| Location | Austin, TX |
| Salary | $87.33 Per Hour |
Location: Austin, TX 78751
Work Arrangement: Onsite, Monday through Friday
Start Date: October 12, 2026
Expected End Date: August 31, 2027
Business Hours: Monday through Friday, 8:00 AM to 5:00 PM
Our client is seeking an experienced Network Security Analyst 2 to support enterprise cybersecurity and security operations in Austin, Texas.
This is a hands-on cybersecurity position responsible for monitoring, detecting, investigating, and responding to security events across network, endpoint, cloud, and enterprise environments.
The ideal candidate will bring extensive experience with SIEM, SOAR, EDR, XDR, NDR, Microsoft Sentinel, KQL, SPL, threat intelligence, detection engineering, and incident response.
This position requires strong technical judgment, analytical skills, attention to detail, and the ability to independently investigate and respond to complex security events.
Monitor security alerts, logs, network events, endpoint telemetry, and threat intelligence feeds.
Analyze suspicious activity, anomalous network behavior, malware indicators, endpoint detections, and SIEM correlation events.
Determine the scope, severity, potential impact, and appropriate response to cybersecurity incidents.
Perform incident triage, investigation, escalation, containment coordination, remediation support, and documentation.
Develop, tune, and maintain security detection rules, dashboards, alerts, queries, and automated response playbooks.
Improve security visibility across network, endpoint, identity, cloud, and enterprise environments.
Conduct threat-hunting activities using KQL, SPL, packet and session analysis, endpoint telemetry, and other investigative techniques.
Identify indicators of compromise, attacker tactics, suspicious network patterns, and endpoint-based threats.
Analyze and correlate security information across multiple systems and data sources.
Support vulnerability, risk, and security control assessments for network infrastructure and enterprise information systems.
Investigate security breaches and identify root causes, affected systems, and appropriate corrective actions.
Collaborate with network, infrastructure, cloud, endpoint, and application teams to validate security events and implement risk-mitigation measures.
Document investigation findings and prepare clear incident reports, corrective actions, metrics, and technical recommendations.
Support compliance, audit, and reporting activities by providing security documentation, evidence, and operational metrics.
Maintain awareness of emerging cyber threats, attack techniques, vulnerabilities, indicators of compromise, and cybersecurity best practices.
Support the security and integrity of systems that process, store, or transmit sensitive information.
Participate in incident response, escalation, and post-incident review activities.
Maintain accurate operational documentation and investigation notes.
Candidates must have a minimum of 7 years of experience in cybersecurity, network security, security operations, incident response, or a closely related information security discipline.
Strong hands-on experience is required in the following areas:
SIEM, SOAR, EDR, XDR, and NDR technologies
Microsoft Sentinel
SIEM platform and architecture support
Security log collection and management
Threat intelligence concepts and analysis
Detection engineering methodology and implementation
Incident investigation and response
Security event correlation and analysis
Network traffic analysis
Endpoint security investigation
Security monitoring and alert management
Candidates should have hands-on experience with Microsoft Sentinel, including:
Incident management
Analytics rules
Workbooks and dashboards
Automation
Data connectors
Kusto Query Language, KQL
Alert investigation and correlation
Security monitoring
Log analysis
Candidates should also have experience writing and interpreting KQL, SPL, and other security queries used for investigations, threat hunting, reporting, and detection engineering.
Strong working knowledge of:
Firewalls
IDS/IPS
Proxy logs
DNS
VPN technologies
TCP/IP
Network segmentation
Secure network architecture
Network Detection and Response, NDR
Endpoint Detection and Response, EDR
Packet and session analysis
Endpoint alert triage
Device investigation
Advanced threat hunting
Endpoint response actions
Candidates should have knowledge of commonly used cybersecurity frameworks, controls, and regulatory requirements, including:
NIST
CIS Controls
HIPAA
Enterprise information security standards and requirements
Security risk and control assessment practices
Candidates with 10+ years of experience in the following areas are strongly preferred:
SIEM, SOAR, EDR, XDR, and NDR
Security log collection and management
Threat intelligence
KQL and SPL query development
SIEM platform and architecture support
Detection engineering and implementation
Previous experience supporting healthcare, government, public-sector, or other highly regulated enterprise environments is also preferred.
Bachelor's degree in:
Cybersecurity
Computer Science
Information Systems
Information Technology
A related technical discipline
Relevant professional experience may be considered in place of formal education where applicable.
Microsoft security certifications are strongly preferred, including:
Microsoft Certified: Security Operations Analyst Associate
Microsoft Certified: Cybersecurity Architect Expert
Microsoft Certified: Azure Security Engineer Associate
Microsoft security and Defender-related certifications
Additional preferred certifications include:
CompTIA Security+
CompTIA CySA+
CISSP
CISM
CISA
GIAC security certifications
Splunk Core Certified Power User
Splunk Enterprise Security certifications
SentinelOne product certifications
Strong understanding of SIEM, SOAR, EDR, XDR, NDR, log management, and threat intelligence concepts.
Advanced ability to write and interpret KQL, SPL, and security queries.
Ability to identify indicators of compromise, attacker tactics, suspicious network patterns, and endpoint threats.
Strong incident triage and investigative skills.
Ability to correlate complex security data from multiple sources.
Strong root-cause analysis and problem-solving abilities.
Ability to prioritize security alerts based on severity, risk, and business impact.
Strong written documentation and reporting skills.
Ability to communicate cybersecurity risks and recommendations to both technical and non-technical stakeholders.
Ability to work independently while collaborating effectively within a security operations environment.
Ability to manage shifting priorities and time-sensitive cybersecurity incidents.
This is a full-time onsite position in Austin, Texas, Monday through Friday during normal business hours.
Candidates should also be available to provide support outside normal business hours when necessary for high-priority cybersecurity incidents or planned maintenance activities.
If you are an experienced cybersecurity professional with deep expertise in Microsoft Sentinel, SIEM, KQL, SPL, detection engineering, network security, and incident response, we encourage you to apply.
Throughout the past 35+ years, MMC, one of the most trusted names in workforce management services, has successfully delivered strategic solutions to large and small businesses in numerous industries.