Network Security Analyst 2

Abacus Service Corporation

  • Austin, TX
  • 2 days ago

    Highlights

    Years Required/Preferred Experience 7 Required Knowledge of SIEM, SOAR, EDR, XDR, NDR 7 Required Experience with security log collection and management 7 Required Experience with threat intelligence concepts 7 Required Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting 7 Required Experience in SIEM platform/architecture support 7 Required Experience in detection engineering methodology and implementation 10 Preferred Knowledge of SIEM, SOAR, EDR, XDR, NDR 10 Preferred Experience with security log collection and management 10 Preferred Experience with threat intelligence concepts 10 Preferred Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting 10 Preferred Experience in SIEM platform/architecture support 10 Preferred Experience in detection engineering methodology and implementation . Any Purchase Order resulting from this Request for Resumes is effective on the date of issuance and expires on the last day of the State fiscal year in which the Purchase Order was issued, unless sooner stated in the Purchase Order or unless sooner terminated, renewed, or extended as provided in the Purchase Order.

    Numbers & Facts

    LocationAustin, TX

    Description

    IT STAFFING SERVICES SOLICITATION UNDER
    DEPARTMENT OF INFORMATION RESOURCES
    IT STAFF AUGMENTATION CONTRACT (ITSAC)
    Solicitation Reference Number: 529701770Working Title: Network Security Analyst 2Title/Level: Network Security Analyst 2
    Category: SecurityFull Time 


    I. DESCRIPTION OF SERVICES

    Texas Health and Human Services Commission requires the services of 1 Network Security Analyst 2, hereafter referred to as Candidate(s), who meets the general qualifications of Network Security Analyst 2, Security and the specifications outlined in this document for the Texas Health and Human Services Commission.

    All work products resulting from the project shall be considered "works made for hire " and are the property of the Texas Health and Human Services Commission and may include pre-selection requirements that potential Vendors (and their Candidates) submit to and satisfy criminal background checks as authorized by Texas law. Texas Health and Human Services Commission will pay no fees for interviews or discussions, which occur during the process of selecting a Candidate(s).

    4-7 years of experience in the field or in a related area. Familiar with standard concepts, practices, and procedures within a particular field. Relies on limited experience and judgment to plan and accomplish goals. A certain degree of creativity and latitude is required. Works under limited supervision with considerable latitude for the use of initiative and independent judgment. Ability to maintain the security and integrity of critical infrastructure systems by preventing unauthorized access and ensuring compliance with laws and regulations related to national security and foreign ownership restrictions.

     

    A network security analyst ensures that information systems and computer networks are secure. This includes protecting the company against hackers and cyber-attacks, as well as monitoring network traffic and server logs for activity that seems unusual. Additionally, these analysts are responsible for finding vulnerabilities in the computer networks and creating recommendations for how to minimize these vulnerabilities. The network security analyst investigates security breaches, develops strategies for any security issues that arise, and utilizes the help of firewalls and antivirus software to maintain security. DISCLAIMER: Candidates for this position will be subject to a pre-employment security review to determine employment eligibility.

     

    The position is expected to work onsite at HHSC in Austin, TX full-time, Monday - Friday during agency business hours.

     

    Job Summary

    The Network Security Analyst II performs advanced cybersecurity and network security analysis work in support of HHSC's enterprise security operations. This role is responsible for monitoring, detecting, investigating, and responding to security events across on-premises, cloud, and endpoint environments. The ideal candidate is a hands-on security operations professional with strong experience across SIEM, SOAR, EDR, network detection, and incident response platforms. This role requires sound judgment, technical depth, attention to detail, and a strong commitment to protecting HHSC systems, data, and services that support the health and well-being of Texans.

    Essential Job Functions

    • Monitor security alerts, logs, network events, endpoint telemetry, and threat intelligence feeds.
    • Analyze suspicious activity, anomalous network behavior, malware indicators, endpoint detections, and SIEM correlation events to determine scope, impact, and required response actions.
    • Perform incident triage, investigation, escalation, containment coordination, and documentation in alignment with HHSC security operations procedures.
    • Develop, tune, and maintain detection rules, dashboards, alerts, playbooks, and queries to improve visibility across network, endpoint, identity, and cloud environments.
    • Support threat hunting activities using KQL, SPL, packet/session analysis, endpoint telemetry, and other investigative techniques.
    • Assist with vulnerability, risk, and control assessments for network security infrastructure and enterprise information systems.
    • Document findings, prepare incident reports, track corrective actions, and communicate technical information to security leadership and business stakeholders.
    • Collaborate with network, infrastructure, cloud, endpoint, and application teams to validate security events and implement risk mitigation measures.
    • Maintain awareness of emerging cyber threats, attack techniques, indicators of compromise, and security best practices relevant to healthcare and public-sector environments.
    • Support compliance, audit, and reporting activities by providing evidence, metrics, and security operations documentation as requested.

    Required Qualifications

    • Minimum of seven years of experience in cybersecurity, network security, security operations, incident response, or a closely related information security role.
    • Hands-on experience with Microsoft Sentinel, including incident management, analytics rules, workbooks, automation, data connectors, and Kusto Query Language.
    • Experience using SIEM for log analysis, alert investigation, dashboarding, correlation searches, and security monitoring.
    • Experience with NDR for network traffic analysis, packet/session investigation, threat detection, and incident support.
    • Experience with EDR tools, including endpoint alert triage, device investigation, advanced hunting, and response actions.
    • Working knowledge of network security concepts, including firewalls, IDS/IPS, proxy logs, DNS, VPN, TCP/IP, segmentation, and secure network architecture.
    • Ability to analyze complex security events, correlate data across multiple sources, and produce clear written documentation and recommendations.
    • Knowledge of security frameworks, standards, and regulatory considerations such as NIST, CIS Controls, HIPAA, and state information security requirements.
    • Strong communication, collaboration, problem-solving, and analytical skills.

    Preferred Education and Certifications

    • Bachelor's degree in cybersecurity, computer science, information systems, information technology, or a related field. Relevant experience may be considered in place of education where applicable.
    • Microsoft security certifications are strongly preferred, such as Microsoft Certified: Security Operations Analyst Associate, Microsoft Certified: Cybersecurity Architect Expert, Microsoft Certified: Azure Security Engineer Associate, or Microsoft 365 Defender-related certifications.
    • Additional preferred certifications include CompTIA Security+, CySA+, GIAC security certifications, CISSP, CISM, CISA, Splunk Core Certified Power User, Splunk Enterprise Security Certified Admin, or SentinelOne product certifications.

    Knowledge, Skills, and Abilities

    • Knowledge of SIEM, SOAR, EDR, XDR, network detection and response, log management, and threat intelligence concepts.
    • Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting.
    • Skill in identifying indicators of compromise, attacker tactics, suspicious network patterns, and endpoint-based threats.
    • Ability to prioritize alerts, document investigative steps, and escalate incidents based on severity and business impact.
    • Ability to work independently and collaboratively in a security operations environment with shifting priorities and time-sensitive incidents.
    • Ability to communicate cybersecurity risks, findings, and recommended actions to both technical and non-technical audiences.

    Work Expectations

    • Participate in incident response, escalation, and after-action review activities as needed.
    • Support enterprise security monitoring for systems that process, store, or transmit sensitive information.
    • Follow HHSC policies, procedures, standards, and applicable state and federal security requirements.
    • Maintain accurate operational documentation, investigation notes, metrics, and leadership-ready summaries.
    • May be required to provide support outside normal business hours during high-priority security incidents or planned maintenance activities.

    II. CANDIDATE SKILLS AND QUALIFICATIONS
    Minimum Requirements:
    Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity.
    YearsRequired/PreferredExperience
    7RequiredKnowledge of SIEM, SOAR, EDR, XDR, NDR
    7RequiredExperience with security log collection and management
    7RequiredExperience with threat intelligence concepts
    7RequiredSkill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting
    7RequiredExperience in SIEM platform/architecture support
    7RequiredExperience in detection engineering methodology and implementation
    10PreferredKnowledge of SIEM, SOAR, EDR, XDR, NDR
    10PreferredExperience with security log collection and management
    10PreferredExperience with threat intelligence concepts
    10PreferredSkill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting
    10PreferredExperience in SIEM platform/architecture support
    10PreferredExperience in detection engineering methodology and implementation


    III. TERMS OF SERVICE

    Services are expected to start 10/12/2026 and are expected to complete by 08/31/2027. Total estimated hours per Candidate shall not exceed 1992 hours. This service may be amended, renewed, and/or extended providing both parties agree to do so in writing

    IV. WORK HOURS AND LOCATION

    Services shall be provided during normal business hours unless otherwise coordinated through the Texas Health and Human Services Commission. Normal business hours are Monday through Friday from 8:00 AM to 5:00 PM, excluding State holidays when the agency is closed.

    The primary work location(s) will be at 701 W 51st St Austin, TX 78751. The working position is On Site. Any and all travel, per diem, parking, and/or living expenses shall be at the Candidate's and/or Vendor's expense. Texas Health and Human Services Commission will provide pre-approved, written authorization for travel for any services to be performed away from the primary work location(s). Pre-approved travel expenses are limited to the rates and comply with the rules prescribed by the State of Texas for travel by its classified employees, including any requirement for original receipts.

    The Candidate(s) may be required to work outside the normal business hours on weekends, evenings and holidays, as requested. Payment for work over 40 hours will be at the hourly rate quoted and must be coordinated and pre-approved through Texas Health and Human Services Commission.

    V. OTHER SPECIAL REQUIREMENTS

    TERM OF SERVICE (Required)

    Services are expected to start on or around October 12, 2026 and are expected to completed by August 31, 2027. Total estimated hours per Candidate shall not exceed 1992 hours for FY27.

     

    Initial Purchase Order Term:

    Any Purchase Order resulting from this Request for Resumes is effective on the date of issuance and expires on the last day of the State fiscal year in which the Purchase Order was issued, unless sooner stated in the Purchase Order or unless sooner terminated, renewed, or extended as provided in the Purchase Order.

     

    Renewal Option(s):

    HHSC, at its sole discretion, may renew the Purchase Order for up to three, one-year optional renewals. Such renewal(s), if exercised, shall be subject to all the requirements and terms and conditions of the Purchase Order.

     

    WORK HOURS AND LOCATION (Required)

    A) Services shall be provided during normal business hours unless otherwise coordinated through the Agency. Normal business hours are Monday through Friday from 8:00 a.m. through 5:00 p.m., excluding Texas state holidays when the agency is closed.

    B) The primary work location will be 701 W 51st St, Austin, TX 78751.

    Position is ONSITE at the location listed above (NO REMOTE WORK). Program will only accept LOCAL ONLY candidates for this position.

    Please do not submit candidates who are currently out of state and are planning to move to Texas. Candidates must already reside in Texas.

    C) Any and all travel, per diem, parking, and/or living expenses shall be at the worker's and/or Vendor's expense.

    D) The worker may be required to work remotely at HHSC discretion, up to 100 percent of the time.

    E) The worker may be required to work outside the normal business hours on weekends, evenings and holidays, as requested. Payment for work over 40 hours will be at the hourly rate quoted and must be coordinated and pre-approved through the Agency.

    OTHER SPECIAL REQUIREMENTS

    Interviews will be conducted: (check all that apply)

    By Phone

    In person

    Through Microsoft Teams

     

    IMPORTANT INFORMATION

    A vendor's submission of a candidate may be disqualified if:

    • The vendor fails to add the candidate to competitive solicitation, or RFR, in the DIR ITSAC Portal.
    • Another vendor submits the same candidate for the same competitive solicitation, also known as a request of resume (RFR).
    • The vendor submits more than one candidate for the same competitive solicitation, or RFR.
    • The vendor submits a candidate after the response period for a competitive solicitation, or RFR.
    • The vendor fails to format the email subject line properly, when submitting a candidate for a competitive solicitation, or RFR:
      • Proper Formatting: Solicitation Number, Vendor Name, Candidate First and Last Name, Position Type and Level
      • Example: 529123456, Sanders Technologies, Jane Doe, Project Lead 3
    • The vendor fails to follow any other instructions noted in the competitive solicitation, or RFR.

     

    Initial Purchase Order Term:

    Any Purchase Order resulting from this Request for Resumes is effective on the date of issuance and expires on the last day of the State fiscal year in which the Purchase Order was issued, unless sooner stated in the Purchase Order or unless sooner terminated, renewed, or extended as provided in the Purchase Order.

     

    Renewal Option(s):

    HHSC, at its sole discretion, may renew the Purchase Order for up to three, one-year optional renewals. Such renewal(s), if exercised, shall be subject to all the requirements and terms and conditions of the Purchase Order.

    By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at Privacy Policy - Abacus.