This is an onsite position in Austin, Texas, with normal business hours Monday through Friday, 8:00 AM to 5:00 PM.
The role supports enterprise systems that process, store, or transmit sensitive information. Candidates may also be required to provide support outside normal business hours during high-priority cybersecurity incidents.
The strongest candidate will have hands-on SOC or cybersecurity operations experience and a solid background in security alert triage, SIEM, EDR/XDR, threat detection, incident response, security investigations, and event correlation.
Experience with Microsoft Sentinel, Microsoft Defender, KQL, threat intelligence platforms, vulnerability management tools, and security scripting will be particularly valuable.